Senior Analyst, Tech GRC M&A
Long Island, NY - USA
Job Summary
The Estée Lauder Companies Inc. is one of the worlds leading manufacturers marketers and sellers of quality skin care makeup fragrance and hair care products and is a steward of luxury and prestige brands globally. The companys products are sold in approximately 150 countries and territories under brand names including: Estée Lauder Aramis Clinique Lab Series Origins MAC La Mer Bobbi Brown Cosmetics Aveda Jo Malone London Bumble and bumble Darphin Paris TOM FORD Smashbox AERIN Beauty Le Labo Editions de Parfums Frédéric Malle GLAMGLOW KILIAN PARIS Too Faced the DECIEM family of brands including The Ordinary and NIOD and BALMAIN Beauty.
This role will support the evangelization of an application security strategy under the direction of the Global Head of Application Security in support of ELCs strategic and tactical initiatives in application modernization DevSecOps artificial intelligence & robotics multicloud adoption and multisite application development. This position will directly contribute to the overall global security of ELCs applications under the direction of the Global Head of Application Security. This candidate will primarily be focused on ensuring security is built into the Software Development Life Cycle and the delivery of trusted products and services to our clients partners and ELC IT/Security associates.
These responsibilities will be fulfilled by performing application security tests developing and providing secure source code consultation services and assisting the development communities with selfservice tools. A person in this position will work within a diverse and geographically disperse team as well as act as a coach and mentor for developing the skill sets of junior team members.
Must have excellent track record and proven ability to produce effective innovative solutions at an enterprise scale. Must be constantly evaluating the evolving security application and technology industries to be on top of the latest innovations and process refinements making recommendations and influencing adoption by IT ECR and the broader ELC community.
Main duties:
- Review current security processes used in our Software Engineering teams & develop optimization strategies.
- Work with the development teams to coordinate and perform vulnerability assessments through the use of automated and manual tools.
- Provide consulting & mentoring expertise to our Developers DevOps and Software Engineering teams in a dynamic environment to promote and implement the DevSecOps program across our organization.
- Ability to review and analyze vulnerability data to identify security risks to the organizations network infrastructure and applications and determine any reported vulnerabilities that are false positives.
- Provide the expertise to prepare security vulnerability and risk management reports for management and other key stakeholders.
- Ensure we deploy best practice Cloud Configuration and Security Management tools and processes into our Software Engineering teams.
- Provide leadership and teaming skills to coordinate remediation of vulnerabilities within established timeframes.
- Experience operating in agile development processes and integrating secure development practices into these models.
- Excellent programming and scripting skills in languages such as C# C/C Java JavaScript PowerShell Python etc.
- Experience with APIs: REST SOAP SOA and other integrations
- Formal training in the primary development toolset: Tools Code Application Engine SQL/DB Security
- Good knowledge and understanding of application security vulnerabilities (SANS OWASP).
- Knowledge of Threat modelling and risk analysis.
- Candidate should be very thorough in internet technologies and highly versed with web development best practices.
- Strong analytical/problem solving skills and cross functional knowledge across multiple development and security disciplines.
- Understanding of Test Automation tools and frameworks such as SAST DAST IAST.
- Ability to communicate securityrelated concepts to a broad range of technical and nontechnical staff.
- Must possess a high degree of integrity be trustworthy and have the ability to lead and inspire change.
- Previous software engineering/architecture experience (Java C#.Net JavaScript) preferred.
- Understanding CI/CD pipelines covering source control integration and deployment (ex: Bitbucket Jenkins JIRA Artifactory Nexus git).
- Knowledge in securing cloud deployment and containers (familiarity with Ansible DeMisto Docker and/or Kubernetes).
- Some experience with development of RESTful and SOAP web services preferred.
- Understanding of advanced iterative Agile methodologies.
- Familiarity with micro services architecture and design Patterns.
Pay Range:
The anticipated base salary range for this position is $90450.00to $135000.00.Exact salary depends on several factors such as experience skills education and budget. Salary range may vary based on geographic addition to base salary this position is eligible for participation in a highly competitive bonus program with the possibility for overachievement based on performance and company results.
In addition The Estée Lauder Companies offers a variety of benefits to eligible employees including health insurance coverage (medical dental and vision insurance) wellness and family support programs life and disability insurance retirement savings plans paid leave programs education-related programs paid holidays and vacation time and many others. Many of these benefits are subsidized or fully paid for by the company.
Equal Opportunity Employer
It is Companys policy not to discriminate against any employee or applicant for employment on the basis of race color creed religion national origin ancestry citizenship status age sex or gender (including pregnancy childbirth and related medical conditions) gender identity or gender expression (including transgender status) sexual orientation marital status military service and veteran status physical or mental disability protected medical condition as defined by applicable state or local law genetic information or any other characteristic protected by applicable federal state or local laws and ordinances. The Company will endeavor to provide a reasonable accommodation consistent with the law to otherwise qualified employees and prospective employees with a disability and to employees and prospective employees with needs related to their religious observance or practices. Should you wish to apply for this position or any other position with the Company and you believe you require assistance to complete an application or participate in an interview please contact
Michigan Applicants: Persons with disabilities needing accommodations for employment must notify the company in writing of the need for an accommodation within 182 days after the date the person with a disability knew or reasonably should have known that an accommodation was needed.
Philadelphia Applicants: Philadelphias Fair Chance Hiring Law
Rhode Island Applicants: The company is subject to chapters 29-38 of title 28 of the general laws of Rhode Island and is therefore covered by the states workers compensation law.
Required Experience:
Senior IC