Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

VP, Risk and Data Security, Protection, and Resilience

$221.6k - $377.2k

Estée Lauder

The Estée Lauder Companies Inc. is one of the world’s leading manufacturers, marketers, and sellers of quality skin care, makeup, fragrance, and hair care products, and is a steward of luxury and prestige brands globally. The company’s products are sold in approximately 150 countries and territories under brand names including: Estée Lauder, Aramis, Clinique, Lab Series, Origins, M·A·C, La Mer, Bobbi Brown Cosmetics, Aveda, Jo Malone London, Bumble and bumble, Darphin Paris, TOM FORD, Smashbox, AERIN Beauty, Le Labo, Editions de Parfums Frédéric Malle, GLAMGLOW, KILIAN PARIS, Too Faced, Dr.Jart+, the DECIEM family of brands, including The Ordinary and NIOD, and BALMAIN Beauty.DescriptionWho We AreDo you want to be part of the team catalyzing digital innovation, harnessing the power of data, and transforming the fabric of security across the world’s most prestigious beauty, skincare, and luxury fragrance brands? Then join our Risk Management and Data Security team in Enterprise Cybersecurity & Risk (ECR) at Estée Lauder Companies (ELC). Our Risk Management and Data Protection team is responsible for identifying, assessing, and mitigating potential risks to the enterprise and our data. This small but important group actively governs these critical pillars of work, shapes our risk management strategies, finds mitigation strategies. They will lead three teams- (1) Strategic Risk Management and Reduction, (2) Supplier Security and Third Party Risk Management, and (3) Data Security including Data Protection and Classification, Data Resilience and Disaster Recovery, and Data Loss Prevention.  Their teams will collaborate across security, technology and business functions and will help to directly fortify the organization against evolving risks.What You’ll DoAs the Vice President, Risk Management and Data Security, you will lead the company’s approach to cybersecurity and technology risk management and securing our data in its various forms, in collaboration with data and analytics and data privacy.In this exciting new role, you will:  Lead and develop teams across technology risk, data protection, and security.  Establish governance forums for risk, security, and data protection decisions.  Partner with IT, Engineering, Legal, Compliance, and Product teams.  Translate technical and cyber risk into clear executive-level reporting.  Drive accountability without creating friction or unnecessary bureaucracy.  Drive consistent governance cadence with clear decision outcomes.  Have strong collaboration with technology and business leaders.  Maintain executive trust in risk and security reporting.  Risk Management and Reduction:  This strategic function will not only oversee the traditional risk management and risk register functions, but design and oversee the modernization of a risk management function meant to resolve and remediate risk, not just track it. This is an expansion of the “second line of defense” ensuring risk is addressed in meaningful and prioritized ways.You will help enable innovation, finding the path forward for our technology innovation and help the organization stay at the cutting edge while keeping security risk to a minimum through technical and resolution-focused risk management.Our risk management function relies more on technical solutions and risk mitigation than most programs, to modernize risk management and create more impact by the function.  You will seek to minimize overall security risk by identifying risks, monitoring requests through approval workflows, providing risk scoring, and presenting data to give a holistic view of the risk associated with risks identified at the company.  Then be responsible for lead the effort to find and execute the solution until remediated.You must have strong technical and business acumen, understanding the details behind and making decisions or influencing based on risk. You must also lead the team in balancing the tradeoffs of having ultimate security and running the business.  You must be able to navigate countering perspectives, setting priorities independently, and leading effectively to manage the expectations of our stakeholders and technical and business leadership. Data Protection and Security:Define and own the enterprise data protection vision, roadmap, and operating model  Serve as the executive authority on data risk, data security, and data lifecycle management  Translate regulatory, legal, and business requirements into actionable data protection policies  Build and lead a high-performing global data protection organization  Define KPIs and dashboards for:  Data risk posture  Coverage of discovery and classification  DLP effectiveness  Remediation progress  Regularly brief executive leadership and the board on data protection risks and progressData Governance and Policy:Establish and oversee enterprise data governance frameworks, including: Data ownership and stewardship  Data lifecycle management  Data quality, retention, and disposition  Partner with business and technology leaders to embed governance into day-to-day operationsEnsure governance scales across cloud, hybrid, and multi-cloud environments  Data Classification and Discovery: Own the enterprise data classification strategy, including:Sensitive data identification (PII, PHI, PCI, IP, regulated data)Labeling and tagging standardsImplement and mature automated data discovery tools