Ver oferta completa

CYBER DIGITAL PROTECTION SECURITY SPECIALIST

Esplugues de Llobregat - Barcelona

Descripción de la oferta de empleo

We are looking for Cyber and Digital Security Specialist – Digital Protection Security to be part of our Digital Protection Security team.
Position Snapshot   Location.
Esplugues de Llobregat  Type of Contract.
Permanent  IT Security & Compliance  Type of work.
Hybrid  Work Language.
Fluent Business English    The role    Cyber and Digital Security Specialist – Digital Protection.
Under the supervision and guidance of their primary Community of Practice Lead and Product Manager, the Cyber and Digital Security Specialist – Digital Protection is responsible for establishing and maintaining security products, platforms and solutions designed to mitigate Digital IT risks across the Group to ensure that information assets are adequately protected.
This person is responsible for the identification, evaluation, reporting and mitigation of information security risks in a manner that meets compliance and regulatory requirements, aligning with and supporting the risk posture of the enterprise.
This person will proactively work with IT and business units to implement practices that meet defined policies and standards for information security.
The Cyber and Digital Security Specialist – Digital Protection continuously researches and stays on top of emerging security threats, technologies and trends.
What you’ll do    Ensures new products, platforms and solutions are implemented "Secure & Compliant by Design".
Works closely with Enterprise Architects, other functional area architects and other Security Specialists to ensure adequate security solutions are in place throughout all IT products and platforms to mitigate identified risks sufficiently and to meet business objectives and regulatory requirements.
Understands and interacts with related disciplines to ensure the consistent application of policies and standards across all product groups; technology projects and systems, including, but not limited to, privacy, risk management, compliance and business continuity management.
Conduct comprehensive risk assessments of architectural designs, identifying potential security gaps, vulnerabilities, and threats.
Develop mitigation strategies and work closely with stakeholders to implement necessary security controls.
Conduct comprehensive reviews of web application architectures to identify security vulnerabilities, weaknesses, and potential risks.
Identify and recommend improvements to enhance the security of web application architectures, including but not limited to authentication, authorization, input validation, session management, and data protection mechanisms.
Help business and IT with web applications security issues mitigation.
Design, implement, and manage the Akamai edge protection product to protect Nestlé’s web applications from potential attacks and vulnerabilities.
Configure and fine-tune the Akamai edge protection rules and policies to effectively mitigate web application security risks.
Stay up-to-date with the latest security trends, vulnerabilities, and industry best practices related to Akamai edge protection and web application security  Investigate and respond to security incidents related to web applications protected by Akamai edge protection, including incident analysis, containment, eradication, and recovery.
Support Product Manager to design the roadmap for Digital Protection Security including the assessment of new vendors, tools, and solutions.
We offer you We offer more than just a job.
We put people first and inspire you to become the best version of yourself.
Great benefits including competitive salary and a comprehensive social benefits package.
We have one of the most competitive pension plans on the market, as well as flexible remuneration with tax advantages.
health insurance, restaurant card, mobility plan, etc.
Personal and professional growth through ongoing training and constant career opportunities reflecting our conviction that people are our most important asset.
Hybrid working environment with flexible working scheme.
Our state-of-the-art campus is dog friendly and equipped with a medical center, canteen and areas to co-create network and chill!    Minimum qualifications.
5+ years of experience in a combination of Information Security Architecture  Excellent written and verbal communication skills in English, interpersonal and collaborative skills, and the ability to communicate security and risk-related concepts to technical and non-technical audiences (e.
.
management, agencies, vendors).
Experience determining technical security requirements by evaluating business strategies and needs following a risk-based approach, and describe associated data flows and security controls needed, interacting with a broad cross-section of personnel to explain and enforce security measures.
Proven track record and experience developing cybersecurity architecture, policies and controls and successfully executing these into a live environment.
Proven experience in conducting architecture reviews for web applications and identifying security vulnerabilities.
Proven experience in assessing and protecting public-facing applications (websites, mobile, e-commerce) and determining the cybersecurity controls which are required.
Excellent analytical and problem-solving skills, with the ability to quickly identify and respond to security incidents.
