Then join our Risk Management and Data Security team in Enterprise Cybersecurity & Risk (ECR) at Estée Lauder Companies (ELC). Our Risk Management and Data Protection team is responsible for ...
Then join our Risk Management and Data Security team in Enterprise Cybersecurity & Risk (ECR) at Estée Lauder Companies (ELC). Our Risk Management and Data Protection team is responsible for ...
Software Engineer, Technology Security & Risk
New York, NY · On-site
$165K - $250K/yr
Software Engineer, Technology Security & Risk Location NY New York United States Business Investment Management Function Engineering Experience Level Experienced Share this job Position Summary Two ...
Software Engineer, Technology Security & Risk
New York, NY · On-site
$165K - $250K/yr
Software Engineer, Technology Security & Risk Location NY New York United States Business Investment Management Function Engineering Experience Level Experienced Share this job Position Summary Two ...
Hudson River Trading (HRT) is seeking a Security Governance, Risk, and Compliance Engineer to join our growing Information Security team. This function combines technical security, automation, and ...
Hudson River Trading (HRT) is seeking a Security Governance, Risk, and Compliance Engineer to join our growing Information Security team. This function combines technical security, automation, and ...
M0 Labs - Head of Security & Risk
New York, NY · On-site +1
$117K - $153K/yr
The information security and risk posture we establish in the next 12 months will define how M0 is perceived by partners, regulators, and institutional investors for years to come. About the Role ...
M0 Labs - Head of Security & Risk
New York, NY · On-site +1
$117K - $153K/yr
The information security and risk posture we establish in the next 12 months will define how M0 is perceived by partners, regulators, and institutional investors for years to come. About the Role ...
Functional title - VP, Information Security Risk and Control (CCO) * Department - Chief Controls Office * Corporate level - Vice President * Report to - Director, Technology Risk and Control
Functional title - VP, Information Security Risk and Control (CCO) * Department - Chief Controls Office * Corporate level - Vice President * Report to - Director, Technology Risk and Control
Contract Duration: 12 Months We are seeking an Information Security Analyst II to support information security, risk, compliance, and process improvement initiatives. The ideal candidate will have ...
Contract Duration: 12 Months We are seeking an Information Security Analyst II to support information security, risk, compliance, and process improvement initiatives. The ideal candidate will have ...
Risk & Compliance Engineer
Newark, NJ · Hybrid
You'll lead and conduct vendor security risk assessments end to end - integrate AI to improve accuracy, evaluate control effectiveness, quantify risk to the business, and partner with risk owners to ...
Risk & Compliance Engineer
Newark, NJ · Hybrid
You'll lead and conduct vendor security risk assessments end to end - integrate AI to improve accuracy, evaluate control effectiveness, quantify risk to the business, and partner with risk owners to ...
Risk & Compliance Engineer
Newark, NJ · On-site
You'll lead and conduct vendor security risk assessments end to end - integrate AI to improve accuracy, evaluate control effectiveness, quantify risk to the business, and partner with risk owners to ...
Risk & Compliance Engineer
Newark, NJ · On-site
You'll lead and conduct vendor security risk assessments end to end - integrate AI to improve accuracy, evaluate control effectiveness, quantify risk to the business, and partner with risk owners to ...
Vice President - Technology (AI Security & Risk Manager)
New York, NY · On-site
$171K - $215K/yr
The AI Security & Risk Manager will be PJT's dedicated subject matter expert at the intersection of AI and security, helping the firm navigate this landscape with rigor and clarity. We are seeking a ...
Vice President - Technology (AI Security & Risk Manager)
New York, NY · On-site
$171K - $215K/yr
The AI Security & Risk Manager will be PJT's dedicated subject matter expert at the intersection of AI and security, helping the firm navigate this landscape with rigor and clarity. We are seeking a ...
Hudson River Trading (HRT) is seeking a Security Governance, Risk, and Compliance Engineer to join our growing Information Security team. This function combines technical security, automation, and ...
Hudson River Trading (HRT) is seeking a Security Governance, Risk, and Compliance Engineer to join our growing Information Security team. This function combines technical security, automation, and ...
