An on-site security engineer in Flushing, NY who builds and runs the security toolchain (EDR, email/identity security, logging, MFA) while owning the PCI-DSS compliance calendar, quarterly scans, access reviews, and audit evidence. Bridges hands-on security operations with compliance work.
This specialist guards both the company’s defenses and its compliance cadence, building and operating the security toolchain while managing the PCI calendar, access reviews, and evidence.
This role does not set company-level security strategy (owned by the Digital Information Manager); it lands controls onto systems and endpoints and keeps compliance continuously attained.
Job Responsibilities
Security toolchain
Build/operate EDR, email security, identity security, logging; land MFA and 802.1X.
Run vulnerability scans and remediation; manage store and cloud baselines.
PCI compliance
Run quarterly scans, annual assessment, SAQ/ROC prep; drive remediation to closure.
Maintain the evidence repository; support QSA and external audits.
Access reviews
Review business-system, cloud, and MSP access periodically.
Investigate, contain, and review security incidents.
Provide security review for infrastructure and system changes.
Qualifications
Education: Bachelor’s degree or above; cybersecurity or computer science preferred.
Experience: 4+ years in security engineering/operations; PCI or GRC experience preferred.
Knowledge & Skills: EDR/SIEM/vulnerability tooling; PCI-DSS controls and IAM concepts; Python scripting.
Competencies: Fast responder with strong evidence discipline; principled; switches fluently between technical and compliance work.
Compensation
$100,000 – $150,000 per year
Quarterly Performance Bonus: This position is eligible for a quarterly performance-based bonus, subject to the eligibility requirements, performance criteria, and terms of the Company's bonus program.
Benefits
401(k) & 401(k) matching - subject to the eligibility requirements