Find your dream job faster with JobLogr
AI-powered job search, resume help, and more.
Try for Free
Eileen Fisher

Eileen Fisher

via Rival

All our jobs are verified from trusted employers and sources. We connect to legitimate platforms only.

Sr. Security Engineer (Hybrid in Irvington, NY)

Irvington, New York
Other
Posted 7/9/2026
Direct Apply
Key Skills:
Incident Response
Vulnerability Management
Cloud Security
Identity and Access Management
PCI-DSS Compliance

Compensation

Salary Range

$85K - 130K a year

Responsibilities

Manage PCI-DSS compliance, IT governance, endpoint and cloud security, and daily security operations.

Requirements

Experienced security professional able to independently build and mature security programs without visa sponsorship.

Full Description

**This is a hybrid role with 1-2 days/week in the office in Irvington, NY.  We are seeking candidates who will not require sponsorship now or in the future** We are seeking a Senior IT Security Engineer to serve as the primary owner of information security across EILEEN FISHER’s entire technology landscape. This is a hands-on leadership role responsible for managing all aspects of IT security—from PCI-DSS compliance and IT governance to WAF management, e-commerce protection, and safeguarding the systems and devices used by employees across retail, corporate, and remote environments. The ideal candidate is a seasoned security professional who can operate independently, build and mature a security program, and serve as the go-to expert for all security matters within the organization. Summary of Duties and Responsibilities: PCI-DSS & Compliance Ownership •     Own end-to-end PCI-DSS compliance across all retail point-of-sale, e-commerce, and payment processing environments •     Lead annual PCI assessments, QSA engagements, and remediation tracking to ensure continuous compliance •     Maintain and enforce the cardholder data environment (CDE) scope, segmentation, and documentation •     Coordinate PCI evidence collection, SAQ/ROC preparation, and audit readiness across all relevant systems   IT Governance & Security Program Management •     Develop, implement, and continuously improve IT security policies, standards, and procedures aligned with business strategy and frameworks (NIST CSF, CIS Controls, ISO 27001) •     Lead the annual enterprise risk assessment process, tracking findings and driving remediation to closure •     Establish and report on security KPIs and metrics to IT leadership and the executive team •     Own the security technology roadmap and prioritize investments in tools, controls, and capabilities   WAF & E-Commerce Security •     Serve as the primary owner of the organization’s WAF provider relationship—managing configuration, tuning, rule sets, and escalations to protect e-commerce and customer-facing platforms •     Monitor and respond to WAF alerts, DDoS events, bot activity, and web application threats •     Secure payment gateways, APIs, and customer data flows in alignment with PCI-DSS and OWASP best practices •     Partner with the e-commerce and development teams to embed security into the SDLC and deployment workflows   Employee & Endpoint Security •     Oversee endpoint protection across all employee devices, including corporate laptops, retail POS terminals, and mobile devices •     Manage email security, IAM, SSO/MFA (Okta, Azure AD), and privileged access controls •     Design and deliver security awareness training to protect employees from phishing, social engineering, and insider threats •     Enforce policies for secure remote work, BYOD, and store-level IT environments   Security Operations •     Direct day-to-day security operations including network monitoring, SIEM management, IDS/IPS, vulnerability scanning, and patch management •     Supervise incident response activities from detection through post-incident review and lessons learned •     Manage certificate lifecycle, sensitive data handling, and encryption standards (TLS/SSL, PKI, key management) •     Conduct and coordinate penetration testing and vulnerability management programs, tracking remediation to resolution   Cloud & Infrastructure Security •     Own security controls across cloud environments (AWS, Azure) including IAM, security groups, logging, and compliance tooling •     Collaborate with IT infrastructure teams to harden systems, enforce least-privilege, and maintain secure baselines •     Ensure secure configurations for SaaS applications, APIs, and third-party integrations PERFORMS OTHER RELATED DUTIES AND ASSIGNMENTS AS REQUIRED.

This job posting was last updated on 7/10/2026

Ready to have AI work for you in your job search?

Sign-up for free and start using JobLogr today!

Get Started »
JobLogr badgeTinyLaunch BadgeJobLogr - AI Job Search Tools to Land Your Next Job Faster than Ever | Product Hunt