Deep understanding of common information security frameworks, such as ISO ,  NIST, MITRE  and OWASP               Deep understanding of industry standards and frameworks related to content delivery security, such as OWASP Top 10, PCI DSS, and ISO .
Experience deploying and operating preventative technologies such as WAF, anti-bot, anti-fraud technologies, integrated cybersecurity SDKs, and other preventative cybersecurity technologies.
Have professional security, software architecture certifications, such as a CISSP, CISSP-ISSAP, CSSLP, GIAC, or other similar credentials, is preferred      Bonus Points If You.
Have Knowledge of cloud security principles and experience with cloud-based web applications (e.
., AWS, Azure) is a plus.
Proficiency in Python scripting and programming languages for automation and customization of security tools.
Knowledge of content delivery network (CDN) principles, CDN security features, and associated technologies.
About the IT Hub    At Nestlé IT, we are a diverse, global team of IT professionals in the biggest health, nutrition and wellness company of the world.
We strive to create an environment where people are valued for who they are.
We innovate every day through future ready technologies to create opportunities for Nestlé to delight consumers, customers and employees alike.
We collaborate with partners around the world to deliver tangible value at global scale.
We continuously work to develop our people to be future ready.
About Nestlé    We are Nestlé, the largest food and beverage company in the world, with a presence in more than 185 countries.
With net sales of CHF 94.
billion in , the company has over employees and 418 factories in 85 countries.
Our values are based on respect.
respect for ourselves, respect for others, respect for diversity, and respect for our future.
Nestlé is dedicated to offering high-quality food and beverage products and services that contribute to the nutrition, health, and well-being of people, pets, and the planet.
Additionally, it is committed to being a leading company in sustainability and achieving net zero greenhouse gas emissions by .
Want to learn more? Visit us at.
www.
estle.
om     We encourage the diversity of applicants across gender, age, ethnicity, nationality, sexual orientation, social background, religion or belief and disability.
Step outside your comfort zone; share your ideas, way of thinking and working to make a difference to the world, every single day.
You own a piece of the action – make it count.
Join Nestlé’s IT Hub #beaforceforgood   How we will proceed.
You send us your CV → We contact relevant applicants → Interviews → Feedback →   Job Offer communication to the Finalist → First working day   We are looking for Cyber and Digital Security Specialist – Digital Protection Security to be part of our Digital Protection Security team.
Position Snapshot   Location.
Esplugues de Llobregat  Type of Contract.
Permanent  IT Security & Compliance  Type of work.
Hybrid  Work Language.
Fluent Business English    The role    Cyber and Digital Security Specialist – Digital Protection.
Under the supervision and guidance of their primary Community of Practice Lead and Product Manager, the Cyber and Digital Security Specialist – Digital Protection is responsible for establishing and maintaining security products, platforms and solutions designed to mitigate Digital IT risks across the Group to ensure that information assets are adequately protected.
This person is responsible for the identification, evaluation, reporting and mitigation of information security risks in a manner that meets compliance and regulatory requirements, aligning with and supporting the risk posture of the enterprise.
This person will proactively work with IT and business units to implement practices that meet defined policies and standards for information security.
The Cyber and Digital Security Specialist – Digital Protection continuously researches and stays on top of emerging security threats, technologies and trends.
What you’ll do    Ensures new products, platforms and solutions are implemented "Secure & Compliant by Design".
Works closely with Enterprise Architects, other functional area architects and other Security Specialists to ensure adequate security solutions are in place throughout all IT products and platforms to mitigate identified risks sufficiently and to meet business objectives and regulatory requirements.
Understands and interacts with related disciplines to ensure the consistent application of policies and standards across all product groups; technology projects and systems, including, but not limited to, privacy, risk management, compliance and business continuity management.
Conduct comprehensive risk assessments of architectural designs, identifying potential security gaps, vulnerabilities, and threats.
Develop mitigation strategies and work closely with stakeholders to implement necessary security controls.
Conduct comprehensive reviews of web application architectures to identify security vulnerabilities, weaknesses, and potential risks.
Identify and recommend improvements to enhance the security of web application architectures, including but not limited to authentication, authorization, input validation, session management, and data protection mechanisms.
Help business and IT with web applications security issues mitigation.
