Jobs and Careers
TH

VP, Risk and Data Security, Protection, and Resilience

The Estée Lauder Companies Inc.
Long Island City, United Statesfull_timeVerifiedPosted 7 Apr 2026
💰 $377,200/yr($221,600/yr$377,200/yr)

About the role

The Estée Lauder Companies Inc. is one of the world’s leading manufacturers, marketers, and sellers of quality skin care, makeup, fragrance, and hair care products, and is a steward of luxury and prestige brands globally. The company’s products are sold in approximately 150 countries and territories under brand names including: Estée Lauder, Aramis, Clinique, Lab Series, Origins, M·A·C, La Mer, Bobbi Brown Cosmetics, Aveda, Jo Malone London, Bumble and bumble, Darphin Paris, TOM FORD, Smashbox, AERIN Beauty, Le Labo, Editions de Parfums Frédéric Malle, GLAMGLOW, KILIAN PARIS, Too Faced, Dr.Jart+, the DECIEM family of brands, including The Ordinary and NIOD, and BALMAIN Beauty.

Description

Who We Are

Do you want to be part of the team catalyzing digital innovation, harnessing the power of data, and transforming the fabric of security across the world’s most prestigious beauty, skincare, and luxury fragrance brands? Then join our Risk Management and Data Security team in Enterprise Cybersecurity & Risk (ECR) at Estée Lauder Companies (ELC). Our Risk Management and Data Protection team is responsible for identifying, assessing, and mitigating potential risks to the enterprise and our data. This small but important group actively governs these critical pillars of work, shapes our risk management strategies, finds mitigation strategies. They will lead three teams- (1) Strategic Risk Management and Reduction, (2) Supplier Security and Third Party Risk Management, and (3) Data Security including Data Protection and Classification, Data Resilience and Disaster Recovery, and Data Loss Prevention.  Their teams will collaborate across security, technology and business functions and will help to directly fortify the organization against evolving risks.

What You’ll Do

As the Vice President, Risk Management and Data Security, you will lead the company’s approach to cybersecurity and technology risk management and securing our data in its various forms, in collaboration with data and analytics and data privacy.

In this exciting new role, you will:  

  • Lead and develop teams across technology risk, data protection, and security.  
  • Establish governance forums for risk, security, and data protection decisions.  
  • Partner with IT, Engineering, Legal, Compliance, and Product teams.  
  • Translate technical and cyber risk into clear executive-level reporting.  
  • Drive accountability without creating friction or unnecessary bureaucracy.  
  • Drive consistent governance cadence with clear decision outcomes.  
  • Have strong collaboration with technology and business leaders.  
  • Maintain executive trust in risk and security reporting.  

Risk Management and Reduction:  

This strategic function will not only oversee the traditional risk management and risk register functions, but design and oversee the modernization of a risk management function meant to resolve and remediate risk, not just track it. This is an expansion of the “second line of defense” ensuring risk is addressed in meaningful and prioritized ways.

You will help enable innovation, finding the path forward for our technology innovation and help the organization stay at the cutting edge while keeping security risk to a minimum through technical and resolution-focused risk management.

Our risk management function relies more on technical solutions and risk mitigation than most programs, to modernize risk management and create more impact by the function.  

You will seek to minimize overall security risk by identifying risks, monitoring requests through approval workflows, providing risk scoring, and presenting data to give a holistic view of the risk associated with risks identified at the company.  Then be responsible for lead the effort to find and execute the solution until remediated.

You must have strong technical and business acumen, understanding the details behind and making decisions or influencing based on risk. You must also lead the team in balancing the tradeoffs of having ultimate security and running the business.  You must be able to navigate countering perspectives, setting priorities independently, and leading effectively to manage the expectations of our stakeholders and technical and business leadership. 

Data Protection and Security:

  • Define and own the enterprise data protection vision, roadmap, and operating model  
  • Serve as the executive authority on data risk, data security, and data lifecycle management  
  • Translate regulatory, legal, and business requirements into actionable data protection policies  
  • Build and lead a high-performing global data protection organization  
  • Define KPIs and dashboards for:  <

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

The Estée Lauder Companies Inc.

View company profile →