Estée Lauder Companies Cybersecurity Risk Management Lead
- Location
- Long Island CityNew YorkUSA
- Employment
- Full-Time
- Seniority
- Lead
- Department
- IT & Technology Systems
- Posted
- Sep 22, 2026
Estée Lauder Companies seeks a Cybersecurity Risk Management Lead in Long Island City, NY to minimize security risk and manage technology risk assessments and remediation strategies.
Role & Responsibilities
- Partner with ECR team members, IT stakeholders, and business owners to identify and evaluate technology and cyber risks, conducting triage and scoring risk level and severity with a focus on defining remediation pathways
- Collaborate to define appropriate solutions to mitigate or remediate identified risks through consensus building and stakeholder management, escalating recommendations based on severity and risk level to ensure appropriate cyber protection capabilities
- Manage risk reduction tracker and maintain project management documentation tracking tasks, status, ownership, issue closure, and timelines
- Support monthly Risk Reduction Governance Committee meetings and coordinate cross-functional project teams to track overall remediation status
- Prepare and provide KRI reporting and dashboard status updates on a scheduled basis
Qualifications
- Minimum 5 years of practical experience in technology risk and control or IT audit (audit firm experience preferred)
- Strong communication, influence, negotiation, and conflict management skills with proven analytical and measurement/visualization capabilities
- Ability to problem-solve, think creatively, challenge the status quo, and manage ambiguity
- Proficiency in Microsoft Excel, Word, PowerPoint, and Power BI for data visualization
- Professional proficiency in English as a business language
- Demonstrated experience handling, securing, and communicating highly confidential and sensitive information
- Undergraduate degree in computer science, business, or equivalent professional experience
- Relevant professional certification (CISSP, CISA, CISM, CRISC, CGEIT, or ITIL) is desirable
Skills
Experience
Minimum 5 years of practical experience in technology risk and control or IT audit, including project governance and management experience. Understanding of business processes, key IT risk and controls, retail and manufacturing environments is required. Minimum 3 years in directly related risk management activities.
Education
Undergraduate degree in computer science, business, or equivalent professional experience. Professional certifications such as CISSP, CISA, CISM, CRISC, CGEIT, or ITIL are desirable.
Workplace
The role is situated in Long Island City, New York, USA — conveniently close to New York.
About Cerulean
Cerulean is the definitive career portal for the global luxury industry. We match exceptional professionals with exclusive opportunities at the world's most prestigious brands. From haute couture and fine watchmaking to prestige beauty, hospitality, and boutique retail, Cerulean centralises luxury employment to help you find the career for which you were destined.
Frequently Asked Questions
The luxury industry is characterised by a diverse and nuanced nomenclature. Esteemed houses frequently employ proprietary terminology, and even within a single organisation like Estée Lauder Companies, titles may vary across global markets to reflect local conventions. To ensure absolute clarity, Cerulean assigns a standardised, industry-coherent canonical title to every listing. However, it is worth noting that this role is functionally synonymous with «Risk Management Director», «Cyber Risk Officer», «Technology Risk Lead», «Security Risk Manager», and other variations. Our sophisticated search architecture anticipates these variations, ensuring that inquiries using related terms will seamlessly yield the exact roles you desire.