> Markdown version of [/jobs/ext/1229113-security-engineer](https://www.wearedevelopers.com/jobs/ext/1229113-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** EILEEN FISHER - **Location:** Irvington, NY, United States (Remote available) - **Experience:** Expert - **Salary:** $120,000.0 - $135,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Antivirus, Software System Penetration Testing, Microsoft Azure, Bash Shell, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Customer Data Management, Identity and Access Management, IT Management, Intrusion Detection Systems, Python (Programming Language), Key Management, Network Monitoring, Open Web Application Security, Payment Gateway, PCI Data Security Standards, Public Key Infrastructure, Windows PowerShell, Systems Development Life Cycle, Azure Active Directory, Phishing, Akamai, Security Information and Event Management, Software Vulnerability Management, Web Applications, EndPointSecurity, Data Logging, Data Processing, Scripting, Transport Layer Security, Cloud Platform System, In-Plane Switching (IPS), Okta, Delivery Pipeline, Information Technology, Patch Management, Cloudflare, Integration Frameworks, CIS Benchmarks, Ddos, Vulnerability Analysis - **Published:** July 10, 2026 - **Apply:** https://jobs.silkroad.com/EileenFisher/USCareers/Apply/MultiForm/305111?embedded=true ## About the Role Education: Bachelors degree in Computer Science or equivalent experience. * 7+ years of progressive IT security experience, with at least 3 years in a senior or lead security role * Demonstrated end-to-end ownership of PCI-DSS compliance-including QSA engagement, CDE scoping, SAQ/ROC preparation, and continuous compliance across retail POS and e-commerce channels * Hands-on experience managing WAF platforms (e.g., Cloudflare, Imperva, Akamai, AWS WAF) including rule tuning, alert response, and vendor relationship management * Experience securing e-commerce environments: payment gateways, APIs, and customer data in alignment with PCI-DSS and OWASP Top 10 * Proven experience building and managing IT governance programs-policies, risk assessments, KPIs, and security roadmaps * Ability to manage security across a distributed workforce including retail stores, corporate offices, and remote employees * Experience with cloud security across AWS and/or Azure (IAM, security groups, logging, Microsoft Defender, Azure Defender) * Strong knowledge of identity and access management (IAM), SSO/MFA (Okta, Azure AD/Entra ID), and privileged access controls * Experience with SIEM platforms, IDS/IPS, endpoint detection & response (EDR), and vulnerability management tools * Strong understanding of encryption, TLS/SSL, PKI, and key management * Scripting/automation skills in Python, Bash, or PowerShell * Excellent communication skills with the ability to present security risk to executive and non-technical audiences * Industry certifications preferred: CISSP, CISM, PCI-ISA/QSA, or equivalent ## Description We are seeking a Senior IT Security Engineer to serve as the primary owner of information security across EILEEN FISHER's entire technology landscape. This is a hands-on leadership role responsible for managing all aspects of IT security-from PCI-DSS compliance and IT governance to WAF management, e-commerce protection, and safeguarding the systems and devices used by employees across retail, corporate, and remote environments. The ideal candidate is a seasoned security professional who can operate independently, build and mature a security program, and serve as the go-to expert for all security matters within the organization., * Own end-to-end PCI-DSS compliance across all retail point-of-sale, e-commerce, and payment processing environments * Lead annual PCI assessments, QSA engagements, and remediation tracking to ensure continuous compliance * Maintain and enforce the cardholder data environment (CDE) scope, segmentation, and documentation * Coordinate PCI evidence collection, SAQ/ROC preparation, and audit readiness across all relevant systems IT Governance & Security Program Management * Develop, implement, and continuously improve IT security policies, standards, and procedures aligned with business strategy and frameworks (NIST CSF, CIS Controls, ISO 27001) * Lead the annual enterprise risk assessment process, tracking findings and driving remediation to closure * Establish and report on security KPIs and metrics to IT leadership and the executive team * Own the security technology roadmap and prioritize investments in tools, controls, and capabilities WAF & E-Commerce Security * Serve as the primary owner of the organization's WAF provider relationship-managing configuration, tuning, rule sets, and escalations to protect e-commerce and customer-facing platforms * Monitor and respond to WAF alerts, DDoS events, bot activity, and web application threats * Secure payment gateways, APIs, and customer data flows in alignment with PCI-DSS and OWASP best practices * Partner with the e-commerce and development teams to embed security into the SDLC and deployment workflows Employee & Endpoint Security * Oversee endpoint protection across all employee devices, including corporate laptops, retail POS terminals, and mobile devices * Manage email security, IAM, SSO/MFA (Okta, Azure AD), and privileged access controls * Design and deliver security awareness training to protect employees from phishing, social engineering, and insider threats * Enforce policies for secure remote work, BYOD, and store-level IT environments Security Operations * Direct day-to-day security operations including network monitoring, SIEM management, IDS/IPS, vulnerability scanning, and patch management * Supervise incident response activities from detection through post-incident review and lessons learned * Manage certificate lifecycle, sensitive data handling, and encryption standards (TLS/SSL, PKI, key management) * Conduct and coordinate penetration testing and vulnerability management programs, tracking remediation to resolution Cloud & Infrastructure Security * Own security controls across cloud environments (AWS, Azure) including IAM, security groups, logging, and compliance tooling * Collaborate with IT infrastructure teams to harden systems, enforce least-privilege, and maintain secure baselines * Ensure secure configurations for SaaS applications, APIs, and third-party integrations PERFORMS OTHER RELATED DUTIES AND ASSIGNMENTS AS REQUIRED. ## Related Videos - [What the Heck is Edge Computing Anyway?](https://www.wearedevelopers.com/videos/593-what-the-heck-is-edge-computing-anyway) - [WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking](https://www.wearedevelopers.com/videos/1331-wearedevelopers-live-chrome-for-sale-comet-the-upcoming-perplexity-browser-stealing-and-leaking) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Micro-frontends anti-patterns](https://www.wearedevelopers.com/videos/299-micro-frontends-anti-patterns) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Fireside Chat with Cloudflare's Chief Strategy Officer, Stephanie Cohen (with Mike Butcher MBE)](https://www.wearedevelopers.com/videos/1366-fireside-chat-with-cloudflare-s-chief-strategy-officer-stephanie-cohen-with-mike-butcher-mbe) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)