VP, Risk and Data Security, Protection, and Resilience
5 days ago
New York
The Estée Lauder Companies Inc. is one of the world’s leading manufacturers, marketers, and sellers of quality skin care, makeup, fragrance, and hair care products. The company’s products are sold in approximately 150 countries and territories under brand names including Estée Lauder, Aramis, Clinique, Lab Series, Origins, M·A·C, La Mer, Bobbi Brown Cosmetics, Aveda, Jo Malone London, Bumble & Bumble, Darphin Paris, TOM FORD, Smashbox, AERIN Beauty, Le Labo, Editions de Parfums Frédéric Malle, GLAMGLOW, KILIAN PARIS, Too Faced, Dr. Jart+, DECIEM family brands (The Ordinary, NIOD), and BALMAIN Beauty. We are a team catalyzing digital innovation, harnessing the power of data, and transforming security across the world’s most prestigious beauty brands. Join our Risk Management & Data Security team in Enterprise Cybersecurity & Risk (ECR) at Estée Lauder. Our Risk Management & Data Protection team identifies, assesses, and mitigates risks to the enterprise and our data, governing these critical pillars and shaping our risk strategies. As Vice President, Risk Management & Data Security, you will lead the company’s approach to cybersecurity and technology risk management, securing our data through collaboration with data, analytics, and privacy teams. • Lead and develop teams across technology risk, data protection, and security., • Establish governance forums for risk, security, and data protection decisions., • Partner with IT, Engineering, Legal, Compliance, and Product teams., • Translate technical and cyber risk into clear executive-level reporting., • Drive accountability without creating friction or unnecessary bureaucracy., • Maintain executive trust in risk and security reporting. This strategic function will not only manage the risk register but also modernize risk processes to remediate risks effectively. • Identify risks, monitor approval workflows, and score risks to present a holistic view., • Lead the effort to find and execute solutions until remediated., • Navigate priorities and balance security with business operations., • Set expectations and manage stakeholder relationships., • Define and own the enterprise data protection vision, roadmap, and operating model., • Serve as the executive authority on data risk, security, and lifecycle management., • Translate regulatory requirements into actionable policies., • Build and lead a high‑performing global data protection organization., • Define KPIs and dashboards for data risk posture, discovery coverage, DLP effectiveness, and remediation progress., • Brief executive leadership and the board on data protection risks and progress., • Establish enterprise data governance frameworks, including ownership, lifecycle, quality, retention, and disposition., • Embed governance into day‑to‑day operations and scale across cloud, hybrid, and multi‑cloud environments., • Own the enterprise classification strategy for sensitive data (PII, PHI, PCI, IP, regulated)., • Implement automated discovery tools across endpoints, SaaS, cloud storage, and data lakes., • Drive continuous discovery and remediation of exposed or over‑retained data., • Design and oversee controls for data at rest, in transit, and in use., • Lead DLP strategy including endpoint, network, cloud, SaaS, insider risk, and exfiltration prevention., • Partner with SOC and Security Operations on detection, response, and incident handling., • Define standards for secure data management in AWS, Azure, GCP., • Implement controls for encryption, key management, access governance, segmentation, and cross‑border transfers., • Address AI training data and model output risks., • Lead the ECR team and technology stakeholders to reduce technology risk by identifying and evaluating risks related to architecture, cloud, identity, DevSecOps, and third‑party risk., • Oversee risk assessments for new technologies, cloud migrations, and high‑risk vendors., • Define risk appetite and tolerance, report against thresholds, and maintain the risk register., • Redefine risk identification and management processes and review risks through triage with mitigation plans., • Collaborate with stakeholders to develop solutions, build consensus, and manage disagreements., • Provide recommendations to leadership and ensure cyber‑protection capabilities are built into plans., • Translate technical risk into business impact and likelihood., • Provide regular risk reporting to executive leadership., • Define and execute data protection strategy, enforce classification, labeling, handling, retention, and access controls., • Partner with Privacy, Legal, and Compliance to meet regulatory requirements (GDPR, CCPA/CPRA, HIPAA, PCI DSS)., • Ensure encryption, DLP, and monitoring are implemented across the enterprise., • Govern response to data exposure and breach incidents internally and with third parties., • Cybersecurity depth across architecture, engineering, operations, IDAM., • Experience with MITRE ATT&CK and industry best practices., • Minimum 2 years in IT domains such as networks, application development, or infrastructure., • Experience with ServiceNow, eGRC tools, and the Integrated Risk modules., • Knowledge of DLP, data discovery, and insider threat governance., • Problem‑solving, proactivity, collaboration, and communication skills., • Administrative skill: Excel, PowerPoint, Power BI reporting., • Adaptability and attention to detail., • Bachelor’s degree in Computer Science or Cybersecurity (required)., • Post‑graduate work or thesis in Risk Management (preferred)., • 15+ years of experience in information or cybersecurity., • 8+ years in cybersecurity leadership roles., • Technical certifications such as OSCP, CEH, CCSP, PenTest+, CISSP, SANS GIAC., • Experience delivering security capabilities and making risk‑based decisions., • Experience in at least two lines of defense., • Business‑management experience and stakeholder influence preferred., • Experience with NIST CSF, PCI, SOX, ISO/IEC 27001, NIST SP800, COBIT, ITIL., • Effective communication in a business language for executive audiences., • Global experience and strong leadership, influence, and motivation., • Professional English fluency., • CISSP, CISM, CCSP, OCSP, or equivalent certification preferred. The anticipated base salary range is $221,600.00 to $377,200.00, with eligibility for a highly competitive bonus program and share incentive plan. Salary may vary by location and experience. Benefits include health, dental, and vision insurance; wellness and family support programs; life and disability insurance; retirement savings plans; paid leave; education programs; paid holidays and vacation; and many others, often subsidized or fully paid by the company. The company does not discriminate on the basis of race, color, creed, religion, national origin, ancestry, citizenship, age, sex, gender, sexual orientation, marital status, military service, disability, or any other protected characteristic. Reasonable accommodation is provided for qualified employees and applicants. Please contact USApplicantAccommodations@Estee.com for assistance. Michigan applicants: persons with disabilities must notify the company of the need for accommodation within 182 days of knowledge. Citizenship and residency requirements apply as described by the company. #J-18808-Ljbffr