Report AI security risk posture, program progress, and emerging threats to the CISO and senior leadership on a regular cadence; serve as a key member of the security leadership team Security Risk ...
Report AI security risk posture, program progress, and emerging threats to the CISO and senior leadership on a regular cadence; serve as a key member of the security leadership team Security Risk ...
Director, AI Security
New York, NY · On-site +1
Report AI security risk posture, program progress, and emerging threats to the CISO and senior leadership on a regular cadence; serve as a key member of the security leadership team Security Risk ...
Director, AI Security
New York, NY · On-site +1
Report AI security risk posture, program progress, and emerging threats to the CISO and senior leadership on a regular cadence; serve as a key member of the security leadership team Security Risk ...
Principal Tech Resiliency
New York, NY · On-site
Partners across Technology, Security, Product, Data, and other business functions to evaluate risk and control practices, including risk assessments, issues management, control validation, key risk ...
Principal Tech Resiliency
New York, NY · On-site
Partners across Technology, Security, Product, Data, and other business functions to evaluate risk and control practices, including risk assessments, issues management, control validation, key risk ...
Cybersecurity Risk Analyst II
$119K - $140K/yr
As a Cybersecurity Risk Analyst II, you'll help strengthen CLEAR's security posture by identifying, assessing, and reducing cyber risk across our products, technology, and third-party ecosystem.
Cybersecurity Risk Analyst II
$119K - $140K/yr
As a Cybersecurity Risk Analyst II, you'll help strengthen CLEAR's security posture by identifying, assessing, and reducing cyber risk across our products, technology, and third-party ecosystem.
Principal Tech Resiliency
Manhattan, NY · On-site
Partners across Technology, Security, Product, Data, and other business functions to evaluate risk and control practices, including risk assessments, issues management, control validation, key risk ...
Principal Tech Resiliency
Manhattan, NY · On-site
Partners across Technology, Security, Product, Data, and other business functions to evaluate risk and control practices, including risk assessments, issues management, control validation, key risk ...
Monitor and manage the IT Security risk register to ensure that all IT Security risks are accurately represented and actively managed * Perform evidence collection and quality assurance of IT and ...
Monitor and manage the IT Security risk register to ensure that all IT Security risks are accurately represented and actively managed * Perform evidence collection and quality assurance of IT and ...
Security Analyst - ISF Healthcheck Job Details Understand and become fluent in the Risk Assessment tool (ISF HealthCheck) Enhance procedures for performing and reporting of the annual Information ...
Security Analyst - ISF Healthcheck Job Details Understand and become fluent in the Risk Assessment tool (ISF HealthCheck) Enhance procedures for performing and reporting of the annual Information ...
Lead, Insider Risk - Cyber Defense & Response
$123K - $204K/yr
Technology - Information Security Are you passionate about safeguarding organizations from within ... As an Insider Risk Specialist, you will partner with business stakeholders, technical teams, and ...
Lead, Insider Risk - Cyber Defense & Response
$123K - $204K/yr
Technology - Information Security Are you passionate about safeguarding organizations from within ... As an Insider Risk Specialist, you will partner with business stakeholders, technical teams, and ...
Lead, Insider Risk - Cyber Defense & Response
Newark, NJ · On-site
$123K - $204K/yr
Technology - Information Security Are you passionate about safeguarding organizations from within ... As an Insider Risk Specialist, you will partner with business stakeholders, technical teams, and ...
Lead, Insider Risk - Cyber Defense & Response
Newark, NJ · On-site
$123K - $204K/yr
Technology - Information Security Are you passionate about safeguarding organizations from within ... As an Insider Risk Specialist, you will partner with business stakeholders, technical teams, and ...
Manager, Cybersecurity Governance and Risk, New York, NY The Manager, Cybersecurity Governance and ... Security perspective. This position is 100% Onsite and not open for Remote. Manager, Cybersecurity ...
Manager, Cybersecurity Governance and Risk, New York, NY The Manager, Cybersecurity Governance and ... Security perspective. This position is 100% Onsite and not open for Remote. Manager, Cybersecurity ...
