Talent.com
Senior IT Security Engineer

Senior IT Security Engineer

E.L.F. Beauty, Inc.New York, NY, United States
1 day ago
Job type
  • Full-time
Job description

About the Company

e.l.f. Beauty, Inc. stands with every eye, lip, face and paw. Our deep commitment to clean, cruelty free beauty at an incredible value has fueled the success of our flagship brand e.l.f. Cosmetics since 2004 and driven our portfolio expansion. Today, our multi-brand portfolio includes e.l.f. Cosmetics, e.l.f. SKIN, pioneering clean beauty brand Well People, Keys Soulcare, a groundbreaking lifestyle beauty brand created with Alicia Keys, Naturium, high-performance, biocompatible, clinically-effective and accessible skin care, and our newest brand, rhode, a line of curated skincare essentials, formulated for a variety of skin types and needs with high performance ingredients, it's a daily routine that nourishes your skin barrier over time.

In our Fiscal year 25, we had net sales of $1 Billion and our business performance has been nothing short of extraordinary with 26 consecutive quarters of net sales growth. We are the #2 mass cosmetics brand in the US and are the fastest growing mass cosmetics brand among the top 5. Our total compensation philosophy offers every full-time new hire competitive pay and benefits, bonus eligibility (200% of target over the last six fiscal years), equity, flexible time off, year-round half-day Fridays, and a hybrid 3 day in office, 2 day at home work environment. We believe the combination of our unique culture, total compensation, workplace flexibility and care for the team is unmatched across not just beauty but any industry.

Visit our Career Page to learn more about our team :

Position Summary

We are seeking a highly skilled Senior Information Security Engineer to lead enterprise-wide cybersecurity initiatives and strengthen our security posture across on-premises and cloud environments. This role involves designing and implementing advanced security solutions, including Zero Trust, DLP, Cloud Security, Network Segmentation, IAM, and Security Automation. The ideal candidate will collaborate with cross-functional teams to identify risks, develop mitigation strategies, ensure regulatory compliance, and proactively defend against evolving threats while safeguarding our systems, data, and infrastructure.

Responsibilities

  • Design, build, deploy, and maintain enterprise security technologies and solutions aligned with business objectives, compliance requirements, and the cybersecurity program.
  • Develop, document, and enforce security policies, standards, and procedures based on frameworks such as NIST, CIS, ISO 27001, and SOX while advancing overall security maturity, governance, and processes.
  • Lead strategic security initiatives, including Zero Trust architecture, Data Loss Prevention (DLP), Cloud Security, Network Segmentation, IAM, Endpoint Security modernization, and security automation.
  • Manage and improve email security, DNS security, and other protective controls to defend against phishing, malware, data exfiltration, and domain-based threats.
  • Lead vulnerability management programs and drive remediation efforts, providing visibility into risks and progress to stakeholders.
  • Oversee incident response lifecycle-detection, analysis, containment, remediation, post-incident review-and continuously enhance disaster recovery and business continuity plans.
  • Monitor and analyze security events and network activity (e.g., traffic analysis, host behavior, forensics, kill chain, Windows event analysis), tuning tools, and event correlation for accurate threat detection.
  • Collaborate with IT, DevOps, and digital teams to embed security into system design, application development, deployment pipelines, and cloud infrastructure.
  • Evaluate and review vendor and partner security practices to ensure alignment with organizational standards.
  • Produce regular security dashboards and metrics to report on incidents, threats, and operational effectiveness.
  • Lead security awareness training, mentor junior engineers, and guide cross-functional teams on secure design principles and best practices.
  • Stay current on emerging threats, vulnerabilities, and technologies to enhance enterprise resilience.

Must Have

  • Strong Technical Security Foundation & Architecture
  • Deep knowledge of network, cloud, and endpoint security .

    Hands-on experience with firewalls, SIEM tools (e.g., Splunk, Sentinel) , EDR / XDR , IAM , and vulnerability management .

    Understanding of encryption, authentication, and secure architecture design .

  • Incident Response & Threat Management Skills
  • Ability to detect, analyze, and respond to security incidents effectively.

    Skilled in log analysis, threat hunting, and forensics .

    Familiarity with MITRE ATT&CK , common attack techniques , and SOC operations .

  • Risk Assessment & Communication
  • Strong ability to assess vulnerabilities , prioritize risks , and implement mitigations .