Design, implement, and manage the Akamai edge protection product to protect Nestlé’s web applications from potential attacks and vulnerabilities.
Configure and fine-tune the Akamai edge protection rules and policies to effectively mitigate web application security risks.
Stay up-to-date with the latest security trends, vulnerabilities, and industry best practices related to Akamai edge protection and web application security  Investigate and respond to security incidents related to web applications protected by Akamai edge protection, including incident analysis, containment, eradication, and recovery.
Support Product Manager to design the roadmap for Digital Protection Security including the assessment of new vendors, tools, and solutions.
We offer you We offer more than just a job.
We put people first and inspire you to become the best version of yourself.
Great benefits including competitive salary and a comprehensive social benefits package.
We have one of the most competitive pension plans on the market, as well as flexible remuneration with tax advantages.
health insurance, restaurant card, mobility plan, etc.
Personal and professional growth through ongoing training and constant career opportunities reflecting our conviction that people are our most important asset.
Hybrid working environment with flexible working scheme.
Our state-of-the-art campus is dog friendly and equipped with a medical center, canteen and areas to co-create network and chill!    Minimum qualifications.
5+ years of experience in a combination of Information Security Architecture  Excellent written and verbal communication skills in English, interpersonal and collaborative skills, and the ability to communicate security and risk-related concepts to technical and non-technical audiences (e.
.
management, agencies, vendors).
Experience determining technical security requirements by evaluating business strategies and needs following a risk-based approach, and describe associated data flows and security controls needed, interacting with a broad cross-section of personnel to explain and enforce security measures.
Proven track record and experience developing cybersecurity architecture, policies and controls and successfully executing these into a live environment.
Proven experience in conducting architecture reviews for web applications and identifying security vulnerabilities.
Proven experience in assessing and protecting public-facing applications (websites, mobile, e-commerce) and determining the cybersecurity controls which are required.
Excellent analytical and problem-solving skills, with the ability to quickly identify and respond to security incidents.
Deep understanding of common information security frameworks, such as ISO ,  NIST, MITRE  and OWASP               Deep understanding of industry standards and frameworks related to content delivery security, such as OWASP Top 10, PCI DSS, and ISO .
Experience deploying and operating preventative technologies such as WAF, anti-bot, anti-fraud technologies, integrated cybersecurity SDKs, and other preventative cybersecurity technologies.
Have professional security, software architecture certifications, such as a CISSP, CISSP-ISSAP, CSSLP, GIAC, or other similar credentials, is preferred      Bonus Points If You.
Have Knowledge of cloud security principles and experience with cloud-based web applications (e.
., AWS, Azure) is a plus.
Proficiency in Python scripting and programming languages for automation and customization of security tools.
Knowledge of content delivery network (CDN) principles, CDN security features, and associated technologies.
About the IT Hub    At Nestlé IT, we are a diverse, global team of IT professionals in the biggest health, nutrition and wellness company of the world.
We strive to create an environment where people are valued for who they are.
We innovate every day through future ready technologies to create opportunities for Nestlé to delight consumers, customers and employees alike.
We collaborate with partners around the world to deliver tangible value at global scale.
We continuously work to develop our people to be future ready.
About Nestlé    We are Nestlé, the largest food and beverage company in the world, with a presence in more than 185 countries.
With net sales of CHF 94.
billion in , the company has over employees and 418 factories in 85 countries.
Our values are based on respect.
respect for ourselves, respect for others, respect for diversity, and respect for our future.
Nestlé is dedicated to offering high-quality food and beverage products and services that contribute to the nutrition, health, and well-being of people, pets, and the planet.
Additionally, it is committed to being a leading company in sustainability and achieving net zero greenhouse gas emissions by .
Want to learn more? Visit us at.
www.
estle.
om     We encourage the diversity of applicants across gender, age, ethnicity, nationality, sexual orientation, social background, religion or belief and disability.
Step outside your comfort zone; share your ideas, way of thinking and working to make a difference to the world, every single day.
You own a piece of the action – make it count.
Join Nestlé’s IT Hub #beaforceforgood   How we will proceed.
You send us your CV → We contact relevant applicants → Interviews → Feedback →   Job Offer communication to the Finalist → First working day   Esplugues Llobregat, B, ES, Esplugues Llobregat, B, ES,
Ver oferta completa

