Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

VP, Risk and Data Security, Protection, and Resilience

$221.6k - $377.2k

Estée Lauder

The Estée Lauder Companies Inc. is one of the world’s leading manufacturers, marketers, and sellers of quality skin care, makeup, fragrance, and hair care products, and is a steward of luxury and prestige brands globally. The company’s products are sold in approximately 150 countries and territories under brand names including: Estée Lauder, Aramis, Clinique, Lab Series, Origins, M·A·C, La Mer, Bobbi Brown Cosmetics, Aveda, Jo Malone London, Bumble and bumble, Darphin Paris, TOM FORD, Smashbox, AERIN Beauty, Le Labo, Editions de Parfums Frédéric Malle, GLAMGLOW, KILIAN PARIS, Too Faced, Dr.Jart+, the DECIEM family of brands, including The Ordinary and NIOD, and BALMAIN Beauty.DescriptionWho We AreDo you want to be part of the team catalyzing digital innovation, harnessing the power of data, and transforming the fabric of security across the world’s most prestigious beauty, skincare, and luxury fragrance brands? Then join our Risk Management and Data Security team in Enterprise Cybersecurity & Risk (ECR) at Estée Lauder Companies (ELC). Our Risk Management and Data Protection team is responsible for identifying, assessing, and mitigating potential risks to the enterprise and our data. This small but important group actively governs these critical pillars of work, shapes our risk management strategies, finds mitigation strategies. They will lead three teams- (1) Strategic Risk Management and Reduction, (2) Supplier Security and Third Party Risk Management, and (3) Data Security including Data Protection and Classification, Data Resilience and Disaster Recovery, and Data Loss Prevention.  Their teams will collaborate across security, technology and business functions and will help to directly fortify the organization against evolving risks.What You’ll DoAs the Vice President, Risk Management and Data Security, you will lead the company’s approach to cybersecurity and technology risk management and securing our data in its various forms, in collaboration with data and analytics and data privacy.In this exciting new role, you will:  Lead and develop teams across technology risk, data protection, and security.  Establish governance forums for risk, security, and data protection decisions.  Partner with IT, Engineering, Legal, Compliance, and Product teams.  Translate technical and cyber risk into clear executive-level reporting.  Drive accountability without creating friction or unnecessary bureaucracy.  Drive consistent governance cadence with clear decision outcomes.  Have strong collaboration with technology and business leaders.  Maintain executive trust in risk and security reporting.  Risk Management and Reduction:  This strategic function will not only oversee the traditional risk management and risk register functions, but design and oversee the modernization of a risk management function meant to resolve and remediate risk, not just track it. This is an expansion of the “second line of defense” ensuring risk is addressed in meaningful and prioritized ways.You will help enable innovation, finding the path forward for our technology innovation and help the organization stay at the cutting edge while keeping security risk to a minimum through technical and resolution-focused risk management.Our risk management function relies more on technical solutions and risk mitigation than most programs, to modernize risk management and create more impact by the function.  You will seek to minimize overall security risk by identifying risks, monitoring requests through approval workflows, providing risk scoring, and presenting data to give a holistic view of the risk associated with risks identified at the company.  Then be responsible for lead the effort to find and execute the solution until remediated.You must have strong technical and business acumen, understanding the details behind and making decisions or influencing based on risk. You must also lead the team in balancing the tradeoffs of having ultimate security and running the business.  You must be able to navigate countering perspectives, setting priorities independently, and leading effectively to manage the expectations of our stakeholders and technical and business leadership. Data Protection and Security:Define and own the enterprise data protection vision, roadmap, and operating model  Serve as the executive authority on data risk, data security, and data lifecycle management  Translate regulatory, legal, and business requirements into actionable data protection policies  Build and lead a high-performing global data protection organization  Define KPIs and dashboards for:  Data risk posture  Coverage of discovery and classification  DLP effectiveness  Remediation progress  Regularly brief executive leadership and the board on data protection risks and progressData Governance and Policy:Establish and oversee enterprise data governance frameworks, including: Data ownership and stewardship  Data lifecycle management  Data quality, retention, and disposition  Partner with business and technology leaders to embed governance into day-to-day operationsEnsure governance scales across cloud, hybrid, and multi-cloud environments  Data Classification and Discovery: Own the enterprise data classification strategy, including:Sensitive data identification (PII, PHI, PCI, IP, regulated data)Labeling and tagging standardsImplement and mature automated data discovery tools