Security Risk information
See New York salary details
$11.31 - $17.24
2% of jobs
$17.24 - $23.17
0% of jobs
$23.17 - $29.10
1% of jobs
$29.10 - $35.03
1% of jobs
$35.03 - $40.95
1% of jobs
$45.40 is the 25th percentile. Wages below this are outliers.
$40.95 - $46.88
26% of jobs
$46.88 - $52.81
11% of jobs
The median wage is $54.93 / hr.
$52.81 - $58.74
22% of jobs
$58.74 - $64.67
9% of jobs
$65.14 is the 75th percentile. Wages above this are outliers.
$64.67 - $70.60
17% of jobs
$70.60 - $76.53
9% of jobs
$11
$55
$76
How much do security risk jobs pay per hour?
What is the difference between Security Risk vs Security Analyst?
| Aspect | Security Risk | Security Analyst |
|---|---|---|
| Required Credentials | Knowledge of security principles, risk assessment skills | Certifications like CompTIA Security+, CISSP, or CISA |
| Work Environment | Identifying potential threats, assessing vulnerabilities | Monitoring security systems, analyzing security data |
| Employer & Industry Usage | Used across industries to identify threats | Commonly employed in cybersecurity teams |
| Search & Comparison Intent | Understanding risk factors and mitigation | Analyzing security incidents and improving defenses |
Security Risk involves identifying and assessing potential threats to an organization, focusing on risk management strategies. Security Analysts, on the other hand, monitor and analyze security systems to detect and respond to threats. While both roles require security knowledge and certifications, Security Risk professionals focus on risk assessment, whereas Security Analysts are more involved in operational security monitoring.
What are security risk professionals?
Can you make $500,000 a year in cyber security?
Is 40 too old for cyber security?
What is the highest paying security job?
What are some common challenges faced by Security Risk professionals, and how can they overcome them?
What are the key skills and qualifications needed to thrive as a Security Risk Analyst, and why are they important?
Is security risk management a good career?

VP, Risk and Data Security, Protection, and Resilience
New York, NY • On-site
Full-time
Posted 18 days ago
Job description
Description
Who We Are
Do you want to be part of the team catalyzing digital innovation, harnessing the power of data, and transforming the fabric of security across the world's most prestigious beauty, skincare, and luxury fragrance brands? Then join our Risk Management and Data Security team in Enterprise Cybersecurity & Risk (ECR) at Estée Lauder Companies (ELC). Our Risk Management and Data Protection team is responsible for identifying, assessing, and mitigating potential risks to the enterprise and our data. This small but important group actively governs these critical pillars of work, shapes our risk management strategies, finds mitigation strategies. They will lead three teams- (1) Strategic Risk Management and Reduction, (2) Supplier Security and Third Party Risk Management, and (3) Data Security including Data Protection and Classification, Data Resilience and Disaster Recovery, and Data Loss Prevention. Their teams will collaborate across security, technology and business functions and will help to directly fortify the organization against evolving risks.
What You'll Do
As the Vice President, Risk Management and Data Security, you will lead the company's approach to cybersecurity and technology risk management and securing our data in its various forms, in collaboration with data and analytics and data privacy.
In this exciting new role, you will:
- Lead and develop teams across technology risk, data protection, and security.
- Establish governance forums for risk, security, and data protection decisions.
- Partner with IT, Engineering, Legal, Compliance, and Product teams.
- Translate technical and cyber risk into clear executive-level reporting.
- Drive accountability without creating friction or unnecessary bureaucracy.
- Drive consistent governance cadence with clear decision outcomes.
- Have strong collaboration with technology and business leaders.
- Maintain executive trust in risk and security reporting.
Risk Management and Reduction:
This strategic function will not only oversee the traditional risk management and risk register functions, but design and oversee the modernization of a risk management function meant to resolve and remediate risk, not just track it. This is an expansion of the "second line of defense" ensuring risk is addressed in meaningful and prioritized ways.