Detalles de la oferta

Empresa
  • Nestlé Careers
Localidad
Dirección
  • Sin especificar - Sin especificar
Fecha de publicación
  • 01/12/2024
Fecha de expiración
  • 01/03/2025
Digital Business Developer
Recruit4Work

Sounds like an adventure for you? check out this position! would you like to develop your career in digital business development? if you're passionate about sales and digital products, outgoing and willing to roll up your sleeves and get things done in a fast-paced, rapidly changing environment, we may......

Beca formativa marketing digital
Nett formacion sl

Por sus profesores, profesionales en activo en grandes empresas digitales, empresas referentes del sector y emprendedores del mundo digital... únete a los más de 2500 alumnos que han dado el salto al mercado laboral digital con la beca talentic... la beca talentic te ofrece la posibilidad de realizar......

Maintenance Specialist
Joivy

Report to the operations specialist and coordinate daily interventions and tasks... great english and spanish fluency (b2-c1 level both written and spoken) being already in possession of a permit to work in spain or the eu other features that would help a lot: effective communication with the operations......

Digital Business Developer
Recruit4Work

Sounds like an adventure for you? check out this position! would you like to develop your career in digital business development? if you're passionate about sales and digital products, outgoing and willing to roll up your sleeves and get things done in a fast-paced, rapidly changing environment, we may......

Vendedor Comisionista Marketing Digital
BluCactus

Actividades a realizar venta de servicios de marketing digital... búsqueda de empresas/ negocios por ofertar prospectar clientes administrar y gestionar cartera asignada asesoría al cliente seguimientos con los clientes juntas con clientes* identificar clientes potenciales... vendedor comisionista blucactus......

Junior it customer success specialist (en language) (remote)
Hostinger

We are looking for a junior technical customer success specialist to join our customer success team... 04 or higher, red hat 8... fully compensated 3... estimated start date: as soon as possible!... high motivation for helping customers and it curiosity, basic technical understanding......

Public Relations Specialist
Involve rh

Descripción del puesto: confidencial cuenta con una posición como public relations specialist para crear y mantener una imagen positiva de la empresa a través de estrategias de comunicación efectivas con los medios y el público... coordinar eventos y conferencias de prensa para promover la marca......

LUXURY CUSTOMER SERVICE SPECIALIST
B2B Recursos Humanos

B2b recursos humanos select luxury customer service specialist for consolidated business group dedicated to providing services related to tourism, short term rentals and flexible accommodations... track all ota, direct, and agent leads, updating the pms as needed... freedom to put your own ideas into......

Digital Business Developer German And Dutch
Recruit4work SL

Strong written and oral business communication skills... relocation package a permanent presence of coaches who will facilitate your personal and professional development established a career path to grow within the project continuous training and certifications bi-weekly, monthly or quarterly......

Prácticas content specialist - holandés
Rankia s.l

Nivel avanzado/nativo de holandés... interés por el sector de los mercados financieros... otros datos del puesto posibilidad de realizar un contrato de prácticas de al menos 500h... crear los mejores contenidos para los blogs temáticos del área... gestionar el contenido relacionado a campañas de partners......