across:EndpointsSaaS applicationsCloud storageData lakes and warehouseDrive continuous discovery and remediation of exposed, misused, or over-retained dataData Security and Data Loss Prevention:Design and oversee data security controls across:Data at rest, in transit, and in useStructured and unstructured dataLead enterprise DLP strategy and execution, including:Endpoint, network, cloud, and SaaS DLPInsider risk managementExfiltration preventionPartner with SOC and Security Operations on detection, response, and incident handling involving data exposure  Cloud and Data Lakes:Define standards for secure data management in cloud platforms (AWS, Azure, GCP)Ensure protection of data within:Cloud storage (S3, Blob, GCS)Container securityData lakesAnalytics platforms and AI/ML pipelinesImplement controls for:Encryption and key managementAccess governanceData segmentation and isolationCross-border data transfersAddress emerging risks related to AI training data and model outputResponsibilitiesLeading the ECR team and its technology stakeholders to reduce the risk of technology to the company by identifying and evaluating technology and cyber risks as they are identified. Risks related to but not limited to:Architecture, infrastructure, cloud, and applicationsIdentity and access managementSoftware development and DevSecOpsVulnerability management, technical debt, and configuration driftThird-party and supply chain technology riskData Lakes and the cloudOverseeing risk assessments and data security and protection for:New and emerging technologies and platformsCloud migrations and architecture changesHigh-risk vendors and service providersDefining risk appetite and tolerance in partnership with leadership, ongoing measurement and reporting on risk against thresholdsMaintain a technology and cyber risk register with clear ownership and mitigation plans.Overseeing and redefining the risk identification and risk management processesResponsible for reviewing risks through triage and evaluative score risk level and severity with a focus on defining a potential path for remediationCollaborating to define appropriate solutions to mitigate or remediate the risk by partnering with key stakeholders in ECR, IT, and the business, which will require consensus building and managing disagreements   Responsibilities ContdEnabling balanced risk decisions by providing recommendations to leadership, escalating based on severity and risk level to ensure appropriate cyber protection capabilities and resiliency are built into the plans.Translating technical risk into business impact and likelihood.Providing regular risk reporting to executive leadership.Defining and execute the data protection strategy focused on risk reduction.Establishing and enforcing:Data classification and labelingData handling and retention standardsAccess controls and least-privilege principlesIn all areas of the business and in all technology platformsPartnering with Privacy, Legal, and Compliance to ensure regulatory data protection requirements are met (e.g., GDPR, CCPA/CPRA, HIPAA, PCI DSS).Overseeing and ensuring the design and implementation of:Encryption at rest and in transitData Loss Prevention (DLP) capabilitiesMonitoring of data access and movement throughout the enterprisePartnering with Architecture and technology teams to ensure our Zero trust framework ensures data is protected at all timesHelping govern the response to data exposure and data breach incidents both internally as well as with third parties.Technical Proficiency:Cybersecurity Depth: Cybersecurity skills include exposure to multiple cybersecurity domains e.g. cybersecurity architecture, engineering, operations, IDAM.Cyber attack framework: First-hand experience in cybersecurity attacks and controls and how one works against the other.  Experience with industry cybersecurity best practices and domains, with a constant willingness to learn more. Understanding of the MITRE ATT&CK framework. IT Proficiency: At least 2 years delivering in at least 1 domain of information technology such as networks, application development, and infrastructure. Basic SDLC knowledge to include engineering and deployment plans and review boards.Risk Management: Experience with ServiceNow and eGRC tools and the Integrated Risk Modules within.Data Governance, Loss Prevention and Insider Threat: Expertise in governing framework for DLP monitoring and configuration. Data discovery experience inProblem-Solving and Proactivity: Ability to identify opportunities for improvement and assist in the implementation of solutions. Initiative and autonomy in supporting ECR’s strategic and operational goals.Collaborative Mindset: Strong teamwork and community-building skills with the ability to collaborate effectively with cross-functional teams and stakeholders at various levels of seniority. Administrative skill: Exposure to foundational data analytics. Basic Excel skills. Basic PowerPoint and Power BI Reporting.Communication Skills: Ability to communicate effectively with both technical and non-technical stakeholders.Adaptability and Flexibility: Ability to work in a dynamic environment and adapt to changing priorities.Attention to Detail: Strong organizational skills and attention to detail in data analysis and reporting.  