lululemon
Senior Cybersecurity Engineer - Security - International Technology
At a Glance
About This Role
Responsibilities
- Build enterprise security systems implementing centralized authentication, security platforms, and organization-wide controls
- Lead comprehensive threat modeling and security assessments for complex systems, evaluating attacker behaviour across integrations and influencing secure design decisions early in the development lifecycle
- Own end-to-end response for complex security incidents, driving deep root cause analysis and delivering coordinated long-term improvements to detection, prevention, and security monitoring capabilities
- Develop advanced security code, tools, and libraries including security automation platforms, scanners and detectors, security testing systems, and security SDKs
- Establish security code standards defining secure coding practices, code review requirements, and implementation quality
- Mentor junior engineers through hands-on technical leadership and knowledge sharing
- Drive improvements to security quality and reliability
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, or related field; security certification strongly preferred
- 6-10 years of experience leading security engineering initiatives, establishing security standards and practices, and building security systems at scale, or equivalent
- Proven experience implementing enterprise security controls and building security infrastructure including centralized authentication, authorization services, and security policy enforcement systems at scale
- Track record of writing complex security systems including security platforms and SDKs
- Experience establishing security code review practices, security checklists, and security development frameworks
- Demonstrated ability to lead advanced threat modeling for complex systems, anticipating sophisticated adversarial behaviour
- Experience owning investigation and resolution of complex security incidents with deep root cause analysis
- Working experience with one or more programming languages: Java, Python, JavaScript preferred
- Understanding of AWS cloud services and concepts such as S3, EC2, Lambda, and VPC
- Experience with common web application testing tools for IAST, DAST and SAST
- Experience with analysis tools and exposure security analysis and best practice recommendation in micro service landscape
- Familiarity with DSPM, DLP, or data governance tooling
- Acknowledge the presence of choice in every moment and take personal responsibility for your life
- Possess an entrepreneurial spirit and continuously innovate to achieve great results
- Communicate with honesty and kindness and create the space for others to do the same
- Lead with courage, knowing the possibility of greatness is bigger than the fear of failure
- Foster connection by putting people first and building trusting relationships
- Integrate fun and joy as a way of being and working
- Authorization to work in the United States is required
Benefits & Perks
About lululemon
Lululemon Athletica is a yoga-inspired athletic apparel company founded in 1998 in Vancouver, Canada, by Chip Wilson. The company designs and sells high-performance athletic wear for both women and men, catering to various sports and fitness activities. Lululemon started as a design studio and opened its first retail store in 2000. It went public in 2007 and expanded into Europe in 2014. Initially focused on women's yoga wear, Lululemon's product line has grown to include accessories, outerwear, and a dedicated men's line. The company is known for its proprietary Luon fabric, which offers durability and comfort. Lululemon stores also serve as community hubs, promoting healthy living and mindfulness while connecting fitness enthusiasts. The brand targets active individuals who seek stylish and functional athletic wear.
Security at lululemon
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- Stated AppSec Mission: 'Embed secure development practices across the SDLC' – Job ID 57297 .
- Developer Enablement: The team focuses on 'DevSecOps integration' and scaling through automation to support development speed. .
- Risk Philosophy: Employs 'threat modeling' and 'secure coding' to address risks within the business context. .
- Stated Goals: 'scale vulnerability remediation through automation' – Job ID 57297 .
Security Team
Org Structure & Reporting Line: The AppSec team is described as a 'key leader within the Technology organization' responsible for embedding practices across the SDLC. . Key Public-Facing Leaders: 1. Robert Masse, Head of Cybersecurity (Global) – https://www.linkedin.com/in/robertmasse. Key Quote: 'mature our global AppSec and Vulnerability Management capabilities' – LinkedIn . 2. Zachary B., Security Engineer – https://www.linkedin.com/in/zachary-blum. Key Quote: 'dedicated to improving our vulnerability pipeline' – LinkedIn . 3. Ravi Sharma, Director, Cloud & Platform Engineering – https://www.linkedin.com/in/ravi-sharma-1389708. Key Quote: 'Unified DevSecOps with GitLab' – LinkedIn . Team Size Estimate (as_of:): Information not publicly available. Active AppSec Job Postings (as_of:): 3 identified (Vulnerability Management, SOC, Awareness).
Key Initiatives
Security Champions Program: Information not publicly available. 'Shift Left' in Practice: Described as 'threat modeling, secure coding, and DevSecOps integration' within the SDLC – Job ID 57297 . Vulnerability Management Process: - Intake: 'Record identified vulnerabilities' – Job ID 57252 . - Triage/Remediation: 'create remediation tickets and track their status' – Job ID 57252 . Recent Initiatives: 'Unified DevSecOps with GitLab' to manage 'thousands of repos' – LinkedIn ; 'comprehensive cybersecurity awareness program' – Job ID 57836 .
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.
Interested in this role?
Apply on LinkedIn