VP, Risk and Data Security, Protection, and Resilience
Long Island, NY - USA
Job Summary
The Estée Lauder Companies Inc. is one of the worlds leading manufacturers marketers and sellers of quality skin care makeup fragrance and hair care products and is a steward of luxury and prestige brands globally. The companys products are sold in approximately 150 countries and territories under brand names including: Estée Lauder Aramis Clinique Lab Series Origins MAC La Mer Bobbi Brown Cosmetics Aveda Jo Malone London Bumble and bumble Darphin Paris TOM FORD Smashbox AERIN Beauty Le Labo Editions de Parfums Frédéric Malle GLAMGLOW KILIAN PARIS Too Faced the DECIEM family of brands including The Ordinary and NIOD and BALMAIN Beauty.
Who We Are
Do you want to be part of the team catalyzing digital innovation harnessing the power of data and transforming the fabric of security across the worlds mostprestigious beauty skincare and luxury fragrance brandsThen joinour Risk Managementand Data Securityteam in Enterprise Cybersecurity & Risk (ECR) at Estée Lauder Companies (ELC). OurRisk Managementand DataProtectionteamis responsible foridentifying assessing and mitigating potentialrisksto the enterpriseand our data. Thissmall but importantgroup activelygoverns these criticalpillarsof workshapesour risk managementstrategiesfindsmitigation strategies. They willlead three teams-(1) StrategicRiskManagement andReduction(2) Supplier Security andThird PartyRisk Management and(3)Data Security includingData Protection and ClassificationData Resilience and Disaster Recovery and Data Loss teams willcollaborateacross securitytechnologyand businessfunctions andwillhelp to directlyfortifythe organization against evolving risks.
WhatYoullDo
As theVice President Risk Managementand Data Securityyou willlead the companys approach to cybersecurity and technology risk managementand securingourdata in its various forms in collaboration withdata and analytics and data privacy.
In this exciting new role you will:
- Lead and develop teams across technology risk data protection and security.
- Establish governance forums for risk security and data protection decisions.
- Partner with IT Engineering Legal Compliance and Product teams.
- Translate technical and cyber risk into clear executive-level reporting.
- Drive accountability without creating friction or unnecessary bureaucracy.
- Drive consistent governance cadence with clear decision outcomes.
- Havestrong collaboration with technology and business leaders.
- Maintain executive trust in risk and security reporting.
Risk Management and Reduction:
This strategic function will not only oversee the traditional risk management and risk register functions but design and oversee the modernization of a risk management functionmeant to resolve and remediate risk not just track it. This is an expansion of the second line of defense ensuring risk is addressed in meaningful and prioritized ways.
You will help enable innovationfindingthe path forward for ourtechnologyinnovation and help the organization stay at thecutting edgewhile keeping security risk to a minimum through technical and resolution-focused risk management.
Our risk management function relies more on technical solutions and risk mitigation than most programs to modernize risk management and create more impact by the function.
You willseekto minimize overall security risk byidentifyingrisks monitoring requests throughapprovalworkflows providing risk scoring and presenting data to give a holistic view of the risk associated with risksidentifiedat the responsible forleadthe effort to find and execute the solution until remediated.
You must have strong technical and business acumen understanding the details behind and making decisions orinfluencingbased on risk. You must also lead the team in balancing thetradeoffs of having ultimate security and must be able to navigate countering perspectives setting priorities independentlyandleadingeffectivelytomanagethe expectations of our stakeholders andtechnical and business leadership.