QualificationsBachelor’s degree in Computer Science or Cybersecurity related field – requiredPost-graduate work or thesis in Risk Management - preferredMinimum 15+ years relevant experience within Information or Cyber Security8+ years experience serving specifically in Cybersecurity leadership rolesTechnical certification such as OSCP, CEH, CCSP, PenTest+, CISSP, SANS GIAC or equivalent to demonstrate technical proficiency  - strongly preferredMust have hands on experience delivering in security capabilities and the technologies powering a security stack, as well as first-hand knowledge of what it takes to engineer and deliver on IT and security technologies and controlsMust have experience in making security decisions, prioritization, and trade-offs based on risk Experience delivering in at least two of the three lines of defense, demonstrating an understanding of what it’s like to be in the audit or owner seat.Previous business management experience preferred, demonstrating effective senior stakeholder engagement and influence capabilityDemonstrated experience in analysis, data gathering, data collation and data interpretationStrong working knowledge of security frameworks, policies and industry standards, appropriate and secure functionality of infrastructure and applications, and experience in assessing and mitigating technology riskStrong understanding of and experience adhering to industry standards and frameworks such as NIST CSF, PCI, SOX, ISO/IEC 27001, NIST SP800, COBIT, ITIL, etc.Ability to dive deeply into technical subject matter with IT and Security leadership and SMEs, influencing and leading change in the technical and process approaches in order to improve the security of the organizationAbility to effectively communicate technical topics in the business language in order to drive successful outcomes for the organizationDemonstration of leadership/management assignments, and prioritization of competing urgenciesBroad experience in team management with a global and virtual capability, demonstrating strong leadership, influence and motivational skills with a known good reputation in both skillset and relationships in the security industry.Deep experience in building and leading teams, identifying and developing cybersecurity talent, and driving operational excellence and effectiveness across security architecture, engineering and operationsTrack record in building and leading strong teams of thriving, motivated, skilled individuals Ability to lead and influence solution development in a complex and challenging environment Global experience that demonstrates effective engagement with a variety of stakeholders who have competing expectations and prioritiesProfessional English fluency and presentation skills required, with the expectation to deliver orally and in writing to executive level audiencesCISSP, CISM, CCSP, OCSP, or equivalent certification is preferred.    Pay Range:The anticipated base salary range for this position is $221,600.00 to $377,200.00. Exact salary depends on several factors such as experience, skills, education, and budget. Salary range may vary based on geographic location. In addition to base salary, this position is eligible for participation in a highly competitive bonus program as well as participation in the share incentive plan. In addition,In addition to base salary, this position is eligible for participation in a highly competitive bonus program with the possibility for overachievement based on performance and company results. In addition, The Estée Lauder Companies offers a variety of benefits to eligible employees, including health insurance coverage (medical, dental, and vision insurance), wellness and family support programs, life and disability insurance, retirement savings plans, paid leave programs, education-related programs, paid holidays and vacation time, and many others. Many of these benefits are subsidized or fully paid for by the company.Equal Opportunity EmployerIt is Company's policy not to discriminate against any employee or applicant for employment on the basis of race, color, creed, religion, national origin, ancestry, citizenship status, age, sex or gender (including pregnancy, childbirth and related medical conditions), gender identity or gender expression (including transgender status), sexual orientation, marital status, military service and veteran status, physical or mental disability, protected medical condition as defined by applicable state or local law, genetic information, or any other characteristic protected by applicable federal, state, or local laws and ordinances. The Company will endeavor to provide a reasonable accommodation consistent with the law to otherwise qualified employees and prospective employees with a disability and to employees and prospective employees with needs related to their religious observance or practices. Should you wish to apply for this position or any other position with the Company and you believe you require assistance to complete an application or participate in an interview, please contact View email address on click.appcast.io Applicants: Persons with disabilities needing accommodations for employment must notify the company in writing of the need for an accommodation within 182 days after the date the person with a disability knew or reasonably should have known that an accommodation was needed.Philadelphia Applicants: Philadelphia's Fair Chance Hiring LawRhode Island Applicants: The company is subject to chapters 29-38 of title 28 of the general laws of Rhode Island and is therefore covered by the state's workers' compensation law.Brand:Estée Lauder CompaniesJob Function:Information TechnologyJob Sub-Function:Security & ComplianceAssignment Category:Fulltime-RegularDepartment:Information Technology