    Can translate technical findings into business impact and communicate clearly with both technical and non-technical teams.

    Understanding of security frameworks and compliance standards (NIST, ISO 27001, CIS).

    Requirements :

  • Bachelor's degree in Computer Science, Cybersecurity, or related field; Master's preferred.
  • 7+ years of experience in information security engineering, architecture, or operations.
  • Expertise in cloud security (AWS, Azure, GCP), data protection, IAM / SSO / MFA, email and DNS security, and secure network architecture.
  • Hands-on experience with key security technologies : firewalls, VPN, NAC, EDR / MDR, IPS / IDS, SIEM, DLP, vulnerability management, and email security platforms (Proofpoint, Mimecast, Microsoft 365 Defender).
  • Strong understanding of Zero Trust, endpoint protection, DevSecOps, security automation, and scripting (Python, PowerShell, Bash).
  • Proven ability to lead incident response, risk assessments, threat detection, and remediation efforts.
  • Experience implementing DNS protection solutions (Cisco Umbrella, Cloudflare, Infoblox, Valimail).
  • Knowledge of security frameworks and compliance standards : NIST CSF, CIS Controls, ISO 27001, SOX.
  • Demonstrated success in leading security awareness programs, mentoring team members, and advancing security program maturity.
  • Relevant certifications preferred : CISSP, CISM, CISA, GIAC, Microsoft Security certifications, AWS Security Specialty, Azure Security Engineer Associate.
  • Strong communication, leadership, and ability to manage multiple security initiatives.
  • $110,000 - $140,000 a year

    This job description is intended to describe the general nature and level of work being performed in this position. It also reflects the general details considered necessary to describe the principal functions of the job identified, and shall not be considered, as detailed description of all the work required inherent in the job. It is not an exhaustive list of responsibilities, and it is subject to changes and exceptions at the supervisors' discretion.

    e.l.f. Beauty respects your privacy. Please see our Job Applicant Privacy Notice (www.elfbeauty.com / us-job-applicant-privacy-notice) for how your personal information is used and shared.

    We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

    Create a job alert for this search

    It Security Engineer • New York, NY, United States

    Related jobs
    • Promoted
    Senior Infrastructure Security Engineer

    Senior Infrastructure Security Engineer

    Motion RecruitmentNew York, NY, United States
    Full-time
    One of our clients is seeking an experienced Infrastructure Security Engineer to help design, implement, and maintain the security of their cloud and on-premises infrastructure.You will be responsi...Show moreLast updated: 9 days ago
    • Promoted
    Sr. IT Security Engineer

    Sr. IT Security Engineer

    MindlanceJersey City, NJ, United States
    Full-time
    Hybrid onsite at Dallas, TX, 75019 / Tampa, FL, 33647 / Jersey City, NJ, 07310 / Boston, MA, 02210.Security Engineer to design, implement, and maintain. The ideal candidate will have experience with...Show moreLast updated: 1 day ago
    • Promoted
    IT SECURITY PRINCIPAL ENGINEER

    IT SECURITY PRINCIPAL ENGINEER

    Tekfortune IncSecaucus, NJ, United States
    Permanent
    Tekfortune is a fast-growing consulting firm specialized in permanent, contract & project-based staffing services for world's leading organizations in a broad range of industries.In this quickly ch...Show moreLast updated: 1 day ago
    • Promoted
    IT Security Engineer

    IT Security Engineer

    Shtudy, IncNew York, NY, United States
    Full-time
    IT Security Engineer ($125,000 - $155,000).Join a well-established organization focused on empowering individuals through secure technological solutions. We are seeking an experienced IT Security En...Show moreLast updated: 1 day ago
    • Promoted
    Senior Infrastructure Security Engineer (m / f / d)

    Senior Infrastructure Security Engineer (m / f / d)

    Raisin GmbHUnion, NJ, United States
    Full-time
    Senior Infrastructure Security Engineer (m / f / d).We are seeking a Senior Infrastructure Security Engineer with extensive experience in securing cloud environments, particularly AWS.This pivotal role...Show moreLast updated: 1 day ago
    • Promoted
    • New!
    IT & Security Engineer

    IT & Security Engineer

    Norm AI, IncNew York, NY, United States
    Full-time
    Norm Ai, the leading Legal & Compliance AI company, has a client base with a combined $30 trillion in assets under management. By turning legal code into AI code, Norm enables enterprises to move fa...Show moreLast updated: 5 hours ago
    • Promoted
    • New!
    Senior Security Engineer, Insider Threat

