Eileen Fisher

Eileen Fisher

1 open position available

1 location
1 employment type
Actively hiring
Other

Latest Positions

Showing 1 most recent job
Eileen Fisher

Sr. Security Engineer (Hybrid in Irvington, NY)

Eileen FisherIrvington, New YorkOther
View Job
Compensation$85K - 130K a year

Manage PCI-DSS compliance, IT governance, endpoint and cloud security, and daily security operations. | Experienced security professional able to independently build and mature security programs without visa sponsorship. | **This is a hybrid role with 1-2 days/week in the office in Irvington, NY.  We are seeking candidates who will not require sponsorship now or in the future** We are seeking a Senior IT Security Engineer to serve as the primary owner of information security across EILEEN FISHER’s entire technology landscape. This is a hands-on leadership role responsible for managing all aspects of IT security—from PCI-DSS compliance and IT governance to WAF management, e-commerce protection, and safeguarding the systems and devices used by employees across retail, corporate, and remote environments. The ideal candidate is a seasoned security professional who can operate independently, build and mature a security program, and serve as the go-to expert for all security matters within the organization. Summary of Duties and Responsibilities: PCI-DSS & Compliance Ownership •     Own end-to-end PCI-DSS compliance across all retail point-of-sale, e-commerce, and payment processing environments •     Lead annual PCI assessments, QSA engagements, and remediation tracking to ensure continuous compliance •     Maintain and enforce the cardholder data environment (CDE) scope, segmentation, and documentation •     Coordinate PCI evidence collection, SAQ/ROC preparation, and audit readiness across all relevant systems   IT Governance & Security Program Management •     Develop, implement, and continuously improve IT security policies, standards, and procedures aligned with business strategy and frameworks (NIST CSF, CIS Controls, ISO 27001) •     Lead the annual enterprise risk assessment process, tracking findings and driving remediation to closure •     Establish and report on security KPIs and metrics to IT leadership and the executive team •     Own the security technology roadmap and prioritize investments in tools, controls, and capabilities   WAF & E-Commerce Security •     Serve as the primary owner of the organization’s WAF provider relationship—managing configuration, tuning, rule sets, and escalations to protect e-commerce and customer-facing platforms •     Monitor and respond to WAF alerts, DDoS events, bot activity, and web application threats •     Secure payment gateways, APIs, and customer data flows in alignment with PCI-DSS and OWASP best practices •     Partner with the e-commerce and development teams to embed security into the SDLC and deployment workflows   Employee & Endpoint Security •     Oversee endpoint protection across all employee devices, including corporate laptops, retail POS terminals, and mobile devices •     Manage email security, IAM, SSO/MFA (Okta, Azure AD), and privileged access controls •     Design and deliver security awareness training to protect employees from phishing, social engineering, and insider threats •     Enforce policies for secure remote work, BYOD, and store-level IT environments   Security Operations •     Direct day-to-day security operations including network monitoring, SIEM management, IDS/IPS, vulnerability scanning, and patch management •     Supervise incident response activities from detection through post-incident review and lessons learned •     Manage certificate lifecycle, sensitive data handling, and encryption standards (TLS/SSL, PKI, key management) •     Conduct and coordinate penetration testing and vulnerability management programs, tracking remediation to resolution   Cloud & Infrastructure Security •     Own security controls across cloud environments (AWS, Azure) including IAM, security groups, logging, and compliance tooling •     Collaborate with IT infrastructure teams to harden systems, enforce least-privilege, and maintain secure baselines •     Ensure secure configurations for SaaS applications, APIs, and third-party integrations PERFORMS OTHER RELATED DUTIES AND ASSIGNMENTS AS REQUIRED.

Incident Response
Vulnerability Management
Cloud Security
Identity and Access Management
PCI-DSS Compliance
Direct Apply
Posted 2 months ago

Ready to join Eileen Fisher?

Create tailored applications specifically for Eileen Fisher with our AI-powered resume builder

Get Started for Free

Ready to have AI work for you in your job search?

Sign-up for free and start using JobLogr today!

Get Started »
JobLogr badgeTinyLaunch BadgeJobLogr - AI Job Search Tools to Land Your Next Job Faster than Ever | Product Hunt