Senior Analyst, Tech GRC M&A

The Estée Lauder Companies Inc.

New York (NY)

On-site

USD 90,450 - 135,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
Wellness programs
Retirement savings plans
Paid leave & holidays
Education-related programs

Job summary

The Estée Lauder Companies Inc. is seeking an experienced Application Security professional to evangelize our security strategy under the Global Head of Application Security.

You will work on SDLC security, DevSecOps, and multi-cloud initiatives to deliver trusted software across global teams. You will test security, provide secure coding consultations, and mentor developers, with a focus on building secure products for clients and internal stakeholders.

Qualifications

  • Good knowledge of application security vulnerabilities (SANS, OWASP).
  • Experience with threat modelling and risk analysis.
  • Understanding of web development best practices.
  • Ability to communicate security concepts to both technical and non-technical staff.
  • Familiarity with CI/CD pipelines and security integration.

Responsibilities

  • Review current security processes and optimize them.
  • Coordinate and perform vulnerability assessments using automated and manual tools.
  • Provide security consulting and mentoring across DevOps and Software Engineering teams.
  • Analyze vulnerability data to identify risks and discern false positives.
  • Prepare security vulnerability and risk management reports for stakeholders.
  • Ensure deployment of best practice cloud configuration and security tools.
  • Lead remediation of vulnerabilities within established timeframes.
  • Integrate secure development practices into agile processes.
  • Demonstrate strong programming and scripting skills (C#, C/C++, Java, JavaScript, PowerShell, Python).
  • Work with APIs: REST, SOAP, SOA and other integrations.
  • Familiarity with primary development toolsets: Tools, Code, SQL/DB Security.

Job description

The Estée Lauder Companies Inc. is one of the world’s leading manufacturers, marketers, and sellers of quality skin care, makeup, fragrance, and hair care products, and is a steward of luxury and prestige brands globally. The company’s products are sold in approximately 150 countries and territories under brand names including: Estée Lauder, Aramis, Clinique, Lab Series, Origins, M·A·C, La Mer, Bobbi Brown Cosmetics, Aveda, Jo Malone London, Bumble and bumble, Darphin Paris, TOM FORD, Smashbox, AERIN Beauty, Le Labo, Editions de Parfums Frédéric Malle, GLAMGLOW, KILIAN PARIS, Too Faced, Dr.Jart+, the DECIEM family of brands, including The Ordinary and NIOD, and BALMAIN Beauty.

Description

This role will support the evangelization of an application security strategy under the direction of the Global Head of Application Security in support of ELC's strategic and tactical initiatives in application modernization, DevSecOps, artificial intelligence & robotics, multi‑cloud adoption, and multi‑site application development. This position will directly contribute to the overall global security of ELC's applications, under the direction of the Global Head of Application Security. This candidate will primarily be focused on ensuring security is built into the Software Development Life Cycle, and the delivery of trusted products and services to our clients, partners, and ELC IT/Security associates.

These responsibilities will be fulfilled by performing application security tests, developing and providing secure source code consultation services, and assisting the development communities with self‑service tools. A person in this position will work within a diverse and geographically disperse team, as well as, act as a coach and mentor for developing the skill sets of junior team members.

Must have excellent track record and proven ability to produce effective, innovative solutions at an enterprise scale. Must be constantly evaluating the evolving security, application and technology industries to be on top of the latest innovations and process refinements, making recommendations and influencing adoption by IT, ECR and the broader ELC community.

Main Duties
  • Review current security processes used in our Software Engineering teams & develop optimization strategies.
  • Work with the development teams to coordinate and perform vulnerability assessments through the use of automated and manual tools.
  • Provide consulting & mentoring expertise to our Developers, DevOps, and Software Engineering teams in a dynamic environment to promote and implement the DevSecOps program across our organization.
  • Ability to review and analyze vulnerability data to identify security risks to the organization's network, infrastructure, and application’s and determine any reported vulnerabilities that are false positives.
  • Provide the expertise to prepare security vulnerability and risk management reports for management and other key stakeholders.
  • Ensure we deploy best practice Cloud Configuration and Security Management tools and processes into our Software Engineering teams.
  • Provide leadership and teaming skills to coordinate remediation of vulnerabilities within established timeframes.
  • Experience operating in agile development processes and integrating secure development practices into these models.
  • Excellent programming and scripting skills in languages such as C#, C/C++, Java, JavaScript, PowerShell, Python, etc.
  • Experience with APIs: REST, SOAP, SOA and other integrations
  • Formal training in the primary development toolset: Tools, Code, Application Engine, SQL/DB Security
Qualifications
  • Good knowledge and understanding of application security vulnerabilities (SANS, OWASP).
  • Knowledge of Threat modelling and risk analysis.
  • Candidate should be very thorough in internet technologies and highly versed with web development best practices.
  • Strong analytical/problem solving skills and cross functional knowledge across multiple development and security disciplines.
  • Understanding of Test Automation tools and frameworks such as SAST, DAST, IAST.
  • Ability to communicate security-related concepts to a broad range of technical and non‑technical staff.
  • Must possess a high degree of integrity, be trustworthy, and have the ability to lead and inspire change.
  • Previous software engineering/architecture experience (Java, C#,.Net, JavaScript) preferred.
  • Understanding CI/CD pipelines covering source control, integration, and deployment (ex: Bitbucket, Jenkins, JIRA, Artifactory, Nexus, git).
  • Knowledge in securing cloud deployment and containers (familiarity with Ansible, DeMisto, Docker, and/or Kubernetes).
  • Some experience with development of RESTful and SOAP web services preferred.
  • Understanding of advanced iterative Agile methodologies.
  • Familiarity with micro services architecture and design Patterns.
Pay Range

