Home
/
Software Engineering
/
Senior Engineer, Application Security, ELC Online
Senior Engineer, Application Security, ELC Online-November 2024
New York
Nov 22, 2024
ABOUT ELC BEAUTY
The Estée Lauder Companies Inc. is one of the world’s leading manufacturers and marketers of quality skin care, makeup, fragrance, and hair care products. The company’s products are sold in approximat
10,000+ employees
Consumer Goods & Services
VIEW COMPANY PROFILE >>
About Senior Engineer, Application Security, ELC Online

  Senior Engineer, Application Security, ELC Online

  WHO WE ARE

  Estée Lauder Companies Online (ELC Online) is the online division of the Estée Lauder Companies Inc. family of brands. We are a tech company, inside of a cosmetics company. We were early adopters of eCommerce in the 90s and have consistently set the industry standard for prestige beauty e-commerce. We support over 400 websites for household names like Estée Lauder, MAC, Clinique, Origins, Jo Malone and Bobbi Brown. We do so from our own in-house technology teams, supported by some great technology partners.

  With headquarters in the heart of Silicon Alley in Manhattan's Flatiron District and offices located around the world, United Kingdom, France, China and many more, we connect with our customers anytime, anywhere, from any device. We're committed to innovation, working with the best tools and technologies available to help our shoppers seamlessly navigate the digital world of beauty. ELC Online is a collaborative work environment that hums with the buzz of 80% female leadership. It's also home to bold technologists who are shaping the future of beauty.

  ROLE SUMMARY

  The Estée Lauder Companies Online platform powers our Online Commerce, Innovation and Omnichannel initiatives for a portfolio of over 400 sites. We are looking for a new member of our Threat Intelligence team, which is part of a larger security group responsible for the security and compliance at ELC Online. The focus of your role will be on application security in particular, and ensuring that possible threats to the e-commerce applications, the platform as a whole, or the infrastructure, are identified, analyzed and remediated in a timely manner.

  WHAT YOU NEED TO SUCCEED

  Have excellent problem-solving skills and be able to perform research and analysis of data and information associated with threat activities. Have a fundamental understanding of different operating systems and concepts related to information security and data privacy. Be language agnostic and agile to pick up new languages and skills and deliver new solutions to unexpected problems. Be willing to learn, follow the trends within the technology space and be able to help future proof solutions. Be able to dedicate time for self-investment through training, certifications, and research. Be open-minded and actively ask questions, listen, and respect other people's opinions. Be able to stay focused on the tasks, prioritize them, and control your time effectively. Be able to communicate effectively with different stakeholders. Be able to work closely with other teams and independently.

  WHAT YOU WILL BE DOING

  Supporting product and development teams in the area of application security, providing hands-on remediation guidance and direction. Verifying the validity of the pentesting reports, internal reports, and external reports related to security findings and potential issues. Analyzing the likelihood of emerging threats impacting the organization and identifying the weaknesses that could be potentially exploited. Delivering reports and recommendations to the business to enable the effectiveness of mitigation and remediation efforts. Analyzing current and planned third-party integrations from the perspective of the risk to security and privacy. Developing mitigation plans and designing technical solutions to address security weaknesses. Participating in and supporting application security reviews and code reviews. Monitoring and analyzing external and internal cyber threats to assess risk. Improving the security tooling, logging and alerting. Providing insights to influence threat mitigation strategies. Consolidating cyber threat intelligence feeds and sources. Analyzing system services and code, and discovering security exposures.

  Qualifications

  TECHNICAL REQUIREMENTS

  Relevant experience in e-commerce, SaaS or similar. Strong knowledge of secure design practices and common software vulnerabilities such as OWASP Top 10 and CWE Top 25. Experience in using DAST and SAST tools, including integrating those into CI/CD and linking them with the issue tracking systems. Experience with Web Application Firewalls and configuring those. Technical expertise in secure software development. Knowledge of common and emerging security threats. Experience in using SEIM systems. Knowledge of Elixir/Erlang and JavaScript is a plus.