- Define and own the enterprise data protection vision roadmap and operating model
- Serve as the executive authority on data risk data security and data lifecycle management
- Translate regulatory legal and business requirements into actionable data protection policies
- Build and lead a high-performing global data protection organization
- Define KPIs and dashboards for:
- Data risk posture
- Coverage of discovery and classification
- DLP effectiveness
- Remediation progress
- Regularly brief executive leadership and the board on data protection risks and progress
Data Governance and Policy:
- Establish and oversee enterprise data governance frameworks including:
- Data ownership and stewardship
- Data lifecycle management
- Data quality retention and disposition
- Partner with business and technology leaders to embed governance into day-to-day operations
- Ensure governance scales across cloud hybrid and multi-cloud environments
- Own the enterprise data classification strategy including:
- Sensitive data identification (PII PHI PCI IP regulated data)
- Labeling and tagging standards
- Implement and mature automated data discovery tools across:
- Endpoints
- SaaS applications
- Cloud storage
- Data lakes and warehouse
- Drive continuous discovery and remediation of exposed misused or over-retained data
Data Security and Data Loss Prevention:
- Design and oversee data security controls across:
- Data at rest in transit and in use
- Structured and unstructured data
- Lead enterprise DLP strategy and execution including:
- Endpoint network cloud and SaaS DLP
- Insider risk management
- Exfiltration prevention
- Partner with SOC and Security Operations on detection response and incident handling involving data exposure
Cloud and Data Lakes:
- Define standards for secure data management in cloud platforms (AWS Azure GCP)
- Ensure protection of data within:
- Cloud storage (S3 Blob GCS)
- Container security
- Data lakes
- Analytics platforms and AI/ML pipelines
- Implement controls for:
- Encryption and key management
- Access governance
- Data segmentation and isolation
- Cross-border data transfers
- Address emerging risks related to AI training data and model output
- Leadingthe ECR team and its technology stakeholders to reduce the risk of technology to the company byidentifyingand evaluating technology and cyber risks as they areidentified. Risks related to but not limited to:
- Architecture infrastructure cloud and applications
- Identity and access management
- Software development andDevSecOps
- Vulnerability management technical debtand configuration drift
- Third-party and supply chain technology risk
- Data Lakes and the cloud
- Overseeingrisk assessmentsand data security and protectionfor:
- New and emerging technologies and platforms
- Cloud migrations and architecture changes
- High-risk vendors and service providers
- Definingrisk appetite and tolerance in partnership with leadership ongoingmeasurementand reportingon risk againstthresholds
- Maintain a technology and cyber risk register with clear ownership and mitigation plans.
- Overseeingand redefining the risk identification and risk managementprocesses
- Responsible for reviewing risks through triage and evaluative score risk level and severity with a focus on defining a potential path for remediation
- Collaboratingto defineappropriate solutionsto mitigate or remediate the risk by partnering with key stakeholders in ECR IT and the business which will require consensus building and managing disagreements
- Enablingbalanced risk decisions by providing recommendations to leadership escalating based on severity and risk level to ensureappropriate cyberprotection capabilities and resiliency are built into the plans.
- Translatingtechnical risk into businessimpactand likelihood.
- Providingregular risk reporting to executive leadership.
- Definingandexecutethe data protection strategy focused on risk reduction.
- Establishingand enforcing:
- Data classificationand labeling
- Data handling and retention standards
- Access controls andleast-privilegeprinciples
- In all areas ofthe businessand in all technology platforms
- Partneringwith Privacy Legal and Compliance to ensure regulatory data protection requirements are met (e.g. GDPR CCPA/CPRA HIPAA PCI DSS).
- Overseeingand ensuringthe design and implementation of:
- Encryption at rest and in transit
- Data Loss Prevention (DLP) capabilities
- Monitoring of data access and movement throughout the enterprise
- Partneringwith Architecture and technology teams to ensureourZero trust framework ensuresdata isprotected at all times
- Helpinggovern the responseto data exposure and databreachincidentsboth internallyas well aswith third parties.
- CybersecurityDepth: Cybersecurity skills include exposure to multiple architecture engineering operations IDAM.
- Cyber attackframework: First-hand experiencein cybersecurity attacks and controls and how one works against the with industry cybersecuritybestpractices and domains with a constant willingness to learn ofthe MITRE ATT&CK framework.
- ITProficiency: At least 2 years delivering in at least 1 domain of information technology such asnetworks application development and infrastructure. Basic SDLC knowledge to include engineering and deployment plans and review boards.
- Risk Management:Experience withServiceNow andeGRCtools and the Integrated Risk Modules within.
- DataGovernanceLossPreventionand Insider Threat:Expertiseingoverningframework for DLP monitoring andconfiguration. Data discovery experience in
- Problem-Solving and Proactivity: Ability toidentifyopportunities for improvement andassistin the implementation of solutions. Initiative and autonomy in supporting ECRs strategic and operational goals.
- Collaborative Mindset: Strong teamwork and community-building skills with the ability to collaborate effectively with cross-functional teams and stakeholders at various levels of seniority.
- Administrative skill:Exposure tofoundational data analytics. Basic Excel skills. Basic PowerPointand Power BI Reporting.
- Communication Skills: Ability to communicate effectively with both technical and non-technical stakeholders.
