1

Waf Manager Jobs (NOW HIRING)

Senior Product Marketing Manager

Seattle, WA ยท On-site

$137K - $180K/yr

The Senior Product Marketing Manager (PMM) for web application firewalls (WAF) will launch and support WAFs and WAF-related products and services. The role requires a technical understanding of WAFs ...

$54 - $72.25/hr

Role Summary The client is seeking an experienced Cloud Engineer with strong AWS WAF expertise to design, implement, and manage web application security controls. The role is hands-on and focused on ...

Senior Product Manager

Boston, MA ยท On-site

$137K - $181K/yr

This role owns our strategic relationships with the CDN, WAF, and security vendors that power our ... Lead strategic partnership management. Own relationships with our CDN, WAF, and security technology ...

Showing results 41-60

Waf Manager information

See salary details

$24.5K

$59.5K

$116K

How much do waf manager jobs pay per year?

As of Sep 14, 2026, the average yearly pay for waf manager in the United States is $59,525.00, according to ZipRecruiter salary data. Most workers in this role earn between $42,000.00 and $68,500.00 per year, depending on experience, location, and employer.

What are the most commonly searched types of Waf jobs?

The most popular types of Waf jobs are:

What are popular job titles related to Waf Manager jobs?

For Waf Manager jobs, the most frequently searched job titles are:

Sr. Security Engineer (Hybrid in Irvington, NY)

Irvington, NY โ€ข Hybrid

Eileen Fisher
Retailย โ€ขย 501 - 1,000 employees

$118K - $161K/yr

Full-time

Medical, PTO

Re-posted 7 days ago


Job description

**This is a hybrid role with 1-2 days/week in the office in Irvington, NY.  We are seeking candidates who will not require sponsorship now or in the future**

We are seeking a Senior IT Security Engineer to serve as the primary owner of information security across EILEEN FISHERโ€™s entire technology landscape. This is a hands-on leadership role responsible for managing all aspects of IT securityโ€”from PCI-DSS compliance and IT governance to WAF management, e-commerce protection, and safeguarding the systems and devices used by employees across retail, corporate, and remote environments. The ideal candidate is a seasoned security professional who can operate independently, build and mature a security program, and serve as the go-to expert for all security matters within the organization.

Summary of Duties and Responsibilities:

PCI-DSS & Compliance Ownership

โ€ข     Own end-to-end PCI-DSS compliance across all retail point-of-sale, e-commerce, and payment processing environments

โ€ข     Lead annual PCI assessments, QSA engagements, and remediation tracking to ensure continuous compliance

โ€ข     Maintain and enforce the cardholder data environment (CDE) scope, segmentation, and documentation

โ€ข     Coordinate PCI evidence collection, SAQ/ROC preparation, and audit readiness across all relevant systems

IT Governance & Security Program Management

โ€ข     Develop, implement, and continuously improve IT security policies, standards, and procedures aligned with business strategy and frameworks (NIST CSF, CIS Controls, ISO 27001)

โ€ข     Lead the annual enterprise risk assessment process, tracking findings and driving remediation to closure

โ€ข     Establish and report on security KPIs and metrics to IT leadership and the executive team

โ€ข     Own the security technology roadmap and prioritize investments in tools, controls, and capabilities

WAF & E-Commerce Security

โ€ข     Serve as the primary owner of the organizationโ€™s WAF provider relationshipโ€”managing configuration, tuning, rule sets, and escalations to protect e-commerce and customer-facing platforms

โ€ข     Monitor and respond to WAF alerts, DDoS events, bot activity, and web application threats

โ€ข     Secure payment gateways, APIs, and customer data flows in alignment with PCI-DSS and OWASP best practices

โ€ข     Partner with the e-commerce and development teams to embed security into the SDLC and deployment workflows

Employee & Endpoint Security

โ€ข     Oversee endpoint protection across all employee devices, including corporate laptops, retail POS terminals, and mobile devices

โ€ข     Manage email security, IAM, SSO/MFA (Okta, Azure AD), and privileged access controls

โ€ข     Design and deliver security awareness training to protect employees from phishing, social engineering, and insider threats

โ€ข     Enforce policies for secure remote work, BYOD, and store-level IT environments

Security Operations

โ€ข     Direct day-to-day security operations including network monitoring, SIEM management, IDS/IPS, vulnerability scanning, and patch management

โ€ข     Supervise incident response activities from detection through post-incident review and lessons learned

โ€ข     Manage certificate lifecycle, sensitive data handling, and encryption standards (TLS/SSL, PKI, key management)

โ€ข     Conduct and coordinate penetration testing and vulnerability management programs, tracking remediation to resolution

Cloud & Infrastructure Security

โ€ข     Own security controls across cloud environments (AWS, Azure) including IAM, security groups, logging, and compliance tooling

โ€ข     Collaborate with IT infrastructure teams to harden systems, enforce least-privilege, and maintain secure baselines

โ€ข     Ensure secure configurations for SaaS applications, APIs, and third-party integrations

PERFORMS OTHER RELATED DUTIES AND ASSIGNMENTS AS REQUIRED.


Required Skills
Required Experience
Education:  Bachelors degree in Computer Science or equivalent experience.
 

โ€ข     7+ years of progressive IT security experience, with at least 3 years in a senior or lead security role

โ€ข     Demonstrated end-to-end ownership of PCI-DSS complianceโ€”including QSA engagement, CDE scoping, SAQ/ROC preparation, and continuous compliance across retail POS and e-commerce channels

โ€ข     Hands-on experience managing WAF platforms (e.g., Cloudflare, Imperva, Akamai, AWS WAF) including rule tuning, alert response, and vendor relationship management

โ€ข     Experience securing e-commerce environments: payment gateways, APIs, and customer data in alignment with PCI-DSS and OWASP Top 10

โ€ข     Proven experience building and managing IT governance programsโ€”policies, risk assessments, KPIs, and security roadmaps

โ€ข     Ability to manage security across a distributed workforce including retail stores, corporate offices, and remote employees

โ€ข     Experience with cloud security across AWS and/or Azure (IAM, security groups, logging, Microsoft Defender, Azure Defender)

โ€ข     Strong knowledge of identity and access management (IAM), SSO/MFA (Okta, Azure AD/Entra ID), and privileged access controls

โ€ข     Experience with SIEM platforms, IDS/IPS, endpoint detection & response (EDR), and vulnerability management tools

โ€ข     Strong understanding of encryption, TLS/SSL, PKI, and key management

โ€ข     Scripting/automation skills in Python, Bash, or PowerShell

โ€ข     Excellent communication skills with the ability to present security risk to executive and non-technical audiences

โ€ข     Industry certifications preferred: CISSP, CISM, PCI-ISA/QSA, or equivalent

The salary range for this position is $120,000 - 135,000/year depending on relevant experience. We offer a competitive total package, including health benefits, generous paid time off, wellness reimbursement, etc.
 
EILEEN FISHER, Inc. is an equal-opportunity employer and is committed to providing a workplace free from harassment and discrimination. We are committed to recruiting, hiring, training and promoting qualified people of all backgrounds, and make all employment decisions without regard to any protected status.