across:EndpointsSaaS applicationsCloud storageData lakes and warehouseDrive continuous discovery and remediation of exposed, misused, or over-retained dataData Security and Data Loss Prevention:Design and oversee data security controls across:Data at rest, in transit, and in useStructured and unstructured dataLead enterprise DLP strategy and execution, including:Endpoint, network, cloud, and SaaS DLPInsider risk managementExfiltration preventionPartner with SOC and Security Operations on detection, response, and incident handling involving data exposure  Cloud and Data Lakes:Define standards for secure data management in cloud platforms (AWS, Azure, GCP)Ensure protection of data within:Cloud storage (S3, Blob, GCS)Container securityData lakesAnalytics platforms and AI/ML pipelinesImplement controls for:Encryption and key managementAccess governanceData segmentation and isolationCross-border data transfersAddress emerging risks related to AI training data and model outputResponsibilitiesLeading the ECR team and its technology stakeholders to reduce the risk of technology to the company by identifying and evaluating technology and cyber risks as they are identified. Risks related to but not limited to:Architecture, infrastructure, cloud, and applicationsIdentity and access managementSoftware development and DevSecOpsVulnerability management, technical debt, and configuration driftThird-party and supply chain technology riskData Lakes and the cloudOverseeing risk assessments and data security and protection for:New and emerging technologies and platformsCloud migrations and architecture changesHigh-risk vendors and service providersDefining risk appetite and tolerance in partnership with leadership, ongoing measurement and reporting on risk against thresholdsMaintain a technology and cyber risk register with clear ownership and mitigation plans.Overseeing and redefining the risk identification and risk management processesResponsible for reviewing risks through triage and evaluative score risk level and severity with a focus on defining a potential path for remediationCollaborating to define appropriate solutions to mitigate or remediate the risk by partnering with key stakeholders in ECR, IT, and the business, which will require consensus building and managing disagreements   Responsibilities ContdEnabling balanced risk decisions by providing recommendations to leadership, escalating based on severity and risk level to ensure appropriate cyber protection capabilities and resiliency are built into the plans.Translating technical risk into business impact and likelihood.Providing regular risk reporting to executive leadership.Defining and execute the data protection strategy focused on risk reduction.Establishing and enforcing:Data classification and labelingData handling and retention standardsAccess controls and least-privilege principlesIn all areas of the business and in all technology platformsPartnering with Privacy, Legal, and Compliance to ensure regulatory data protection requirements are met (e.g., GDPR, CCPA/CPRA, HIPAA, PCI DSS).Overseeing and ensuring the design and implementation of:Encryption at rest and in transitData Loss Prevention (DLP) capabilitiesMonitoring of data access and movement throughout the enterprisePartnering with Architecture and technology teams to ensure our Zero trust framework ensures data is protected at all timesHelping govern the response to data exposure and data breach incidents both internally as well as with third parties.Technical Proficiency:Cybersecurity Depth: Cybersecurity skills include exposure to multiple cybersecurity domains e.g. cybersecurity architecture, engineering, operations, IDAM.Cyber attack framework: First-hand experience in cybersecurity attacks and controls and how one works against the other.  Experience with industry cybersecurity best practices and domains, with a constant willingness to learn more. Understanding of the MITRE ATT&CK framework. IT Proficiency: At least 2 years delivering in at least 1 domain of information technology such as networks, application development, and infrastructure. Basic SDLC knowledge to include engineering and deployment plans and review boards.Risk Management: Experience with ServiceNow and eGRC tools and the Integrated Risk Modules within.Data Governance, Loss Prevention and Insider Threat: Expertise in governing framework for DLP monitoring and configuration. Data discovery experience inProblem-Solving and Proactivity: Ability to identify opportunities for improvement and assist in the implementation of solutions. Initiative and autonomy in supporting ECR’s strategic and operational goals.Collaborative Mindset: Strong teamwork and community-building skills with the ability to collaborate effectively with cross-functional teams and stakeholders at various levels of seniority. Administrative skill: Exposure to foundational data analytics. Basic Excel skills. Basic PowerPoint and Power BI Reporting.Communication Skills: Ability to communicate effectively with both technical and non-technical stakeholders.Adaptability and Flexibility: Ability to work in a dynamic environment and adapt to changing priorities.Attention to Detail: Strong organizational skills and attention to detail in data analysis and reporting.  