Senior Analyst, Tech GRC M&A

Estée Lauder Companies, NY
$90,450 - $135,000

About The Position

This role will support the evangelization of an application security strategy under the direction of the Global Head of Application Security in support of ELC's strategic and tactical initiatives in application modernization, DevSecOps, artificial intelligence & robotics, multi⁃cloud adoption, and multi⁃site application development. This position will directly contribute to the overall global security of ELC's applications, under the direction of the Global Head of Application Security. This candidate will primarily be focused on ensuring security is built into the Software Development Life Cycle, and the delivery of trusted products and services to our clients, partners, and ELC IT/Security associates. These responsibilities will be fulfilled by performing application security tests, developing and providing secure source code consultation services, and assisting the development communities with self⁃service tools. A person in this position will work within a diverse and geographically disperse team, as well as, act as a coach and mentor for developing the skill sets of junior team members. Must have excellent track record and proven ability to produce effective, innovative solutions at an enterprise scale. Must be constantly evaluating the evolving security, application and technology industries to be on top of the latest innovations and process refinements, making recommendations and influencing adoption by IT, ECR and the broader ELC community.

Requirements

  • Excellent programming and scripting skills in languages such as C#, C/C++, Java, JavaScript, PowerShell, Python, etc.
  • Experience with APIs: REST, SOAP, SOA and other integrations
  • Formal training in the primary development toolset: Tools, Code, Application Engine, SQL/DB Security
  • Good knowledge and understanding of application security vulnerabilities (SANS, OWASP).
  • Knowledge of Threat modelling and risk analysis.
  • Candidate should be very thorough in internet technologies and highly versed with web development best practices.
  • Strong analytical/problem solving skills and cross functional knowledge across multiple development and security disciplines.
  • Understanding of Test Automation tools and frameworks such as SAST, DAST, IAST.
  • Ability to communicate security⁃related concepts to a broad range of technical and non⁃technical staff.
  • Must possess a high degree of integrity, be trustworthy, and have the ability to lead and inspire change.

Nice To Haves

  • Previous software engineering/architecture experience (Java, C#,.Net, JavaScript) preferred.
  • Understanding CI/CD pipelines covering source control, integration, and deployment (ex: Bitbucket, Jenkins, JIRA, Artifactory, Nexus, git).
  • Knowledge in securing cloud deployment and containers (familiarity with Ansible, DeMisto, Docker, and/or Kubernetes).
  • Some experience with development of RESTful and SOAP web services preferred.
  • Understanding of advanced iterative Agile methodologies.
  • Familiarity with micro services architecture and design Patterns.

Responsibilities

  • Review current security processes used in our Software Engineering teams & develop optimization strategies.
  • Work with the development teams to coordinate and perform vulnerability assessments through the use of automated and manual tools.
  • Provide consulting & mentoring expertise to our Developers, DevOps, and Software Engineering teams in a dynamic environment to promote and implement the DevSecOps program across our organization.
  • Ability to review and analyze vulnerability data to identify security risks to the organization's network, infrastructure, and application's and determine any reported vulnerabilities that are false positives.
  • Provide the expertise to prepare security vulnerability and risk management reports for management and other key stakeholders.
  • Ensure we deploy best practice Cloud Configuration and Security Management tools and processes into our Software Engineering teams.
  • Provide leadership and teaming skills to coordinate remediation of vulnerabilities within established timeframes.
  • Experience operating in agile development processes and integrating secure development practices into these models.

Benefits

  • health insurance coverage (medical, dental, and vision insurance)
  • wellness and family support programs
  • life and disability insurance
  • retirement savings plans
  • paid leave programs
  • education-related programs
  • paid holidays and vacation time
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service