Senior Analyst, Tech GRC M&A
The Estée Lauder Companies Inc. is one of the world’s leading manufacturers, marketers, and sellers of quality skin care, makeup, fragrance, and hair care products, and is a steward of luxury and prestige brands globally. The company’s products are sold in approximately 150 countries and territories under brand names including: Estée Lauder, Aramis, Clinique, Lab Series, Origins, M·A·C, La Mer, Bobbi Brown Cosmetics, Aveda, Jo Malone London, Bumble and bumble, Darphin Paris, TOM FORD, Smashbox, AERIN Beauty, Le Labo, Editions de Parfums Frédéric Malle, GLAMGLOW, KILIAN PARIS, Too Faced, Dr.Jart+, the DECIEM family of brands, including The Ordinary and NIOD, and BALMAIN Beauty.
Description
This role will support the evangelization of an application security strategy under the direction of the Global Head of Application Security in support of ELC's strategic and tactical initiatives in application modernization, DevSecOps, artificial intelligence & robotics, multi⁃cloud adoption, and multi⁃site application development. This position will directly contribute to the overall global security of ELC's applications, under the direction of the Global Head of Application Security. This candidate will primarily be focused on ensuring security is built into the Software Development Life Cycle, and the delivery of trusted products and services to our clients, partners, and ELC IT/Security associates.
These responsibilities will be fulfilled by performing application security tests, developing and providing secure source code consultation services, and assisting the development communities with self⁃service tools. A person in this position will work within a diverse and geographically disperse team, as well as, act as a coach and mentor for developing the skill sets of junior team members.
Must have excellent track record and proven ability to produce effective, innovative solutions at an enterprise scale. Must be constantly evaluating the evolving security, application and technology industries to be on top of the latest innovations and process refinements, making recommendations and influencing adoption by IT, ECR and the broader ELC community.
Main duties:
- Review current security processes used in our Software Engineering teams & develop optimization strategies.
- Work with the development teams to coordinate and perform vulnerability assessments through the use of automated and manual tools.
- Provide consulting & mentoring expertise to our Developers, DevOps, and Software Engineering teams in a dynamic environment to promote and implement the DevSecOps program across our organization.
- Ability to review and analyze vulnerability data to identify security risks to the organization's network, infrastructure, and application's and determine any reported vulnerabilities that are false positives.
- Provide the expertise to prepare security vulnerability and risk management reports for management and other key stakeholders.
- Ensure we deploy best practice Cloud Configuration and Security Management tools and processes into our Software Engineering teams.
- Provide leadership and teaming skills to coordinate remediation of vulnerabilities within established timeframes.
- Experience operating in agile development processes and integrating secure development practices into these models.
- Excellent programming and scripting skills in languages such as C#, C/C++, Java, JavaScript, PowerShell, Python, etc.
- Experience with APIs: REST, SOAP, SOA and other integrations
- Formal training in the primary development toolset: Tools, Code, Application Engine, SQL/DB Security
Qualifications
- Good knowledge and understanding of application security vulnerabilities (SANS, OWASP).
- Knowledge of Threat modelling and risk analysis.
- Candidate should be very thorough in internet technologies and highly versed with web development best practices.
- Strong analytical/problem solving skills and cross functional knowledge across multiple development and security disciplines.
- Understanding of Test Automation tools and frameworks such as SAST, DAST, IAST.
- Ability to communicate security⁃related concepts to a broad range of technical and non⁃technical staff.
- Must possess a high degree of integrity, be trustworthy, and have the ability to lead and inspire change.
- Previous software engineering/architecture experience (Java, C#,.Net, JavaScript) preferred.
- Understanding CI/CD pipelines covering source control, integration, and deployment (ex: Bitbucket, Jenkins, JIRA, Artifactory, Nexus, git).
- Knowledge in securing cloud deployment and containers (familiarity with Ansible, DeMisto, Docker, and/or Kubernetes).
- Some experience with development of RESTful and SOAP web services preferred.
- Understanding of advanced iterative Agile methodologies.
- Familiarity with micro services architecture and design Patterns.
Pay Range:
The anticipated base salary range for this position is $90,450.00 to $135,000.00. Exact salary depends on several factors such as experience, skills, education, and budget. Salary range may vary based on geographic location. In addition to base salary, this position is eligible for participation in a highly competitive bonus program with the possibility for overachievement based on performance and company results.
In addition, The Estée Lauder Companies offers a variety of benefits to eligible employees, including health insurance coverage (medical, dental, and vision insurance), wellness and family support programs, life and disability insurance, retirement savings plans, paid leave programs, education-related programs, paid holidays and vacation time, and many others. Many of these benefits are subsidized or fully paid for by the company.
Equal Opportunity Employer
It is Company's policy not to discriminate against any employee or applicant for employment on the basis of race, color, creed, religion, national origin, ancestry, citizenship status, age, sex or gender (including pregnancy, childbirth and related medical conditions), gender identity or gender expression (including transgender status), sexual orientation, marital status, military service and veteran status, physical or mental disability, protected medical condition as defined by applicable state or local law, genetic information, or any other characteristic protected by applicable federal, state, or local laws and ordinances. The Company will endeavor to provide a reasonable accommodation consistent with the law to otherwise qualified employees and prospective employees with a disability and to employees and prospective employees with needs related to their religious observance or practices. Should you wish to apply for this position or any other position with the Company and you believe you require assistance to complete an application or participate in an interview, please contact USApplicantAccommodations@Estee.com.
Michigan Applicants: Persons with disabilities needing accommodations for employment must notify the company in writing of the need for an accommodation within 182 days after the date the person with a disability knew or reasonably should have known that an accommodation was needed.
Philadelphia Applicants: Philadelphia's Fair Chance Hiring Law
Rhode Island Applicants: The company is subject to chapters 29-38 of title 28 of the general laws of Rhode Island and is therefore covered by the state's workers' compensation law.