Back to jobs

Senior Application Security Engineer - Customer Growth (f/m/d)

Senior Application Security Engineer ​​(f/m/d) - Customer Growth

In Decathlon Digital, Customer Growth provides best-in-class seamless customer identification and connection to the whole Decathlon ecosystem at a global scale.

We operate in 70+ countries and are responsible for 200M+ individual accounts across the World.

We are also responsible for developing customer 360 knowledge and leading the business through personalized experiences and recommendations.

The Customer Growth security team is looking for a Senior Application Security Engineer to join us in our lovely new Amsterdam office. The scope of this role is to enhance and maintain a high level of application security of the Identity (customer database) and Login (API authorization server + login workflow) products which are highly critical.

 

Your responsibilities

  • Provide hands-on support to business-critical digital products. You will be at the “fort door” of the Decathlon customer data and you want to help teams implement the best solution to solve problems on a global scale.

  • Analyze the findings identified by the security of tooling (SAST, SCA, CSPM, CWPP, monitoring, and WAF tools) in order to continuously (1) improve detection, (2) automate and scale up the prevention of these defects in a shift-left manner while (3) making teams more empowered to excel in their security practices.

  • Provide security expertise to the ongoing and upcoming security enhancements of account security: risk-based authentication, Passkeys, anti-bot management, and fraud prevention.

  • Analyze the reports raised by our Bug Bounty hunters. Forward the report to the right persons and suggest the best mitigation.

  • Stay at the forefront of cybersecurity trends and developments, continually expanding your knowledge and skills to adapt to evolving threats and technologies. We invest a lot in continuous skills development.

  • Identify and assess the risks related to application security and technical design choices. Lead this threat modeling approach to limit risks from appearing.

  • Data-driven approach: Set up and maintain the tools to ingest and provide dashboards from security-related data in order to best inform the empowered teams and the leadership team on the security situation and the outcome of the actions.

  • Adapt and contribute to the (pragmatic) application security guidelines definition (secure defaults, hardening configuration, use of identity federation, choice of dependencies, etc.).

  • Lead the organization of some security audits performed by external security audit firms.

  • Occasionally, help with security incident response.

  • Occasionally, assess the security of websites, API, code, CI/CD, or cloud configuration by performing security audits and security analysis.

 

What You Need to be Successful

  • We are looking for a passionate application security engineer with 4+ years of experience in development-related cybersecurity activities.

  • You have solid technical knowledge in a majority of the following areas: backend software security (preferably in Java/SpringBoot), frontend security, secure SDLC, CI/CD pipelines, and containers.

  • You have an experience with OAuth2 / OIDC protocols.

  • You have experience and a deep understanding of API management and API security.

  • You enjoy writing code and fixing code (following the best code management practices).

  • You enjoy working in a distributed team and with international colleagues present in several cities across several countries.

  • You have full professional proficiency in English.

  • You have strong problem-solving skills, excellent communication, and collaboration skills.

  • You are passionate about sports and you want to share your passion with a team of passionate people.

  • Being risk-based and working with a product mindset is your philosophy (not unconditionally chasing the last shiny thing).

 

About the tech

  • Security tooling: CSPM, CWPP, SAST, SCA, Cloudflare, Vault.
  • Monitoring and SIEM: Datadog, Splunk.Operating model: Best-in-class organization based on empowered product teams.
  • Backend: Java (Spring Boot), PostgreSQL, Kafka, Redis.
  • Full cloud: GCP, AWS.
  • CI/CD: GitHub Actions, Rancher, Helm, Flux.
  • Containers: Kubernetes, GKE
  • Collaboration tools: Slack, Google Workspace, Confluence.

Benefits

  • Hybrid and flexible work environment.
  • Hardware provided in accordance with your missions and our social commitments (Mac, Windows).
  • Skills development and mentoring (diversity of projects, technical certifications from the first year, internal and external training, etc.).
  • Remuneration package (monthly/quarterly bonuses)

 

 

DECATHLON DIGITAL CONTEXT 

What if technology allowed us to push the boundaries and take sports experiences to new levels? That's exactly our goal at Decathlon Digital! We are a team of 5,000+ experts in software engineering, product management, data, cloud, and cybersecurity, distributed across Paris, Lille, and Amsterdam. Together, we are creating the largest digital sports platform, leveraging tech innovation from design to value chain optimization, connected experiences and product second life.


Changing the game for good. We are in this for the love of sports. And like everything we love, we want it to last. That’s why we are embarking on a journey to create a more sustainable tech model, reducing our direct environmental impact while maintaining a safe, diverse, and inclusive space for all our people to learn and thrive together. Team up with us to design the digital future of sports.

Apply for this job

*

indicates a required field

Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Select...

RGPD : Lorsque vous postulez à une offre d'emploi sur ce site, les données personnelles concernant votre candidature seront collectées par Decathlon SE, (" Responsable du traitement "), qui est situé au 4 Boulevard de Mons 59650 Villeneuve d'Ascq. Vos données personnelles seront traitées aux fins de la gestion des activités de recrutement du Responsable du traitement. Vos données personnelles seront conservées par Decathlon SE pendant la durée nécessaire à l'évaluation de votre candidature à un emploi sans que cette durée n'excède 2 ans. 

 

  • Vous disposez du droit d'accéder à vos données personnelles, de demander qu'elles soient rectifiées, effacées, et de demander que leur traitement soit limité.
  • Vous disposez également du droit de demander leur portabilité.
  • Vous pouvez accéder à ces droits en cliquant ici.
  • Par ailleurs, vous pouvez également consulter notre politique de confidentialité pour plus d'informations sur les traitements effectués.

 

GDPR : When you apply to a job on this site, the personal data contained in your application will be collected by Decathlon SE, (“Controller”), which is located at 4 Boulevard de Mons 59650 Villeneuve d'Ascq.  Your personal data will be processed for the purposes of managing Controller’s recruitment related activities. Your personal data will be retained by Controller as long as Controller determines it is necessary to evaluate your application for employment but for no longer than 2 years. 

 

  • You have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted.
  • You also have the right to data portability. You can request these rights by clicking here. 
  • In addition, you can also visit our privacy policy for more information on the processing carried out.

Diversity & non discrimination policy / Politique de diversité et de non discrimination

As part of our diversity and non-discrimination policy, Decathlon Digital wants to ensure that gender, disability, or age of our candidates are not a factor in our decision. If you wish, we suggest that you provide us with this information. This data will be anonymized and used in the macro analysis of the diversity of applications received. This information will be kept separate from your application and will have no effect on its processing.

___________________

Dans le cadre de sa politique de diversité et de non discrimination, Decathlon Digital souhaite s'assurer que le genre, le handicap, ou l'âge de nos candidat·e·s ne sont pas des facteurs de décision. Si tu le souhaites, nous te proposons de nous indiquer ces informations. Ces données seront anonymisées et utilisées dans l'analyse macro de la diversité des candidatures reçues. Ces informations seront séparées de ta candidature et n'auront donc aucun effet sur le traitement de celle-ci.

Select...
Select...
Select...