QualificationsBachelor’s degree in Computer Science or Cybersecurity related field – requiredPost-graduate work or thesis in Risk Management - preferredMinimum 15+ years relevant experience within Information or Cyber Security8+ years experience serving specifically in Cybersecurity leadership rolesTechnical certification such as OSCP, CEH, CCSP, PenTest+, CISSP, SANS GIAC or equivalent to demonstrate technical proficiency  - strongly preferredMust have hands on experience delivering in security capabilities and the technologies powering a security stack, as well as first-hand knowledge of what it takes to engineer and deliver on IT and security technologies and controlsMust have experience in making security decisions, prioritization, and trade-offs based on risk Experience delivering in at least two of the three lines of defense, demonstrating an understanding of what it’s like to be in the audit or owner seat.Previous business management experience preferred, demonstrating effective senior stakeholder engagement and influence capabilityDemonstrated experience in analysis, data gathering, data collation and data interpretationStrong working knowledge of security frameworks, policies and industry standards, appropriate and secure functionality of infrastructure and applications, and experience in assessing and mitigating technology riskStrong understanding of and experience adhering to industry standards and frameworks such as NIST CSF, PCI, SOX, ISO/IEC 27001, NIST SP800, COBIT, ITIL, etc.Ability to dive deeply into technical subject matter with IT and Security leadership and SMEs, influencing and leading change in the technical and process approaches in order to improve the security of the organizationAbility to effectively communicate technical topics in the business language in order to drive successful outcomes for the organizationDemonstration of leadership/management assignments, and prioritization of competing urgenciesBroad experience in team management with a global and virtual capability, demonstrating strong leadership, influence and motivational skills with a known good reputation in both skillset and relationships in the security industry.Deep experience in building and leading teams, identifying and developing cybersecurity talent, and driving operational excellence and effectiveness across security architecture, engineering and operationsTrack record in building and leading strong teams of thriving, motivated, skilled individuals Ability to lead and influence solution development in a complex and challenging environment Global experience that demonstrates effective engagement with a variety of stakeholders who have competing expectations and prioritiesProfessional English fluency and presentation skills required, with the expectation to deliver orally and in writing to executive level audiencesCISSP, CISM, CCSP, OCSP, or equivalent certification is preferred.    Pay Range:The anticipated base salary range for this position is $221,600.00 to $377,200.00. Exact salary depends on several factors such as experience, skills, education, and budget. Salary range may vary based on geographic location. In addition to base salary, this position is eligible for participation in a highly competitive bonus program as well as participation in the share incentive plan. In addition,In addition to base salary, this position is eligible for participation in a highly competitive bonus program with the possibility for overachievement based on performance and company results. In addition, The Estée Lauder Companies offers a variety of benefits to eligible employees, including health insurance coverage (medical, dental, and vision insurance), wellness and family support programs, life and disability insurance, retirement savings plans, paid leave programs, education-related programs, paid holidays and vacation time, and many others. Many of these benefits are subsidized or fully paid for by the company.Equal Opportunity EmployerIt is Company's policy not to discriminate against any employee or applicant for employment on the basis of race, color, creed, religion, national origin, ancestry, citizenship status, age, sex or gender (including pregnancy, childbirth and related medical conditions), gender identity or gender expression (including transgender status), sexual orientation, marital status, military service and veteran status, physical or mental disability, protected medical condition as defined by applicable state or local law, genetic information, or any other characteristic protected by applicable federal, state, or local laws and ordinances. The Company will endeavor to provide a reasonable accommodation consistent with the law to otherwise qualified employees and prospective employees with a disability and to employees and prospective employees with needs related to their religious observance or practices. Should you wish to apply for this position or any other position with the Company and you believe you require assistance to complete an application or participate in an interview, please contact View email address on click.appcast.io Applicants: Persons with disabilities needing accommodations for employment must notify the company in writing of the need for an accommodation within 182 days after the date the person with a disability knew or reasonably should have known that an accommodation was needed.Philadelphia Applicants: Philadelphia's Fair Chance Hiring LawRhode Island Applicants: The company is subject to chapters 29-38 of title 28 of the general laws of Rhode Island and is therefore covered by the state's workers' compensation law.Brand:Estée Lauder CompaniesJob Function:Information TechnologyJob Sub-Function:Security & ComplianceAssignment Category:Fulltime-RegularDepartment:Information Technology

