Security Specialist
Lane Crawford is an internationally renowned luxury department store with over 170 years of success, delivering an exceptional and eclectic product curation with dynamic Asian spirit and values. As the Security Specialist, you will play a vital role in safeguarding Lane Crawford's assets and information by implementing robust security measures and protocols. Your expertise will contribute to creating a secure environment for both our customers and staff, enhancing overall business resilience.
The Role
- Implement and oversee security compliance initiatives, ensuring adherence to industry standards and best practices such as OWASP, PCI DSS, CIS benchmarks, and well-architecture frameworks.
- Conduct regular security assessments and vulnerability scans to identify and mitigate risks within the infrastructure and applications.
- Collaborate with development and operations teams to integrate security practices into the software development lifecycle (SDLC) and CI/CD pipelines.
- Implement security controls, including access controls, authentication mechanisms, encryption, and secure configuration management.
- Monitor and respond to security incidents, conducting root cause analysis and implementing remediation actions.
- Develop and maintain security policies, procedures, and documentation to ensure compliance with relevant standards and regulations.
- Participate in security audits and assessments, providing necessary documentation and evidence.
- Stay up to date with emerging security threats, vulnerabilities, and industry trends, and provide recommendations for risk mitigation.
- Conduct security training and awareness programs for development and operations teams to promote a security-first mindset.
- Collaborate with cross-functional teams to implement security-focused automation and infrastructure-as-code practices.
- Support incident response efforts, including forensic investigations, evidence gathering, and reporting.
The Ideal Candidate
- Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent work experience).
- Solid understanding of security compliance frameworks and standards, such as OWASP, PCI DSS, CIS benchmarks, and well-architecture frameworks.
- Experience implementing security controls and best practices in a DevSecOps environment
- Familiarity with secure coding practices and security testing techniques.
- Knowledge of cloud security principles and experience working with cloud service providers (e.g., AlibabaCloud, AWS, Azure).
- Proficiency in scripting and automation tools (e.g., Terraform, Bash, Ansible) to develop security-focused automation.
- Understanding vulnerability management, threat modeling, and risk assessment methodologies.
- Experience with security incident response and incident handling procedures.
- Strong knowledge of network and web application security principles.
- Excellent problem-solving and analytical skills to identify and mitigate security risks.
- Strong communication and collaboration skills to work effectively with cross-functional teams.
- Relevant certifications such as Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), or Certified Cloud Security Professional (CCSP) are a plus
Benefits
At Lane Crawford you work hard and play hard while we take care of your wellbeing. Your annual holiday leave is supplemented by special leave for birthday and work anniversaries, time off to celebrate key holidays and Summer Fridays. Our enhanced medical, dental, pension benefits and life insurance give you peace of mind. And it’s true, that all our permanent staff can enjoy staff discount and visit our legendary staff sales! You can develop your skills and knowledge on the job supported by curated learning experiences at The Academy, and have the opportunity to work with, and be exposed to, a team of internationally minded professionals who will support and stretch your career development. We offer staff wellness programmes to nurture mind, body and spirit in our head office and stores. We treasure opportunities to come together, whether it’s at an office Happy Hour, networking in the "Gin Den" or our Talk of The Town Staff Parties.
Personal data provided will be used for recruitment purposes only. By applying for this position, you consent to the collection, use and disclosure of your personal data to Lane Crawford Joyce Group. Your personal data will be processed in accordance with our Privacy Policy.