Cyber Digital Protection Security Specialist
We are looking for a Cyber and Digital Security Specialist – Digital Protection Security to be part of our Digital Protection Security team.
Position Snapshot
- Type of Contract : Permanent
- IT Security & Compliance
- Type of work : Hybrid
- Work Language : Fluent Business English
The role
The Cyber and Digital Security Specialist – Digital Protection is responsible for establishing and maintaining security products, platforms, and solutions designed to mitigate Digital IT risks across the Group to ensure that information assets are adequately protected. This person is responsible for the identification, evaluation, reporting, and mitigation of information security risks in a manner that meets compliance and regulatory requirements, aligning with and supporting the risk posture of the enterprise. The Cyber and Digital Security Specialist – Digital Protection continuously researches and stays on top of emerging security threats, technologies, and trends.
What you’ll do
Ensure new products, platforms, and solutions are implemented "Secure & Compliant by Design".Work closely with Enterprise Architects, other functional area architects, and other Security Specialists to ensure adequate security solutions are in place throughout all IT products and platforms to mitigate identified risks sufficiently and to meet business objectives and regulatory requirements.Conduct comprehensive risk assessments of architectural designs, identifying potential security gaps, vulnerabilities, and threats. Develop mitigation strategies and work closely with stakeholders to implement necessary security controls.Conduct comprehensive reviews of web application architectures to identify security vulnerabilities, weaknesses, and potential risks.Identify and recommend improvements to enhance the security of web application architectures, including but not limited to authentication, authorization, input validation, session management, and data protection mechanisms.Help business and IT with web applications security issues mitigation.Design, implement, and manage the Akamai edge protection product to protect web applications from potential attacks and vulnerabilities.Stay up-to-date with the latest security trends, vulnerabilities, and industry best practices related to Akamai edge protection and web application security.Investigate and respond to security incidents related to web applications protected by Akamai edge protection, including incident analysis, containment, eradication, and recovery.Support Product Manager to design the roadmap for Digital Protection Security including the assessment of new vendors, tools, and solutions.We offer you
Great benefits : including competitive salary and a comprehensive social benefits package. We have one of the most competitive pension plans on the market, as well as flexible remuneration with tax advantages : health insurance, restaurant card, mobility plan, etc.Personal and professional growth : through ongoing training and constant career opportunities reflecting our conviction that people are our most important asset.Hybrid working environment : Our state-of-the-art campus is dog-friendly and equipped with a medical center, canteen, and areas to co-create network and chill!5+ years of experience in a combination of Information Security Architecture.Excellent written and verbal communication skills in English, interpersonal and collaborative skills, and the ability to communicate security and risk-related concepts to technical and non-technical audiences.Proven experience in conducting architecture reviews for web applications and identifying security vulnerabilities.Proven experience in assessing and protecting public-facing applications (websites, mobile, e-commerce) and determining the cybersecurity controls which are required.Deep understanding of common information security frameworks, such as ISO 27001, NIST, MITRE, and OWASP.Experience deploying and operating preventative technologies such as WAF, anti-bot, anti-fraud technologies, integrated cybersecurity SDKs, and other preventative cybersecurity technologies.Professional security, software architecture certifications, such as a CISSP, CISSP-ISSAP, CSSLP, GIAC, or other similar credentials, is preferred.Bonus Points If You :
Have knowledge of cloud security principles and experience with cloud-based web applications (e.g., AWS, Azure).Proficiency in Python scripting and programming languages for automation and customization of security tools.Knowledge of content delivery network (CDN) principles, CDN security features, and associated technologies.About the IT Hub
At Nestlé IT, we are a diverse, global team of IT professionals in the biggest health, nutrition, and wellness company in the world. We strive to create an environment where people are valued for who they are. We innovate every day through future-ready technologies to create opportunities for Nestlé to delight consumers, customers, and employees alike.
We are Nestlé, the largest food and beverage company in the world, with a presence in more than 185 countries. Our values are based on respect : respect for ourselves, respect for others, respect for diversity, and respect for our future. Nestlé is dedicated to offering high-quality food and beverage products and services that contribute to the nutrition, health, and well-being of people, pets, and the planet.
We encourage the diversity of applicants across gender, age, ethnicity, nationality, sexual orientation, social background, religion or belief, and disability.
How we will proceed :
You send us your CV → We contact relevant applicants → Interviews → Feedback → Job Offer communication to the Finalist → First working day
J-18808-Ljbffr