- Adaptability and Flexibility: Ability to work in a dynamic environment and adapt to changing priorities.
- Attention to Detail: Strong organizational skills and attention to detail in data analysis and reporting.
- Bachelors degree in Computer Scienceor Cybersecurity related field required
- Post-graduate work or thesis in Risk Management - preferred
- Minimum15years relevant experience within Informationor Cyber Security
- 8years experienceservingspecificallyin Cybersecurity leadership roles
- Technical certification such as OSCP CEH CCSPPenTest CISSP SANS GIAC or equivalent todemonstratetechnicalproficiency -strongly preferred
- Must have hands on experiencedelivering insecurity capabilitiesand the technologies powering a security stack as well as first-hand knowledge of what it takes to engineer and deliver on IT and security technologies and controls
- Must have experience inmaking security decisions prioritization and trade-offs based on risk
- Experience delivering in at least two of the three lines of defensedemonstratingan understanding of whatitslike to be in the audit orownerseat.
- Previousbusiness management experience preferreddemonstratingeffective senior stakeholder engagement and influence capability
- Demonstrated experience in analysis data gathering data collation and data interpretation
- Strong working knowledge of security frameworks policies and industry standardsappropriateand secure functionality of infrastructure and applications and experience in assessing and mitigating technologyrisk
- Strong understanding of and experience adhering to industry standards and frameworks such asNIST CSFPCI SOX ISO/IEC 27001 NIST SP800 COBIT ITIL etc.
- Ability to dive deeply into technical subject matter with IT and Security leadership and SMEs influencing and leadingchangein the technical and process approachesin order toimprove the security of the organization
- Ability to effectively communicate technicaltopics inthe businesslanguagein order todrive successful outcomes for the organizationDemonstration of leadership/management assignments and prioritization of competing urgencies
- Broad experience in team management with a global and virtual capabilitydemonstratingstrong leadershipinfluenceand motivational skills with aknown goodreputationin both skillset and relationshipsin the security industry.
- Deep experience in building and leading teamsidentifyingand developing cybersecurity talent and driving operational excellence and effectiveness across security architectureengineeringand operations
- Track recordin building and leading strong teams ofthriving motivated skilled individuals
- Ability to lead andinfluence solution development in a complex and challenging environment
- Global experience thatdemonstrateseffective engagement with a variety of stakeholders who have competing expectations and priorities
- Professional English fluency and presentation skills required with the expectation to deliver orally and in writing to executive level audiences
- CISSP CISM CCSP OCSPorequivalent certification is preferred.
Pay Range:
The anticipated base salary range for this position is$221600.00 to $377200.00. Exact salary depends on several factors such as experience skills education and budget. Salary range may vary based on geographic addition to base salary this position is eligible for participation in a highly competitive bonus program as well as participation in the share incentive addition
In addition to base salary this position is eligible for participation in a highly competitive bonus program with the possibility for overachievement based on performance and company addition The Estée Lauder Companies offers a variety of benefits to eligible employees including health insurance coverage (medical dental and vision insurance) wellness and family support programs life and disability insurance retirement savings plans paid leave programs education-related programs paid holidays and vacation time and many others. Many of these benefits are subsidized or fully paid for by the company.
Equal Opportunity Employer
It is Companys policy not to discriminate against any employee or applicant for employment on the basis of race color creed religion national origin ancestry citizenship status age sex or gender (including pregnancy childbirth and related medical conditions) gender identity or gender expression (including transgender status) sexual orientation marital status military service and veteran status physical or mental disability protected medical condition as defined by applicable state or local law genetic information or any other characteristic protected by applicable federal state or local laws and ordinances. The Company will endeavor to provide a reasonable accommodation consistent with the law to otherwise qualified employees and prospective employees with a disability and to employees and prospective employees with needs related to their religious observance or practices. Should you wish to apply for this position or any other position with the Company and you believe you require assistance to complete an application or participate in an interview please contact
Michigan Applicants: Persons with disabilities needing accommodations for employment must notify the company in writing of the need for an accommodation within 182 days after the date the person with a disability knew or reasonably should have known that an accommodation was needed.
Philadelphia Applicants: Philadelphias Fair Chance Hiring Law
Rhode Island Applicants: The company is subject to chapters 29-38 of title 28 of the general laws of Rhode Island and is therefore covered by the states workers compensation law.
Required Experience:
Exec