Vacancy posted 22 hours ago
Similar jobs that could be interesting for youBased on the VP, Risk and Data Security, Protection, and Resilience in Long Island City, NY vacancy
  • $127 per hour

     ...financial enterprise. The focus is on security, compliance, and operational...  ..., compliance standards, and data security.Lead development and...  ...of comprehensive data protection, security, and compliance measures...  ...work with Internal Audit and Risk teams to provide evidence of controls... 
    Risk
    Full time
    Work at office
    Local area
    Remote work
    1 day per week

    MUFG

    Jersey City, NJ
    5 days ago
  •  ...Administrative Office - Chief Data & Analytics Office and help shape...  ..., Analytics, Operations, and Risk and Control functions. Your...  ...data quality, integrity, and security, while supporting innovation and...  ...data lifecycle, including data protection, privacy, retention,... 
    Risk
    Work at office

    JP Morgan Chase

    Jersey City, NJ
    4 days ago
  • $134.5k - $265.1k

     ...Summary Cyber Defense & Resilience - Insider Risk Manager Are you interested...  ...place for you. Traditional security and integrated risk...  ...Entity Behavior Analytics, and Data Loss Prevention capabilities...  ...investigations, compliance, data protection, or enterprise risk... 
    Risk
    Local area
    Visa sponsorship

    Deloitte

    Jersey City, NJ
    3 days ago
  •  ...rollouts.Align with governance & security: Work within the established...  .... Incorporate guidance on data privacy, security, and responsible...  ...including timelines, risks, stakeholders, and reporting.Passion...  ...age, ancestry, marital status, protected veteran and military status, disability... 
    Risk
    Full time
    Work at office
    Local area
    Immediate start
    Remote work
    1 day per week

    MUFG

    Jersey City, NJ
    4 days ago
  •  ...environments and on-premises data centers. You will...  ...Cloud & Compute Engineering, Security, Risk, and Development, as well as...  ...build a highly scalable and resilient network infrastructure that...  ..., ancestry, marital status, protected veteran and military status,... 
    Risk
    Full time
    Work at office
    Local area
    Remote work
    Weekend work
    1 day per week

    MUFG

    Jersey City, NJ
    3 days ago
  • As Deputy Head of Data Management, you will support the Head of Data...  ..., Analytics, Operations, and Risk and Control functions. Your...  ...data quality, integrity, and security, while supporting innovation and...  ...data lifecycle, including data protection, privacy, retention,... 
    Risk
    Work at office

    JP Morgan Chase

    Jersey City, NJ
    5 days ago
  •  ...Overview:MUFG is seeking a highly motivated Security Data Architect & Governance person to be part...  ...to understand security risks and controls, to analyze various methods...  ...identity, sex, age, ancestry, marital status, protected veteran and military status, disability,... 
    Risk
    Full time
    Work experience placement
    Work at office
    Local area
    Remote work

    MUFG

    Jersey City, NJ
    22 hours ago
  • $165k - $205k

     ...enterprise migration from Atlassian Data Center to Atlassian Cloud. You...  ...Confluence, setting standards, managing risk, and ensuring the platform scales securely and reliably across the...  ...sex, age, ancestry, marital status, protected veteran and military status, disability... 
    Risk
    Full time
    Work at office
    Local area
    Remote work
    1 day per week