  The anticipated base salary range for this position is $98,500 to $165,750. Exact salary depends on several factors such as experience, skills, education, and budget. Salary range may vary based on geographic location. In addition to base salary, this position is eligible for participation in a highly competitive bonus program with possibility for overachievement based on performance and company results as well as participation in the share incentive plan.

  In addition, The Estée Lauder Companies offers a variety of benefits to eligible employees, including health insurance coverage, wellness and family support programs, life and disability insurance, retirement savings plans, paid leave programs, education-related programs, paid holidays and vacation time, and many others. Many of these benefits are subsidized or fully paid for by the company.

  Job: Online / E-Commerce

  Primary Location: US-NY-New York

  Job Type: Standard

  Schedule: Full-time

  Shift: 1st (Day) Shift

  Job Number: 2315009

  We are an equal opportunity employer. Minorities, women, veterans, and individuals with disabilities are encouraged to apply. It is Company's policy not to discriminate against any employee or applicant for employment on the basis of race, color, creed, religion, national origin, ancestry, citizenship status, age, sex or gender (including pregnancy, childbirth and related medical conditions), gender identity or gender expression (including transgender status), sexual orientation, marital status, military service and veteran status, physical or mental disability, protected medical condition as defined by applicable state or local law, genetic information, or any other characteristic protected by applicable federal, state, or local laws and ordinances. The Company will endeavor to provide a reasonable accommodation consistent with the law to otherwise qualified employees and prospective employees with a disability and to employees and prospective employees with needs related to their religious observance or practices. Should you wish to apply for this position or any other position with the Company and you believe you require assistance to complete an application or participate in an interview, please contact [email protected].

Comments
Welcome to zdrecruit comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
SIMILAR JOBS
Senior Software Engineer, Experience Containerization
Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers a
Software Developer in Test - Vice President
iCapital is powering the world’s alternative investment marketplace. Our financial technology platform has transformed how advisors, wealth management firms, asset managers, and banks evaluate and re
Software Engineer (Hybrid)
Software Engineer - IE08DE We're determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to
Lagerleiter*in (d/w/m)
DU BIST MEHR ALS DEIN JOB-TITEL. MEHR ALS ZAHLEN UND BUCHSTABEN IN DEINEM LEBENSLAUF. UND WIR SIND MEHR ALS EIN UNTERNEHMEN. WIE WÄR'S ALSO, WENN WIR UNS EINFACH ZUSAMMENTUN - UND GEMEINSAM NOCH MEHR
Engineering Manager - Corlu IC
ABOUT UNILEVER With 3.4 billion people in over 190 countries using our products every day, Unilever is a business that makes a real impact on the world. Work on brands that are loved and improve the
Staff Software Engineer - Backend (Growth Data Platform Team)
Hinge Health is creating a new health care system, built around you. Accessible to 26 million members across 1,500 customers, Hinge Health is the #1 digital clinic for joint and muscle pain, deliveri
Software Engineer - Card Processing and Authorisation
Company Description Checkout.com is one of the most exciting FinTechs in the world. Our mission is to enable businesses and their communities to thrive in the digital economy. We’re the strategic pay
Software Engineer - Full Stack
OVERVIEW This position can be based out of San Francisco or New York City We're looking for Full-Stack Software Engineers to join our Engineering team. In this role, you will build innovative payment
Sr. Manager, Analytics Engineer - Biopharma
ROLE SUMMARY: Pfizer is seeking hardworking, passionate and results-oriented individuals to join our Analytics Engineering team to build data foundations and tools to craft the future. You will desig
Site Reliability Engineer
At Broadridge, we've built a culture where the highest goal is to empower others to accomplish more. If you're passionate about developing your career, while helping others along the way, come join t
Copyright 2023-2024 - www.zdrecruit.com All Rights Reserved