    Senior Security Engineer, Insider Threat

    DoorDash USANew York, NY, United States
    Full-time
    Senior Security Engineer, Insider Threat.Chicago, IL; United States - Remote.At DoorDash we’re building the industry’s most scalable and reliable delivery network to support our three-sided marketp...Show moreLast updated: 17 hours ago
    • Promoted
    Senior IT Systems Security Engineer (External)

    Senior IT Systems Security Engineer (External)

    SerotoninNew York, NY, United States
    Full-time
    Our client is on a mission to build a more financially inclusive future by making the power and utility of the US Dollar accessible across the globe. AUSD is the first fully collateralized, freely t...Show moreLast updated: 1 day ago
    • Promoted
    IT Security Engineer

    IT Security Engineer

    NYCIRBNew York, NY, United States
    Full-time
    The New York Compensation Insurance Rating Board (NYCIRB) is a non-profit, unincorporated association of insurance carriers. NYCIRB is licensed by the New York State Department of Financial Services...Show moreLast updated: 1 day ago
    • Promoted
    Senior Infrastructure Security Engineer

    Senior Infrastructure Security Engineer

    Unity TechnologiesNew York, NY, United States
    Full-time
    Senior Infrastructure Security Engineer.Unity is seeking a Senior Infrastructure Security Engineer to join our Security team to drive continuous improvement in security standards, policies, and Sec...Show moreLast updated: 9 days ago
    • Promoted
    IT Senior Security Engineer

    IT Senior Security Engineer

    Gellert Global GroupElizabeth, NJ, United States
    Full-time
    Gellert Global Group consists of many of the leading North American food importing companies (Atalanta Corporation, Camerican International, Finica, Tipico Cheese Products) and has been importing f...Show moreLast updated: 1 day ago
    • Promoted
    Security Engineer

    Security Engineer

    SNCHHicksville, NY, United States
    Full-time
    Mount Sinai South Nassau provides a salary range in good faith determination of potential compensation to comply with the New York State law on Salary Transparency in Job Advertisements.Actual sala...Show moreLast updated: 1 day ago
    • Promoted
    IT Security Engineer

    IT Security Engineer

    Jane StreetNew York, NY, United States
    Full-time
    We are looking for an IT Security Engineer with a strong Windows engineering background and practical exposure to modern platform security controls to join a global team dedicated to securing Jane ...Show moreLast updated: 1 day ago
    • Promoted
    IT Security Engineer

    IT Security Engineer

    Staffing the UniverseNew York, NY, United States
    Full-time
    Contract Position Summary : Experience (Years) : 6-8 Years.IT Security Engineer CrowdStrike Alert Coordination.CrowdStrike Alert Coordination And Analysis, CS Sensor Deployment Coordination, CSPM Con...Show moreLast updated: 30+ days ago
    • Promoted
    Senior / Staff Enterprise Security Engineer

    Senior / Staff Enterprise Security Engineer

    Abridge Al, IncNew York, NY, United States
    Full-time
    Abridge was founded in 2018 with the mission of powering deeper understanding in healthcare.Our AI-powered platform was purpose-built for medical conversations, improving clinical documentation eff...Show moreLast updated: 1 day ago
    • Promoted
    Senior Security Systems Engineer

    Senior Security Systems Engineer

    EPAM Systems IncNew York, NY, United States
    Full-time
    Senior Security Systems Engineer.WiFi performance testing, automation, and network analysis in laboratory environments.This role requires deep expertise in wireless protocols, hands-on experience w...Show moreLast updated: 1 day ago
    • Promoted
    IT Security Engineer

    IT Security Engineer

    InterSourcesNew York, NY, United States
    Full-time
    CrowdStrike alert coordination CrowdStrike alert coordination and analysis, CS sensor deployment coordination, CSPM configuration. CrowdStrike Endpoint Detection And Response.Certified Diverse Suppl...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Security Engineer

    Senior Security Engineer

    S&P GlobalNew York, NY, United States
    Full-time
    Kensho is S&P Global's hub for AI innovation and transformation.With expertise in Machine Learning and data discovery, we develop and deploy novel solutions for S&P Global and its customers worldwi...Show moreLast updated: 1 day ago