VP, Risk and Data Security, Protection, and Resilience
2 days ago
Queens
The Este Lauder Companies Inc. is one of the world's leading manufacturers, marketers, and sellers of quality skin care, makeup, fragrance, and hair care products, and is a steward of luxury and prestige brands globally. The company's products are sold in approximately 150 countries and territories under brand names including: Este Lauder, Aramis, Clinique, Lab Series, Origins, MAC, La Mer, Bobbi Brown Cosmetics, Aveda, Jo Malone London, Bumble and bumble, Darphin Paris, TOM FORD, Smashbox, AERIN Beauty, Le Labo, Editions de Parfums Frdric Malle, GLAMGLOW, KILIAN PARIS, Too Faced, Dr.Jart+, the DECIEM family of brands, including The Ordinary and NIOD, and BALMAIN Beauty. Do you want to be part of the team catalyzing digital innovation, harnessing the power of data, and transforming the fabric of security across the world's most prestigious beauty, skincare, and luxury fragrance brands? Then join our Risk Management and Data Security team in Enterprise Cybersecurity & Risk (ECR) at Este Lauder Companies (ELC). Our Risk Management and Data Protection team is responsible for identifying, assessing, and mitigating potential risks to the enterprise and our data. This small but important group actively governs these critical pillars of work, shapes our risk management strategies, finds mitigation strategies. They will lead three teams- (1) Strategic Risk Management and Reduction, (2) Supplier Security and Third Party Risk Management, and (3) Data Security including Data Protection and Classification, Data Resilience and Disaster Recovery, and Data Loss Prevention. Their teams will collaborate across security, technology and business functions and will help to directly fortify the organization against evolving risks. As the Vice President, Risk Management and Data Security, you will lead the company's approach to cybersecurity and technology risk management and securing our data in its various forms, in collaboration with data and analytics and data privacy. In this exciting new role, you will: • Lead and develop teams across technology risk, data protection, and security., • Establish governance forums for risk, security, and data protection decisions., • Partner with IT, Engineering, Legal, Compliance, and Product teams., • Translate technical and cyber risk into clear executive-level reporting., • Drive accountability without creating friction or unnecessary bureaucracy., • Drive consistent governance cadence with clear decision outcomes., • Have strong collaboration with technology and business leaders., • Maintain executive trust in risk and security reporting. Responsibilities: • Leading the ECR team and its technology stakeholders to reduce the risk of technology to the company by identifying and evaluating technology and cyber risks as they are identified. Risks related to but not limited to: Architecture, infrastructure, cloud, and applications Identity and access management Software development and DevSecOps Vulnerability management, technical debt, and configuration drift Third-party and supply chain technology risk Data Lakes and the cloud, • Overseeing risk assessments and data security and protection for: New and emerging technologies and platforms Cloud migrations and architecture changes High-risk vendors and service providers, • Defining risk appetite and tolerance in partnership with leadership, ongoing measurement and reporting on risk against thresholds, • Maintain a technology and cyber risk register with clear ownership and mitigation plans., • Overseeing and redefining the risk identification and risk management processes, • Responsible for reviewing risks through triage and evaluative score risk level and severity with a focus on defining a potential path for remediation, • Collaborating to define appropriate solutions to mitigate or remediate the risk by partnering with key stakeholders in ECR, IT, and the business, which will require consensus building and managing disagreements Technical Proficiency: • Cybersecurity Depth: Cybersecurity skills include exposure to multiple cybersecurity domains e.g. cybersecurity architecture, engineering, operations, IDAM., • Cyber attack framework: First-hand experience in cybersecurity attacks and controls and how one works against the other. Experience with industry cybersecurity best practices and domains, with a constant willingness to learn more. Understanding of the MITRE ATT&CK framework., • IT Proficiency: At least 2 years delivering in at least 1 domain of information technology such as networks, application development, and infrastructure. Basic SDLC knowledge to include engineering and deployment plans and review boards., • Risk Management: Experience with ServiceNow and eGRC tools and the Integrated Risk Modules within., • Data Governance, Loss Prevention and Insider Threat: Expertise in governing framework for DLP monitoring and configuration. Data discovery experience in, • Problem-Solving and Proactivity: Ability to identify opportunities for improvement and assist in the implementation of solutions. Initiative and autonomy in supporting ECR's strategic and operational goals., • Collaborative Mindset: Strong teamwork and community-building skills with the ability to collaborate effectively with cross-functional teams and stakeholders at various levels of seniority., • Administrative skill: Exposure to foundational data analytics. Basic Excel skills. Basic PowerPoint and Power BI Reporting., • Communication Skills: Ability to communicate effectively with both technical and non-technical stakeholders., • Adaptability and Flexibility: Ability to work in a dynamic environment and adapt to changing priorities., • Attention to Detail: Strong organizational skills and attention to detail in data analysis and reporting. Qualifications: • Bachelor's degree in Computer Science or Cybersecurity related field required, • Post-graduate work or thesis in Risk Management - preferred, • Minimum 15+ years relevant experience within Information or Cyber Security, • 8+ years experience serving specifically in Cybersecurity leadership roles, • Technical certification such as OSCP, CEH, CCSP, PenTest+, CISSP, SANS GIAC or equivalent to demonstrate technical proficiency - strongly preferred, • Must have hands on experience delivering in security capabilities and the technologies powering a security stack, as well as first-hand knowledge of what it takes to engineer and deliver on IT and security technologies and controls, • Must have experience in making security decisions, prioritization, and trade-offs based on risk, • Experience delivering in at least two of the three lines of defense, demonstrating an understanding of what it's like to be in the audit or owner seat., • Previous business management experience preferred, demonstrating effective senior stakeholder engagement and influence capability, • Demonstrated experience in analysis, data gathering, data collation and data interpretation, • Strong working knowledge of security frameworks, policies and industry standards, appropriate and secure functionality of infrastructure and applications, and experience in assessing and mitigating technology risk, • Strong understanding of and experience adhering to industry standards and frameworks such as NIST CSF, PCI, SOX, ISO/IEC 27001, NIST SP800, COBIT, ITIL, etc., • Ability to dive deeply into technical subject matter with IT and Security leadership and SMEs, influencing and leading change in the technical and process approaches in order to improve the security of the organization, • Ability to effectively communicate technical topics in the business language in order to drive successful outcomes for the organization Demonstration of leadership/management assignments, and prioritization of competing urgencies, • Broad experience in team management with a global and virtual capability, demonstrating strong leadership, influence and motivational skills with a known good reputation in both skillset and relationships in the security industry., • Deep experience in building and leading teams, identifying and developing cybersecurity talent, and driving operational excellence and effectiveness across security architecture, engineering and operations, • Track record in building and leading strong teams of thriving, motivated, skilled individuals, • Ability to lead and influence solution development in a complex and challenging environment, • Global experience that demonstrates effective engagement with a variety of stakeholders who have competing expectations and priorities, • Professional English fluency and presentation skills required, with the expectation to deliver orally and in writing to executive level audiences, • CISSP, CISM, CCSP, OCSP, or equivalent certification is preferred. Pay Range: The anticipated base salary range for this position is $221,600.00 to $377,200.00. Exact salary depends on several factors such as experience, skills, education, and budget. Salary range may vary based on geographic location. In addition to base salary, this position is eligible for participation in a highly competitive bonus program as well as participation in the share incentive plan. In addition, The Este Lauder Companies offers a variety of benefits to eligible employees, including health insurance coverage (medical, dental, and vision insurance), wellness and family support programs, life and disability insurance, retirement savings plans, paid leave programs, education-related programs,