Jobs and Careers
SE

Program Manager, Vendor Security, Cybersecurity

Sephora
Remote, CA, US, USA 522388, United StatesRemotefull_timeVerifiedPosted 1 Oct 2024
💰 $201,600/yr($163,260/yr$201,600/yr)

About the role

Job ID: 256316
Location Name: FSC REMOTE SF/NY/DC -173(USA_0173)
Address: FSC, Remote, CA 94105, United States (US)
Job Type: Full Time
Position Type: Regular
Job Function: Information Technology
Remote Eligible:Yes

 

Company Overview:

At Sephora we inspire our customers, empower our teams, and help them become the best versions of themselves.  We create an environment where people are valued, and differences are celebrated. Every day, our teams across the world bring to life our purpose: to expand the way the world sees beauty by empowering the Extra Ordinary in each of us.  We are united by a common goal - to reimagine the future of beauty.

 

The Opportunity:

About the Team

Sephora Cyber Security team is a dynamic, passionate, innovative, highly experienced, results-oriented Team within a Technology Organization with a deep commitment to ensuring security of Sephora informational assets.

 

Summary

The Program Manager- Vendor Security leads Sephora North America Vendor Security Risk Management Program. This highly visible and impactful role within the organization is responsible for performing functions required to manage Vendor Security Review process end to end.

 

In addition to reviewing new, existing and expanding vendor relationships, this role manages entire Sephora vendor portfolio from security perspective and maintains understanding of services these vendors provide and inherent information security risk presented by those vendors. Based on this, creates vendor risk specific security review approach for each vendor. The Program Manager will connect with relevant stakeholders across the company including Business and Technical Owners, Legal, Privacy and Sourcing to manage the vendor security review process and provides training to entire Sephora North America population.

Responsible to understand Sephora methodologies and relentlessly champion best security practices.

 

Your responsibilities include:

  • Manages Sephora North America Vendor Security Review process end to end including but not limited to: reviewing intake documentation, managing internal meetings, reviewing project documents, creating a security review approach, reviewing vendor security documents, managing vendor security meeting, drafting meeting recap notes and follow ups, managing contract security reviews, etc.
  • Drives vendor security related projects as needed
  • Prepares weekly status updates and quarterly including dashboards etc.
  • Provides ongoing vendor security review process training across org
  • Demonstrate our Sephora values: Passion, Innovation, Expertise, Balance, Respect, Teamwork, and Initiative.

 

We would love to hear from you if

  • 5+ years of experience working in Cyber Security Team in vendor security, compliance, risk management, audit, security awareness or program/project management function with knowledge of information security principles.
  • Ability to excel in high paced and dynamic environment
  • Attention to Detail is a MUST. Strong organizational skills are a MUST.
  • Ability to learn the vendor security review lifecycle management: intake form, internal meetings, reviewing project documents, reviewing vendor security documents, vendor security meeting, contract reviews, follow ups, repeat review etc.
  • Ability to learn quickly and think critically specifically about Sephora vendor provided services, the inherent risk

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Sephora

View company profile →