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the VP, Risk and Data Security, Protection, and Resilience in Long Island City, NY vacancy
  • $121 - $194 per hour

     ...details.EXPERIENCE5-7 year of experience in data security and protectionMust have experience with...  ...and mitigating data security risks through continuous monitoring and evaluation...  ...data security strategiesKnowledge of data protection and data loss prevention (DLP)... 
    Risk
    Full time
    Work at office
    Local area
    Remote work
    1 day per week

    MUFG

    Jersey City, NJ
    4 days ago
  • $127 per hour

     ...financial enterprise. The focus is on security, compliance, and operational...  ..., compliance standards, and data security.Lead development and...  ...of comprehensive data protection, security, and compliance measures...  ...work with Internal Audit and Risk teams to provide evidence of controls... 
    Risk
    Full time
    Work at office
    Local area
    Remote work
    1 day per week

    MUFG

    Jersey City, NJ
    2 days ago
  •  ...Administrative Office - Chief Data & Analytics Office and help shape...  ..., Analytics, Operations, and Risk and Control functions. Your...  ...data quality, integrity, and security, while supporting innovation and...  ...data lifecycle, including data protection, privacy, retention,... 
    Risk
    Work at office

    JP Morgan Chase

    Jersey City, NJ
    1 day ago
  • $149 per hour

     ...engineering, integration, data, cloud, security, and platform modernization...  ...deliver secure, scalable, and resilient solutions. Expertise in...  ...delivery teams, reduce technology risk, and accelerate the...  ...ancestry, marital status, protected veteran and military status... 
    Risk
    Full time
    Work at office
    Local area
    Remote work
    1 day per week

    MUFG

    Jersey City, NJ
    3 days ago
  • $134.5k - $265.1k

    Position Summary Tech Resilience Manager Lead complex...  ...on continuity, recovery, and risk priorities. This is an opportunity...  ...network, storage, database, and data protection technologies, with...  ...Information Systems, Cyber Security, or equivalent demonstrated... 
    Risk
    Local area
    Visa sponsorship

    Deloitte

    Jersey City, NJ
    5 days ago
  • $105.4k - $207.8k

     ...Senior Consultant - Technology Resilience Accelerate your career as a...  ...stakeholders to address risk, continuity, and recovery priorities...  ..., storage, database, and data protection technologies, with...  ...Information Systems, Cyber Security, or equivalent demonstrated... 
    Risk
    Local area
    Visa sponsorship

    Deloitte

    Jersey City, NJ
    4 days ago
  • $134.5k - $265.1k

     ...Summary Cyber Defense & Resilience - Insider Risk Manager Are you interested...  ...place for you. Traditional security and integrated risk...  ...Entity Behavior Analytics, and Data Loss Prevention capabilities...  ...investigations, compliance, data protection, or enterprise risk... 
    Risk
    Local area
    Visa sponsorship

    Deloitte

    Jersey City, NJ
    5 days ago
  • $169.54k - $195k

     ...including banking, leasing, securities, credit cards, and consumer finance...  ..., and development of the data platform, beginning with the...  ...Equities reference, operational and risk data; ETL/ELT streaming and...  ...Azure event hub; Dev Ops and Resiliency Management; and build... 
    Risk
    Full time
    Work at office
    Local area
    Remote work
    Work from home
    Worldwide