    MUFG

    Jersey City, NJ
    5 days ago
  • $105.4k - $207.8k

     ...our clients to operate with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role...  ...to identify gaps, risks, and improvement opportunitiesDeveloping...  ..., access integrity, and protection of data and digital productsA successful... 
    Risk
    Work experience placement
    Local area

    Deloitte

    Jersey City, NJ
    22 hours ago
  •  ...workplace that looks like the world that we serve.Our Risk Management teams work to protect the safety and soundness of our systems and are responsible...  ...Impact you will have in this role:Operational Risk and Resilience protects the firm’s interests by fostering a consistent... 
    Risk
    Remote work
    Flexible hours

    DTCC- The Depository Trust & Clearing Corporation

    Jersey City, NJ
    2 days ago
  • $140 per hour

     ...program into MUFG's Enterprise Information Security Risk Next Generation across Combined U.S....  ...understand the state of our technology and data control suite, while working together to...  ..., sex, age, ancestry, marital status, protected veteran and military status, disability,... 
    Risk
    Full time
    Work at office
    Local area
    Remote work
    1 day per week

    MUFG

    Jersey City, NJ
    3 days ago
  •  ...experienced Modern Infrastructure and Security Architect, Vice President who...  ...about enabling secure, resilient, and scalable technology...  ...architects, engineering leads, and risk stakeholders to identify,...  ...age, ancestry, marital status, protected veteran and military status,... 
    Risk
    Full time
    Work at office
    Local area
    Remote work

    MUFG

    Jersey City, NJ
    3 days ago
  • $227.92k - $364.67k

     ...trusted partnerships. We mitigate risk, employ innovative thinking,...  ...outcomes, costs and resiliency, and automate procurement processes...  ...of our business. Supply Security and Resilience: Assess and proactively...  ...gender identity, disability, protected veteran status, or any other... 
    Risk
    Worldwide

    Avery Dennison

    Brooklyn, NY
    2 days ago
  •  ...JPMorgan Chase. As part of Risk Management and...  ...JPMorgan Chase strong and resilient. You help the firm...  ...broker-dealer (J.P. Morgan Securities, LLC) offering. *...  ...metrics; ability to perform data mining and analysis....  ...on the basis of any protected attribute, including... 
    Risk
    Full time

    JPMorgan Chase & Co.

    Jersey City, NJ
    2 days ago
  • $134.5k - $265.1k

     ...enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this...  ...Manager on the Cloud Cyber Risk team, you will be responsible...  ...security, container security, data protection, monitoring, and secure deliveryArchitecting... 
    Risk
    Local area
    Visa sponsorship

    Deloitte

    Jersey City, NJ
    4 days ago
  • $82.6k - $162.8k

     ...clients to operate with resilience, grow with confidence,...  ...proactively manage to secure success.Recruiting for...  ...AI on the Cloud Cyber Risk team, you will be responsible...  ..., resilience, and data protectionPerforming cloud...  ...native application protection platform (CNAPP), cloud... 
    Risk
    Local area
    Visa sponsorship

    Deloitte

    Jersey City, NJ
    2 days ago
  • $134.5k - $265.1k

     ...enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this...  ...on strategic and practical data protection and encryption requirements based on new and emerging data risks.Advising clients on encryption... 
    Risk
    Local area

    Deloitte

    Jersey City, NJ
    5 days ago
  •  ...Technology group delivers secure, reliable technology...  ...needs and implementing data standards and governance...  ...RoleThe Senior Data Protection Analyst plays a critical...  ...reporting, audit evidence, and risk narratives accurately...  ..., bringing enhanced resilience and soundness to... 
    Risk
    Remote work
    Flexible hours

    DTCC- The Depository Trust & Clearing Corporation

    Jersey City, NJ
    4 days ago
  • $240k - $330k

     ...with knowledge of privacy and data governance, and emerging technology...  ...managing legal and regulatory risk in a highly dynamic, consumer-...  ...familiarity with global data protection frameworks (e.g., GDPR)...  ...standardsIdentify safety and security concerns, issues, incidents or... 
    Risk
    Temporary work
    Work at office
    Immediate start
    Remote work
    Flexible hours
    Night shift

