About the Role
Serve as the primary owner of information security across EILEEN FISHER’s technology landscape. This hands-on leadership role is responsible for managing all aspects of IT security, including PCI-DSS compliance, IT governance, WAF management, e-commerce protection, and safeguarding systems and devices used by employees across retail, corporate, and remote environments. The ideal candidate will operate independently, build and mature a security program, and act as the go-to expert for all security matters.
Responsibilities
- Own end-to-end PCI-DSS compliance across all retail point-of-sale, e-commerce, and payment processing environments
- Lead annual PCI assessments, QSA engagements, and remediation tracking
- Maintain and enforce the cardholder data environment (CDE) scope, segmentation, and documentation
- Coordinate PCI evidence collection, SAQ/ROC preparation, and audit readiness
- Develop, implement, and continuously improve IT security policies, standards, and procedures aligned with business strategy and frameworks (NIST CSF, CIS Controls, ISO 27001)
- Lead the annual enterprise risk assessment process, tracking findings and driving remediation
- Establish and report on security KPIs and metrics to IT leadership and the executive team
- Own the security technology roadmap and prioritize investments in tools, controls, and capabilities
- Serve as the primary owner of the organization’s WAF provider relationship—managing configuration, tuning, rule sets, and escalations
- Monitor and respond to WAF alerts, DDoS events, bot activity, and web application threats
- Secure payment gateways, APIs, and customer data flows in alignment with PCI-DSS and OWASP best practices
- Partner with the e-commerce and development teams to embed security into the SDLC and deployment workflows
- Oversee endpoint protection across all employee devices, including corporate laptops, retail POS terminals, and mobile devices
- Manage email security, IAM, SSO/MFA (Okta, Azure AD), and privileged access controls
- Design and deliver security awareness training to protect employees from phishing, social engineering, and insider threats
- Enforce policies for secure remote work, BYOD, and store-level IT environments
- Direct day-to-day security operations including network monitoring, SIEM management, IDS/IPS, vulnerability scanning, and patch management
- Supervise incident response activities from detection through post-incident review and lessons learned
- Manage certificate lifecycle, sensitive data handling, and encryption standards (TLS/SSL, PKI, key management)
- Conduct and coordinate penetration testing and vulnerability management programs, tracking remediation to resolution
- Own security controls across cloud environments (AWS, Azure) including IAM, security groups, logging, and compliance tooling
- Collaborate with IT infrastructure teams to harden systems, enforce least-privilege, and maintain secure baselines
- Ensure secure configurations for SaaS applications, APIs, and third-party integrations
Requirements
- Candidates will not require sponsorship now or in the future
Skills
- PCI-DSS compliance
- IT governance
- WAF management
- E-commerce protection
- NIST CSF
- CIS Controls
- ISO 27001
- OWASP best practices
- Email security
- IAM
- SSO/MFA (Okta, Azure AD)
- SIEM management
- IDS/IPS
- Vulnerability scanning
- Patch management
- TLS/SSL
- PKI
- Key management
- Cloud security (AWS, Azure)
Location
- Irvington, NY
Work Type
- Hybrid
- 1-2 days/week in the office
Experience Level
- Senior
- Seasoned security professional
About the Company
- EILEEN FISHER is a global women's تیار clothing retailer.