The anticipated base salary range for this position is $90,450.00 to $135,000.00. Exact salary depends on several factors such as experience, skills, education, and budget. Salary range may vary based on geographic location. In addition to base salary, this position is eligible for participation in a highly competitive bonus program with the possibility for overachievement based on performance and company results.

In addition, The Estée Lauder Companies offers a variety of benefits to eligible employees, including health insurance coverage (medical, dental, and vision insurance), wellness and family support programs, life and disability insurance, retirement savings plans, paid leave programs, education-related programs, paid holidays and vacation time, and many others. Many of these benefits are subsidized or fully paid for by the company.

Equal Opportunity Employer

It is Company's policy not to discriminate against any employee or applicant for employment on the basis of race, color, creed, religion, national origin, ancestry, citizenship status, age, sex or gender (including pregnancy, childbirth and related medical conditions), gender identity or gender expression (including transgender status), sexual orientation, marital status, military service and veteran status, physical or mental disability, protected medical condition as defined by applicable state or local law, genetic information, or any other characteristic protected by applicable federal, state, or local laws and ordinances. The Company will endeavor to provide a reasonable accommodation consistent with the law to otherwise qualified employees and prospective employees with a disability and to employees and prospective employees with needs related to their religious observance or practices. Should you wish to apply for this position or any other position with the Company and you believe you require assistance to complete an application or participate in an interview, please contact USApplicantAccommodations@Estee.com.

Michigan Applicants

Persons with disabilities needing accommodations for employment must notify the company in writing of the need for an accommodation within 182 days after the date the person with a disability knew or reasonably should have known that an accommodation was needed.

Philadelphia Applicants

Philadelphia's Fair Chance Hiring Law

Rhode Island Applicants

The company is subject to chapters 29-38 of title 28 of the general laws of Rhode Island and is therefore covered by the state's workers' compensation law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

VP, Risk and Data Security, Protection, and Resilience
VP, Risk and Data Security, Protection, and Resilience

The Estée Lauder Companies Inc. • New York (NY)

On-site
USD 221,000 - 378,000
Health, dental, and vision insurance
Retirement savings plans
Education programs
Manager, Responsible Sourcing
Manager, Responsible Sourcing

Estée Lauder Companies • New York (NY)

On-site
USD 88,000 - 144,000
Health insurance (medical, dental, and
Vision insurance
Life and disability insurance
+3
Manager, Responsible Sourcing
Manager, Responsible Sourcing

The Estée Lauder Companies Inc. • New York (NY)

On-site
USD 88,000 - 144,000
Health insurance coverage
Retirement savings plans
Paid leave programs
+1
Vice President, Business Services Operations, Global Business Services
Vice President, Business Services Operations, Global Business Services

The Estée Lauder Companies Inc. • New York (NY)

On-site
USD 221,000 - 378,000
Health insurance
Wellness programs
Retirement savings plans
+1
Director, Internal & Executive Communications, North America
Director, Internal & Executive Communications, North America

Estée Lauder Companies • New York (NY)

Hybrid
USD 124,000 - 214,000
Health insurance
Retirement savings plans
Paid time off & holidays
+1
Associate Director, Technical Project Management
Associate Director, Technical Project Management

The Estée Lauder Companies Inc. • Melville (NY)

On-site
USD 102,000 - 169,000
Health insurance
Retirement plan
Paid leave
+1
Manager, Strategy, North America
Manager, Strategy, North America

The Estée Lauder Companies Inc. • New York (NY)

On-site
USD 87,000 - 143,000
Manager, Strategy, North America
Manager, Strategy, North America

Estée Lauder Companies • New York (NY)

On-site
USD 87,000 - 143,000
Staff Machine Learning Engineer
Staff Machine Learning Engineer

Estée Lauder Companies • New York (NY)

On-site
USD 119,000 - 197,000
Health insurance
Paid vacation
Retirement savings plans
+1
Estee Lauder - Field Executive - San Francisco / East Bay
Estee Lauder - Field Executive - San Francisco / East Bay

The Estée Lauder Companies Inc. • San Francisco (CA)

On-site
USD 78,144 - 117,216
Health insurance (medical, dental, and
Wellness and family support programs
Retirement savings plans
+2