Sr. Security Engineer (Hybrid in Irvington, NY) at Eileen Fisher
Irvington, NY
$120,000–$135,000from the description
Jul 9, 2026
Irvington, NY
Jul 20, 2026
What this job asks for AI summary
A solo senior security practitioner role with broad ownership across an entire organization's security program — spanning PCI-DSS compliance, WAF administration, endpoint and identity management, cloud security, and security operations. The position covers both day-to-day hands-on work (incident response, vulnerability management, SIEM) and program-level responsibilities (governance, risk assessments, roadmap, executive reporting) across retail, corporate, and remote environments. Best suited to an experienced, self-directed security generalist comfortable operating without a dedicated security team beneath them.
Senior level · 7+ years · New York-Newark-Jersey City, NY-NJ-PA · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 160 people in the New York-Newark-Jersey City, NY-NJ-PA area plausibly meet what this posting asks for (information security analysts). range 40–240
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $143,559 (middle half $110,181–$179,574). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (9)
The role is hybrid (1–2 days/week on-site) in Irvington, NY; the nearest major CBSA is New York-Newark-Jersey City, NY-NJ-PA.
The degree requirement states 'Bachelor's degree in Computer Science or equivalent experience,' so no hard degree gate is set.
WAF platform experience is required; Cloudflare, Imperva, Akamai, and AWS WAF are listed as interchangeable examples — Cloudflare is used as the primary name with the others as alternatives.
Cloud security is required across 'AWS and/or Azure,' treated as a single hard gate with AWS as primary and Azure as alternative.
Scripting/automation is required; Python, Bash, and PowerShell are listed as interchangeable options — Python is used as primary with the others as alternatives.
SSO/MFA identity platforms (Okta, Azure AD/Entra ID) are listed in the required section as interchangeable; Okta is primary with Azure AD as alternative.
Microsoft Defender / Azure Defender appear only in a parenthetical example within the cloud security requirement and are listed as preferred rather than a standalone hard gate.
NIST CSF, CIS Controls, and ISO 27001 appear as framework references in the governance duties section rather than in a hard-requirements block — listed as preferred.
Industry certifications (CISSP, CISM, PCI-ISA/QSA) are explicitly marked 'preferred' in the posting.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.