You will help enable innovation, finding the path forward for our technology innovation and help the organization stay at the cutting edge while keeping security risk to a minimum through technical and resolution-focused risk management.
Our risk management function relies more on technical solutions and risk mitigation than most programs, to modernize risk management and create more impact by the function.
You will seek to minimize overall security risk by identifying risks, monitoring requests through approval workflows, providing risk scoring, and presenting data to give a holistic view of the risk associated with risks identified at the company. Then be responsible for lead the effort to find and execute the solution until remediated.
You must have strong technical and business acumen, understanding the details behind and making decisions or influencing based on risk. You must also lead the team in balancing the tradeoffs of having ultimate security and running the business. You must be able to navigate countering perspectives, setting priorities independently, and leading effectively to manage the expectations of our stakeholders and technical and business leadership.
Data Protection and Security:
- Define and own the enterprise data protection vision, roadmap, and operating model
- Serve as the executive authority on data risk, data security, and data lifecycle management
- Translate regulatory, legal, and business requirements into actionable data protection policies
- Build and lead a high-performing global data protection organization
- Define KPIs and dashboards for:
- Data risk posture
- Coverage of discovery and classification
- DLP effectiveness
- Remediation progress
- Regularly brief executive leadership and the board on data protection risks and progress
Data Governance and Policy:
- Establish and oversee enterprise data governance frameworks, including:
- Data ownership and stewardship
- Data lifecycle management
- Data quality, retention, and disposition
- Partner with business and technology leaders to embed governance into day-to-day operations
- Ensure governance scales across cloud, hybrid, and multi-cloud environments
Data Classification and Discovery:
- Own the enterprise data classification strategy, including:
- Sensitive data identification (PII, PHI, PCI, IP, regulated data)
- Labeling and tagging standards
- Implement and mature automated data discovery tools across:
- Endpoints
- SaaS applications
- Cloud storage
- Data lakes and warehouse
- Drive continuous discovery and remediation of exposed, misused, or over-retained data
Data Security and Data Loss Prevention:
- Design and oversee data security controls across:
- Data at rest, in transit, and in use
- Structured and unstructured data
- Lead enterprise DLP strategy and execution, including:
- Endpoint, network, cloud, and SaaS DLP
- Insider risk management
- Exfiltration prevention
- Partner with SOC and Security Operations on detection, response, and incident handling involving data exposure
Cloud and Data Lakes:
- Define standards for secure data management in cloud platforms (AWS, Azure, GCP)
- Ensure protection of data within:
- Cloud storage (S3, Blob, GCS)
- Container security
- Data lakes
- Analytics platforms and AI/ML pipelines
- Implement controls for:
- Encryption and key management
- Access governance
- Data segmentation and isolation
- Cross-border data transfers
- Address emerging risks related to AI training data and model output
Responsibilities
- Leading the ECR team and its technology stakeholders to reduce the risk of technology to the company by identifying and evaluating technology and cyber risks as they are identified. Risks related to but not limited to:
- Architecture, infrastructure, cloud, and applications
- Identity and access management
- Software development and DevSecOps
- Vulnerability management, technical debt, and configuration drift
- Third-party and supply chain technology risk
- Data Lakes and the cloud
- Overseeing risk assessments and data security and protection for:
- New and emerging technologies and platforms
- Cloud migrations and architecture changes
- High-risk vendors and service providers
- Defining risk appetite and tolerance in partnership with leadership, ongoing measurement and reporting on risk against thresholds
- Maintain a technology and cyber risk register with clear ownership and mitigation plans.
- Overseeing and redefining the risk identification and risk management processes
- Responsible for reviewing risks through triage and evaluative score risk level and severity with a focus on defining a potential path for remediation
- Collaborating to define appropriate solutions to mitigate or remediate the risk by partnering with key stakeholders in ECR, IT, and the business, which will require consensus building and managing disagreements
Responsibilities Contd
- Enabling balanced risk decisions by providing recommendations to leadership, escalating based on severity and risk level to ensure appropriate cyber protection capabilities and resiliency are built into the plans.
- Translating technical risk into business impact and likelihood.
