About the Company
e.l.f. Beauty, Inc. stands with every eye, lip, face and paw. Our deep commitment to clean, cruelty free beauty at an incredible value has fueled the success of our flagship brand e.l.f. Cosmetics since 2004 and driven our portfolio expansion. Today, our multi-brand portfolio includes e.l.f. Cosmetics, e.l.f. SKIN, pioneering clean beauty brand Well People, Keys Soulcare, a groundbreaking lifestyle beauty brand created with Alicia Keys, Naturium, high-performance, biocompatible, clinically-effective and accessible skin care, and our newest brand, rhode, a line of curated skincare essentials, formulated for a variety of skin types and needs with high performance ingredients, it’s a daily routine that nourishes your skin barrier over time.
In our Fiscal year 25, we had net sales of $1 Billion and our business performance has been nothing short of extraordinary with 26 consecutive quarters of net sales growth. We are the #2 mass cosmetics brand in the US and are the fastest growing mass cosmetics brand among the top 5. Our total compensation philosophy offers every full-time new hire competitive pay and benefits, bonus eligibility (200% of target over the last six fiscal years), equity, flexible time off, year-round half-day Fridays, and a hybrid 3 day in office, 2 day at home work environment. We believe the combination of our unique culture, total compensation, workplace flexibility and care for the team is unmatched across not just beauty but any industry.
Position Summary
We are seeking a highly skilled Senior Information Security Engineer to lead enterprise-wide cybersecurity initiatives and strengthen our security posture across on-premises and cloud environments. This role involves designing and implementing advanced security solutions, including Zero Trust, DLP, Cloud Security, Network Segmentation, IAM, and Security Automation. The ideal candidate will collaborate with cross-functional teams to identify risks, develop mitigation strategies, ensure regulatory compliance, and proactively defend against evolving threats while safeguarding our systems, data, and infrastructure.
Must Have
- Strong Technical Security Foundation & Architecture
Deep knowledge of network, cloud, and endpoint security.
Hands-on experience with firewalls, SIEM tools (e.g., Splunk, Sentinel), EDR/XDR, IAM, and vulnerability management.
Understanding of encryption, authentication, and secure architecture design.
- Incident Response & Threat Management Skills
Ability to detect, analyze, and respond to security incidents effectively.
Skilled in log analysis, threat hunting, and forensics.
Familiarity with MITRE ATT&CK, common attack techniques, and SOC operations.
- Risk Assessment & Communication
Strong ability to assess vulnerabilities, prioritize risks, and implement mitigations.
Can translate technical findings into business impact and communicate clearly with both technical and non-technical teams.
Understanding of security frameworks and compliance standards (NIST, ISO 27001, CIS).