    Sumitomo Mitsui Banking Corporation

    Jersey City, NJ
    3 days ago
  •  ...Overview:MUFG is seeking a highly motivated Security Data Architect & Governance person to be part...  ...to understand security risks and controls, to analyze various methods...  ...identity, sex, age, ancestry, marital status, protected veteran and military status, disability,... 
    Risk
    Full time
    Work experience placement
    Work at office
    Local area
    Remote work

    MUFG

    Jersey City, NJ
    3 days ago
  • Join the Data Protection Management and Governance team and help ensure the organization meets data...  ...years of relevant experience in data risk management, data protection, or data access...  ...of key principles of cyber security, including encryption, network security,... 
    Risk

    JP Morgan Chase

    Jersey City, NJ
    3 days ago
  • $165k - $205k

     ...enterprise migration from Atlassian Data Center to Atlassian Cloud. You...  ...Confluence, setting standards, managing risk, and ensuring the platform scales securely and reliably across the...  ...sex, age, ancestry, marital status, protected veteran and military status, disability... 
    Risk
    Full time
    Work at office
    Local area
    Remote work
    1 day per week

    MUFG

    Jersey City, NJ
    2 days ago
  •  ...receive an alert: Create Alert NTT DATA strives to hire exceptional,...  ...are currently seeking a Cyber Risk Consultant to join our team in...  ..., Business Information Security Office (BISO) operations, and...  ...architectures, AI security risks, data protection considerations, and AI risk... 
    Risk
    Work at office

    NTT DATA

    Brooklyn, NY
    3 days ago
  •  ...Sr Information Security Analyst - Insider Risk The Insider Risk Analyst supports Regeneron's insider risk capability within the Global Data Protection & AI Security pillar, working alongside the Insider Risk & IP Protection lead. The role focuses on insider data risk,... 
    Risk

    Relha LLC

    Brooklyn, NY
    5 days ago
  •  ...workplace that looks like the world that we serve.Our Risk Management teams work to protect the safety and soundness of our systems and are responsible...  ...Impact you will have in this role:Operational Risk and Resilience protects the firm’s interests by fostering a consistent... 
    Risk
    Remote work
    Flexible hours

    DTCC- The Depository Trust & Clearing Corporation

    Jersey City, NJ
    4 days ago
  •  ...Technology group delivers secure, reliable technology...  ...needs and implementing data standards and governance...  ...AI‑focused data protection. This will include policies...  ...AI policy targeting and risk prioritization. Documentation...  ..., bringing enhanced resilience and soundness to... 
    Risk
    Remote work
    Flexible hours

    DTCC- The Depository Trust & Clearing Corporation

    Jersey City, NJ
    5 days ago
  • $177k - $266k

     ...efficiency, effectiveness, and resilience of Medline customer’s end-to-...  ...improvement initiatives. Risk Management Develop and implement...  ..., such as automation, data analytics, AI, and other customer...  ...disability, neurodivergence, protected veteran status, marital or family... 
    Risk
    Minimum wage
    Work experience placement
    Local area
    Worldwide

    Medline

    Brooklyn, NY
    3 days ago
  •  ...experienced Modern Infrastructure and Security Architect, Vice President who...  ...about enabling secure, resilient, and scalable technology...  ...architects, engineering leads, and risk stakeholders to identify,...  ...age, ancestry, marital status, protected veteran and military status,... 
    Risk
    Full time
    Work at office
    Local area
    Remote work

    MUFG

    Jersey City, NJ
    5 days ago
  • $134.5k - $265.1k

     ...enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this...  ...Manager on the Cloud Cyber Risk team, you will be responsible...  ...security, container security, data protection, monitoring, and secure deliveryArchitecting... 
    Risk
    Local area
    Visa sponsorship

    Deloitte

    Jersey City, NJ
    2 days ago
  • $82.6k - $162.8k

     ...principles to practices: risk tiering, model and...  ...models, agents, tools, data sources, and integrations...  ...across privacy, security, model risk, and misuse...  ...assessments, and data protection impact assessments.Experience...  ...testing, jailbreak resilience, hallucination... 
    Risk
    Local area
    Visa sponsorship