- Providing regular risk reporting to executive leadership.
- Defining and execute the data protection strategy focused on risk reduction.
- Establishing and enforcing:
- Data classification and labeling
- Data handling and retention standards
- Access controls and least-privilege principles
- In all areas of the business and in all technology platforms
- Partnering with Privacy, Legal, and Compliance to ensure regulatory data protection requirements are met (e.g., GDPR, CCPA/CPRA, HIPAA, PCI DSS).
- Overseeing and ensuring the design and implementation of:
- Encryption at rest and in transit
- Data Loss Prevention (DLP) capabilities
- Monitoring of data access and movement throughout the enterprise
- Partnering with Architecture and technology teams to ensure our Zero trust framework ensures data is protected at all times
- Helping govern the response to data exposure and data breach incidents both internally as well as with third parties.
Technical Proficiency:
- Cybersecurity Depth: Cybersecurity skills include exposure to multiple cybersecurity domains e.g. cybersecurity architecture, engineering, operations, IDAM.
- Cyber attack framework: First-hand experience in cybersecurity attacks and controls and how one works against the other. Experience with industry cybersecurity best practices and domains, with a constant willingness to learn more. Understanding of the MITRE ATT&CK framework.
- IT Proficiency: At least 2 years delivering in at least 1 domain of information technology such as networks, application development, and infrastructure. Basic SDLC knowledge to include engineering and deployment plans and review boards.
- Risk Management: Experience with ServiceNow and eGRC tools and the Integrated Risk Modules within.
- Data Governance, Loss Prevention and Insider Threat: Expertise in governing framework for DLP monitoring and configuration. Data discovery experience in
- Problem-Solving and Proactivity: Ability to identify opportunities for improvement and assist in the implementation of solutions. Initiative and autonomy in supporting ECR's strategic and operational goals.
- Collaborative Mindset: Strong teamwork and community-building skills with the ability to collaborate effectively with cross-functional teams and stakeholders at various levels of seniority.
- Administrative skill: Exposure to foundational data analytics. Basic Excel skills. Basic PowerPoint and Power BI Reporting.
- Communication Skills: Ability to communicate effectively with both technical and non-technical stakeholders.
- Adaptability and Flexibility: Ability to work in a dynamic environment and adapt to changing priorities.
- Attention to Detail: Strong organizational skills and attention to detail in data analysis and reporting.
Qualifications
- Bachelor's degree in Computer Science or Cybersecurity related field - required
- Post-graduate work or thesis in Risk Management - preferred
- Minimum 15+ years relevant experience within Information or Cyber Security
- 8+ years experience serving specifically in Cybersecurity leadership roles
- Technical certification such as OSCP, CEH, CCSP, PenTest+, CISSP, SANS GIAC or equivalent to demonstrate technical proficiency - strongly preferred
- Must have hands on experience delivering in security capabilities and the technologies powering a security stack, as well as first-hand knowledge of what it takes to engineer and deliver on IT and security technologies and controls
- Must have experience in making security decisions, prioritization, and trade-offs based on risk
- Experience delivering in at least two of the three lines of defense, demonstrating an understanding of what it's like to be in the audit or owner seat.
- Previous business management experience preferred, demonstrating effective senior stakeholder engagement and influence capability
- Demonstrated experience in analysis, data gathering, data collation and data interpretation
- Strong working knowledge of security frameworks, policies and industry standards, appropriate and secure functionality of infrastructure and applications, and experience in assessing and mitigating technology risk
- Strong understanding of and experience adhering to industry standards and frameworks such as NIST CSF, PCI, SOX, ISO/IEC 27001, NIST SP800, COBIT, ITIL, etc.
- Ability to dive deeply into technical subject matter with IT and Security leadership and SMEs, influencing and leading change in the technical and process approaches in order to improve the security of the organization
- Ability to effectively communicate technical topics in the business language in order to drive successful outcomes for the organizationDemonstration of leadership/management assignments, and prioritization of competing urgencies
- Broad experience in team management with a global and virtual capability, demonstrating strong leadership, influence and motivational skills with a known good reputation in both skil