Who we are
lululemon is an innovative performance apparel company for yoga, running, training, and other athletic pursuits. Setting the bar in technical fabrics and functional design, we create transformational products and experiences that support people in moving, growing, connecting, and being well. We owe our success to our innovative product, emphasis on stores, commitment to our people, and the incredible connections we make in every community we're in. As a company, we focus on creating positive change to build a healthier, thriving future. In particular, that includes creating an equitable, inclusive and growth-focused environment for our people.
About this team
The lululemon Cybersecurity team enables lululemon to conduct its global operations in a secure manner and safeguard the trusted information of its guests and users. This is accomplished by understanding business risk as manifested through cybersecurity and compliance risk, and by maintaining a high degree of employee awareness of all security and compliance topics. To further enhance our team, we are looking for a Security Analyst - Cybersecurity Risk, to support our Cybersecurity Risk Management team.
A day in the life:
The Technology Risk Management team are cybersecurity experts, problem solvers, insight and solution generators, and trusted risk & compliance advisors to the business. We leverage our risk, information security and control expertise to support risk management, IT Security, Regulatory Compliance and to drive continuous process improvements and cost savings. We also partner with various parts of the business (Brand, Product, Technology, and Finance, to name a few) and engage in open dialogue to tap into the creativity of our people and action innovative security solutions.
As a Security Analyst - Cybersecurity Risk, you will be conducting Technology risk assessments, security reviews, maintaining the Technology Risk Register, generating management metrics and reporting and working with stakeholders on risk mitigation plans.
- Support a culture of risk management, risk and control visibility with measurable risk reduction and effective reporting and governance of risk reduction activities.
- Participate in performing Security Risk Assessments of all new projects and technology implementations.
- Determine information security risk profiles for various systems, assets, data etc., using knowledge of lululemon policy, frameworks, standards and relevant industry best practices.
- Develops, updates, establish risk assessment procedures and process documentation
- Ability to characterize the system, identify threats / vulnerabilities, control deficiencies, likelihood determination, impact analysis, risk levels, compensatory control recommendation and results documentation.
- Support and conduct context establishment, risk identification, risk analysis, evaluation, treatment, documentation, communication as well as periodic monitoring / risk re-reviews.
- Escalate security risk exceptions, threats, vulnerabilities, quality, performance, gaps, change control and delivery issues as required.
- Ability to lead stakeholder management, risk communication, risk reviews, driving risk acceptance and risk treatment activities
- Execute automation in applying GRC workflows, tracking risk life-cycle, engaging stakeholders, monitoring and reporting risks
- Collaborates with other members of the Policy, IT Security & Risk Assessment team on complex matters.
- Identifies needs, develops and implements technology-related continuous improvement initiatives for the department.
Qualifications:
- Bachelor’s degree (preferably Management Information Systems). At least one of the following professional certifications: CISA, CRISC, or ISO27001 LA
- Hands-on working experience of Service Now IRM / GRC modules
- 3+ years Technology risk management experience or a combination of Technology Risk-GRC and information security experience
- Knowledge/experience with data security and privacy regulations (e.g. NIST CSF, ISO 27001, PCI DSS, GDPR).
- Effective communication and relationship-building skills, a natural affinity for being curious and inquisitive, and an ability to work with ambiguity, analyze situations and problem solve.
Must haves:
- Acknowledges the presence of choice in every moment and takes personal responsibility for their life.
- Possesses an entrepreneurial spirit and continuously innovates to achieve great results.
- Communicates with honesty and kindness and creates the space for others to do the same.
- Leads with courage, knowing the possibility of greatness is bigger than the fear of failure.
- Fosters connection by putting people first and building trusting relationships.
- Integrates fun and joy as a way of being and working, aka doesn’t take themselves too seriously.
Additional Notes
Immigration support is potentially available for this role.
Compensation and Benefits Package
lululemon’s compensation offerings are grounded in a pay-for-performance philosophy that recognizes exceptional individual and team performance. The typical hiring range for this position is from $105,800 - 132,200 annually; the base pay offered is based on market location and may vary depending on job-related knowledge, skills, experience, and internal equity. As part of our total rewards offering, permanent employees in this position may be eligible for our competitive annual bonus program, subject to program eligibility requirements.
At lululemon, investing in our people is a top priority. We believe that when life works, work works. We strive to be the place where inclusive leaders come to develop and enable all to be well. Recognizing our teams for their performance and dedication, other components of our total rewards offerings include support of career development, wellbeing, and personal growth:
- Extended health and dental benefits, and mental health plans
- Paid time off
- Savings and retirement plan matching
- Generous employee discount
- Fitness & yoga classes
- Parenthood top-up
- Extensive catalog of development course offerings
- People networks, mentorship programs, and leadership series (to name a few)
Note: The incentive programs, benefits, and perks have certain eligibility requirements. The Company reserves the right to alter these incentive programs, benefits, and perks in whole or in part at any time without advance notice.
workplace arrangement
This role is classified as HYBRID under our SSC Workplace Policy:
Hybrid
In-person collaboration is important, and much of the role can be performed remotely. Work is performed onsite at least 3 days per week.
#LI-Hybrid
#LI-MF