×
Register Here to Apply for Jobs or Post Jobs. X

Sr. Security Engineer (Hybrid in Irvington, NY

Remote / Online - Candidates ideally in
New York, USA
Listing for: Eileen Fisher
Full Time, Part Time, Remote/Work from Home position
Listed on 2026-08-04
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 150000 - 190000 USD Yearly USD 150000.00 190000.00 YEAR
Job Description & How to Apply Below
Position: Sr. Security Engineer (Hybrid in Irvington, NY)

** This is a hybrid role with 1-2 days/week in the office in Irvington, NY. We are seeking candidates who will not require sponsorship now or in the future**

We are seeking a Senior IT Security Engineer to serve as the primary owner of information security across EILEEN FISHER’s entire technology landscape. This is a hands‑on leadership role responsible for managing all aspects of IT security—from PCI-DSS compliance and IT governance to WAF management, e‑commerce protection, and safeguarding the systems and devices used by employees across retail, corporate, and remote environments.

The ideal candidate is a seasoned security professional who can operate independently, build and mature a security program, and serve as the go‑to expert for all security matters within the organization.

Summary of

Duties and Responsibilities:

PCI-DSS & Compliance Ownership
  • Own end-to-end PCI-DSS compliance across all retail point-of-sale, e-commerce, and payment processing environments
  • Lead annual PCI assessments, QSA engagements, and remediation tracking to ensure continuous compliance
  • Maintain and enforce the cardholder data environment (CDE) scope, segmentation, and documentation
  • Coordinate PCI evidence collection, SAQ/ROC preparation, and audit readiness across all relevant systems
IT Governance & Security Program Management
  • Develop, implement, and continuously improve IT security policies, standards, and procedures aligned with business strategy and frameworks (NIST CSF, CIS Controls, ISO 27001)
  • Lead the annual enterprise risk assessment process, tracking findings and driving remediation to closure
  • Establish and report on security KPIs and metrics to IT leadership and the executive team
  • Own the security technology roadmap and prioritize investments in tools, controls, and capabilities
WAF & E-Commerce Security
  • Serve as the primary owner of the organization’s WAF provider relationship—managing configuration, tuning, rule sets, and escalations to protect e‑commerce and customer‑facing platforms
  • Monitor and respond to WAF alerts, DDoS events, bot activity, and web application threats
  • Secure payment gateways, APIs, and customer data flows in alignment with PCI-DSS and OWASP best practices
  • Partner with the e‑commerce and development teams to embed security into the SDLC and deployment workflows
Employee & Endpoint Security
  • Oversee endpoint protection across all employee devices, including corporate laptops, retail POS terminals, and mobile devices
  • Manage email security, IAM, SSO/MFA (Okta, Azure AD), and privileged access controls
  • Design and deliver security awareness training to protect employees from phishing, social engineering, and insider threats
  • Enforce policies for secure remote work, BYOD, and store‑level IT environments
Security Operations
  • Direct day‑to‑day security operations including network monitoring, SIEM management, IDS/IPS, vulnerability scanning, and patch management
  • Supervise incident response activities from detection through post‑incident review and lessons learned
  • Manage certificate lifecycle, sensitive data handling, and encryption standards (TLS/SSL, PKI, key management)
  • Conduct and coordinate penetration testing and vulnerability management programs, tracking remediation to resolution
Cloud & Infrastructure Security
  • Own security controls across cloud environments (AWS, Azure) including IAM, security groups, logging, and compliance tooling
  • Collaborate with IT infrastructure teams to harden systems, enforce least‑privilege, and maintain secure baselines
  • Ensure secure configurations for SaaS applications, APIs, and third‑party integrations

PERFORMS OTHER RELATED DUTIES AND ASSIGNMENTS AS REQUIRED.

#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary