AppSec Jobs
← Back to all jobs

lululemon

Senior Cybersecurity Engineer - Security - International Technology

Seattle, WAPosted 6 days ago$147,300 - $193,300 annuallyWebsite
Apply on LinkedIn →

At a Glance

10+ years experienceAWSPythonJavaJavaScript/TypeScriptThreat Modeling

About This Role

As a Senior Cybersecurity Engineer, you will lead complex security engineering initiatives, designing and implementing security controls, platforms, and solutions that protect critical systems at scale. You will build and operate enterprise security capabilities such as centralized authentication, security enforcement mechanisms, and security automation, while applying secure coding practices and rigorous testing and validation. You will partner closely with engineering teams to embed security into system design and delivery, drive improvements to security quality and reliability, and mentor junior engineers through hands-on technical leadership and knowledge sharing.

Responsibilities

  • Build enterprise security systems implementing centralized authentication, security platforms, and organization-wide controls
  • Lead comprehensive threat modeling and security assessments for complex systems, evaluating attacker behaviour across integrations and influencing secure design decisions early in the development lifecycle
  • Own end-to-end response for complex security incidents, driving deep root cause analysis and delivering coordinated long-term improvements to detection, prevention, and security monitoring capabilities
  • Develop advanced security code, tools, and libraries including security automation platforms, scanners and detectors, security testing systems, and security SDKs
  • Establish security code standards defining secure coding practices, code review requirements, and implementation quality
  • Mentor junior engineers through hands-on technical leadership and knowledge sharing
  • Drive improvements to security quality and reliability

Requirements

JavaPythonJavaScriptAWSDASTSAST
  • Bachelor's degree in Computer Science, Cybersecurity, or related field; security certification strongly preferred
  • 6-10 years of experience leading security engineering initiatives, establishing security standards and practices, and building security systems at scale, or equivalent
  • Proven experience implementing enterprise security controls and building security infrastructure including centralized authentication, authorization services, and security policy enforcement systems at scale
  • Track record of writing complex security systems including security platforms and SDKs
  • Experience establishing security code review practices, security checklists, and security development frameworks
  • Demonstrated ability to lead advanced threat modeling for complex systems, anticipating sophisticated adversarial behaviour
  • Experience owning investigation and resolution of complex security incidents with deep root cause analysis
  • Working experience with one or more programming languages: Java, Python, JavaScript preferred
  • Understanding of AWS cloud services and concepts such as S3, EC2, Lambda, and VPC
  • Experience with common web application testing tools for IAST, DAST and SAST
  • Experience with analysis tools and exposure security analysis and best practice recommendation in micro service landscape
  • Familiarity with DSPM, DLP, or data governance tooling
  • Acknowledge the presence of choice in every moment and take personal responsibility for your life
  • Possess an entrepreneurial spirit and continuously innovate to achieve great results
  • Communicate with honesty and kindness and create the space for others to do the same
  • Lead with courage, knowing the possibility of greatness is bigger than the fear of failure
  • Foster connection by putting people first and building trusting relationships
  • Integrate fun and joy as a way of being and working
  • Authorization to work in the United States is required

Benefits & Perks

Competitive annual bonus program (subject to program eligibility requirements)
Extended health and dental benefits, and mental health plans
Paid time off
Savings and retirement plan matching
Generous employee discount
Fitness & yoga classes
Parenthood top-up
Extensive catalog of development course offerings
People networks, mentorship programs, and leadership series
Support of career development, wellbeing, and personal growth

About lululemon

Lululemon Athletica is a yoga-inspired athletic apparel company founded in 1998 in Vancouver, Canada, by Chip Wilson. The company designs and sells high-performance athletic wear for both women and men, catering to various sports and fitness activities. Lululemon started as a design studio and opened its first retail store in 2000. It went public in 2007 and expanded into Europe in 2014. Initially focused on women's yoga wear, Lululemon's product line has grown to include accessories, outerwear, and a dedicated men's line. The company is known for its proprietary Luon fabric, which offers durability and comfort. Lululemon stores also serve as community hubs, promoting healthy living and mindfulness while connecting fitness enthusiasts. The brand targets active individuals who seek stylish and functional athletic wear.

Industry

retail

Employees

39,000

1026 engineers

Revenue

$11B

Website

Visit →

Security at lululemon

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

  • Stated AppSec Mission: 'Embed secure development practices across the SDLC' – Job ID 57297 .
  • Developer Enablement: The team focuses on 'DevSecOps integration' and scaling through automation to support development speed. .
  • Risk Philosophy: Employs 'threat modeling' and 'secure coding' to address risks within the business context. .
  • Stated Goals: 'scale vulnerability remediation through automation' – Job ID 57297 .

Security Team

Org Structure & Reporting Line: The AppSec team is described as a 'key leader within the Technology organization' responsible for embedding practices across the SDLC. . Key Public-Facing Leaders: 1. Robert Masse, Head of Cybersecurity (Global) – https://www.linkedin.com/in/robertmasse. Key Quote: 'mature our global AppSec and Vulnerability Management capabilities' – LinkedIn . 2. Zachary B., Security Engineer – https://www.linkedin.com/in/zachary-blum. Key Quote: 'dedicated to improving our vulnerability pipeline' – LinkedIn . 3. Ravi Sharma, Director, Cloud & Platform Engineering – https://www.linkedin.com/in/ravi-sharma-1389708. Key Quote: 'Unified DevSecOps with GitLab' – LinkedIn . Team Size Estimate (as_of:): Information not publicly available. Active AppSec Job Postings (as_of:): 3 identified (Vulnerability Management, SOC, Awareness).

Key Initiatives

Security Champions Program: Information not publicly available. 'Shift Left' in Practice: Described as 'threat modeling, secure coding, and DevSecOps integration' within the SDLC – Job ID 57297 . Vulnerability Management Process: - Intake: 'Record identified vulnerabilities' – Job ID 57252 . - Triage/Remediation: 'create remediation tickets and track their status' – Job ID 57252 . Recent Initiatives: 'Unified DevSecOps with GitLab' to manage 'thousands of repos' – LinkedIn ; 'comprehensive cybersecurity awareness program' – Job ID 57836 .

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.

Interested in this role?

Apply on LinkedIn