    JetBlue Airways

    Long Island City, NY
    4 days ago
  •  ...central to our technological resilience, offering a unique...  ...shape the firm's tech risk strategy and enhance industry...  ...regarding their security obligations, facilitating...  ...and experience leading data security, risk...  ...discriminate on the basis of any protected attribute, including... 
    Risk

    JP Morgan Chase

    Jersey City, NJ
    22 hours ago
  • $118.7k - $218.6k

    Position Summary Cyber Data Protection and PKI Specialist - Senior...  ...enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this...  ...based on new and emerging data risks, advising on best practices... 
    Risk
    Work experience placement
    Local area
    Visa sponsorship

    Deloitte

    Jersey City, NJ
    22 hours ago
  •  ...Vice President in the Compliance, Conduct, and Operational Risk (CCOR) Data & AI team, you will be part of an innovative and talented team...  ...at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin,... 
    Risk
    Work at office

    JP Morgan Chase

    Jersey City, NJ
    2 days ago
  • $151k - $203k

     ...Information Systems (EIS) Governance, Risk, and Compliance (GRC) team....  ...disciplines including Cloud Security Governance, Policy Management,...  ...cybersecurity domains (IAM, Data Security, Configuration...  ...age, ancestry, marital status, protected veteran and military status, disability... 
    Risk
    Full time
    Work at office
    Local area
    Remote work

    MUFG

    Jersey City, NJ
    2 days ago
  •  ...to JPMorgan Chase. As part of Risk Management and Compliance, you...  ...keeping JPMorgan Chase strong and resilient. You help the firm grow its...  ...translate complex portfolio data into consumable information for...  ...discriminate on the basis of any protected attribute, including race,... 
    Risk

    JP Morgan Chase

    Jersey City, NJ
    4 days ago
  •  ...to JPMorgan Chase. As part of Risk Management and Compliance, you...  ...keeping JPMorgan Chase strong and resilient. You help the firm grow its...  ...in class.As a Vice President, Data Scientist in the Data Science...  ...discriminate on the basis of any protected attribute, including race,... 
    Risk

    JP Morgan Chase

    Jersey City, NJ
    4 days ago
  • $145k - $200k

     ...control functions to ensure SoD risks are identified, assessed,...  ...the intersection of identity security, risk management, and business...  ...g., IGA platform, entitlement data quality, and application onboarding...  ..., or any other factor protected by applicable law. We are committed... 
    Risk
    Full time
    Part time
    Local area

    Jefferies Financial Group

    Jersey City, NJ
    5 days ago
  •  ...expertise to JPMorganChase. As part of Risk Management and Compliance, you play a crucial...  ...JPMorganChase's strength and resilience. You help the firm grow its business in...  ...do not discriminate on the basis of any protected attribute, including race, religion, color... 
    Risk

    JP Morgan Chase

    Jersey City, NJ
    4 days ago
  • $200k - $250k

     ...finance.What We're Looking ForReporting into the Chief Credit Risk Officer, we are seeking a VP, Consumer Credit Risk & Counter Parrty who will be...  ...experience in unsecured closed end, and revolving products. Secured consumer product experience a plus.Experience in end to... 
    Risk

    Cross River

    Fort Lee, NJ
    22 hours ago
  •  ...to JPMorgan Chase. As part of Risk Management and Compliance, you...  ...keeping JPMorgan Chase strong and resilient. You help the firm grow its...  ...reporting of wholesale credit data and the Allowance for Credit...  ...discriminate on the basis of any protected attribute, including race,... 
    Risk

    JP Morgan Chase

    Brooklyn, NY
    5 days ago
  •  ...to JPMorgan Chase. As part of Risk Management and Compliance, you...  ...keeping JPMorgan Chase strong and resilient. You help the firm grow its...  ...traceability, transparency, data quality, explainability, governance...  ...on the basis of any protected attribute, including race, religion... 
    Risk

    JP Morgan Chase

    Jersey City, NJ
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to VP, Risk and Data Security, Protection, and Resilience. Be the first to apply!