    Deloitte

    Jersey City, NJ
    5 days ago
  • $82.6k - $162.8k

     ...clients to operate with resilience, grow with confidence,...  ...proactively manage to secure success.Recruiting for...  ...AI on the Cloud Cyber Risk team, you will be responsible...  ..., resilience, and data protectionPerforming cloud...  ...native application protection platform (CNAPP), cloud... 
    Risk
    Local area
    Visa sponsorship

    Deloitte

    Jersey City, NJ
    4 days ago
  • $134.5k - $265.1k

     ...enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this...  ...on strategic and practical data protection and encryption requirements based on new and emerging data risks.Advising clients on encryption... 
    Risk
    Local area

    Deloitte

    Jersey City, NJ
    2 days ago
  •  ...Description Be Part Of A High-Performing Data Protection Team: Join a global financial...  ...is an opportunity to work alongside data security leaders, governance SMEs, and technology...  ...teams to enhance the organization’s data risk posture while supporting both U.S. and Japan... 
    Risk

    Axiom Path

    Jersey City, NJ
    7 days ago
  • Jobtailor is seeking a senior resiliency leader to steer enterprise-wide recovery, continuity planning and disaster recovery programs. You...  ...and drive remediation progress at scale. You will analyze risk exposures, lead continuous improvement, and communicate complex... 
    Risk

    Jobtailor

    Brooklyn, NY
    4 days ago
  •  ...Technology group delivers secure, reliable technology...  ...needs and implementing data standards and governance...  ...at DTCC, the Data Protection Senior Asscociate supports...  ...make sound triage and risk decisions. Your Primary...  ...classes, bringing enhanced resilience and soundness to... 
    Risk
    Remote work
    Flexible hours

    DTCC- The Depository Trust & Clearing Corporation

    Jersey City, NJ
    5 days ago
  •  ...Technology group delivers secure, reliable technology...  ...needs and implementing data standards and governance...  ...RoleThe Senior Data Protection Analyst plays a critical...  ...reporting, audit evidence, and risk narratives accurately...  ..., bringing enhanced resilience and soundness to... 
    Risk
    Remote work
    Flexible hours

    DTCC- The Depository Trust & Clearing Corporation

    Jersey City, NJ
    1 day ago
  • $240k - $330k

     ...with knowledge of privacy and data governance, and emerging technology...  ...managing legal and regulatory risk in a highly dynamic, consumer-...  ...familiarity with global data protection frameworks (e.g., GDPR)...  ...standardsIdentify safety and security concerns, issues, incidents or... 
    Risk
    Temporary work
    Work at office
    Immediate start
    Remote work
    Flexible hours
    Night shift

    JetBlue Airways

    Long Island City, NY
    1 day ago
  • $93.5k - $182.85k

     ...the gold standard in cyber resilience. The company empowers...  ...from cyberattacks - keeping data safe and businesses resilient...  ...best-in-class data protection, exceptional data security, advanced data intelligence...  ...relied on Commvault to reduce risks, improve governance, and do... 
    Risk
    Full time
    Remote work

    Commvault

    Brooklyn, NY
    1 day ago
  • $160k - $200k

    VP, Strategic Initiatives Leadership Advisory | Full-Time | Remote...  ...flag delays, dependencies, risks, and items requiring escalation...  ...and priorities take hold. Data Analysis and Reporting Maintain...  ...confidentiality, integrity, and resilience in handling sensitive information... 
    Risk
    Full time
    Local area
    Remote work

    Council Advisors

    Brooklyn, NY
    1 day ago
  • Morgan Stanley is seeking a Risk professional at VP level to join the Cyber, Technology and Information Security Standards team in Alpharetta or Baltimore. The role focuses on independent 2LoD review of 1LoD standards and active governance participation, within a global... 
    Risk

    Koitecc Solutions

    Brooklyn, NY
    5 days ago
  • $118.7k - $218.6k

    Position Summary Cyber Data Protection and PKI Specialist - Senior...  ...enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this...  ...based on new and emerging data risks, advising on best practices... 
    Risk
    Work experience placement
    Local area
    Visa sponsorship

    Deloitte

    Jersey City, NJ
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to VP, Risk and Data Security, Protection, and Resilience. Be the first to apply!