1

Pci Dss Jobs (NOW HIRING)

Support and maintain the organization's PCI DSS compliance program across all in-scope systems, networks, and business units. Conduct internal PCI assessments, gap analyses, and readiness reviews to ...

This is an exciting opportunity to drive process improvements, ensure PCI DSS compliance, and contribute to high-impact financial initiatives alongside a collaborative team. If you thrive in a fast ...

Support and maintain the organization's PCI DSS compliance program across all in-scope systems, networks, and business units. Conduct internal PCI assessments, gap analyses, and readiness reviews to ...

next page

Showing results 1-20

PCI DSS information

See salary details

$9

$56

$86

How much do pci dss jobs pay per hour?

As of Jul 3, 2026, the average hourly pay for pci dss in the United States is $56.27, according to ZipRecruiter salary data. Most workers in this role earn between $44.95 and $69.95 per hour, depending on experience, location, and employer.

Is SOC an entry level job?

A Security Operations Center (SOC) analyst role is typically not entry-level and often requires some experience with cybersecurity tools, incident response, or network monitoring. Entry-level positions in cybersecurity may include roles like SOC analyst I or security technician, but higher-level SOC roles usually demand relevant certifications such as CompTIA Security+ or CISSP and prior experience. Skills in log analysis, threat detection, and familiarity with security information and event management (SIEM) systems are also important for advancement.

How do I become a PCI DSS certified?

To become PCI DSS certified, an organization must complete a Self-Assessment Questionnaire or undergo a formal assessment by a Qualified Security Assessor, demonstrating compliance with PCI DSS requirements for protecting cardholder data. This involves implementing security controls, maintaining documentation, and regularly testing security measures. Certification is typically required for merchants and service providers handling payment card information.

What is PCI in a job?

A PCI DSS (Payment Card Industry Data Security Standard) job involves ensuring the security of credit card data for organizations that handle payment transactions. Professionals in this role typically perform security assessments, implement compliance measures, and work with tools like firewalls and encryption to protect sensitive information. Certification such as PCI DSS Qualified Security Assessor (QSA) is often required.

What is a PCI DSS job?

A PCI DSS job involves ensuring that an organization complies with the Payment Card Industry Data Security Standard (PCI DSS). Professionals in this field assess security controls, implement required safeguards, and conduct audits to protect cardholder data. They may also provide training and develop policies to maintain ongoing compliance. These roles are common in industries that handle payment card transactions, such as banking, retail, and e-commerce.

What is the role of PCI DSS?

The role of PCI DSS (Payment Card Industry Data Security Standard) is to establish security requirements for organizations that handle credit card information, ensuring the protection of cardholder data. Professionals working in PCI DSS compliance assess, implement, and monitor security controls to meet these standards and prevent data breaches.

What are the typical daily responsibilities of a PCI DSS Compliance Specialist?

A PCI DSS Compliance Specialist spends most days monitoring security controls, conducting risk assessments, and ensuring that all cardholder data environments meet the required security standards. You may regularly coordinate with IT teams, audit internal processes, document compliance evidence, and plan remediation activities for any identified gaps. This role often requires ongoing communication with auditors, vendors, and management to keep everyone aligned on compliance status. Staying current with evolving PCI DSS requirements and proactively addressing new security risks are critical aspects of the job.

What are the key skills and qualifications needed to thrive in the Pci Dss position, and why are they important?

To thrive as a PCI DSS (Payment Card Industry Data Security Standard) Compliance Specialist, you need in-depth knowledge of cybersecurity, regulatory compliance, and risk management, often supported by a degree in information security or related certifications such as PCI Professional (PCI-P) or Certified Information Systems Auditor (CISA). Familiarity with tools like vulnerability scanners, SIEM solutions, and compliance management platforms is expected. Strong analytical thinking, attention to detail, and effective communication skills help in navigating complex regulations and interacting with technical and non-technical stakeholders. These skills are vital for ensuring organizations safeguard sensitive payment data and consistently meet regulatory requirements.

More about PCI DSS jobs
What cities are hiring for Pci Dss jobs? Cities with the most Pci Dss job openings:
What are the most commonly searched types of Pci Dss jobs? The most popular types of Pci Dss jobs are:
What states have the most Pci Dss jobs? States with the most job openings for Pci Dss jobs include:
Senior Security GRC Analyst (PCI ISA Specialist)

Senior Security GRC Analyst (PCI ISA Specialist)

Bigcommerce

Austin, TX โ€ข Hybrid

$88K - $150K/yr

Full-time

Posted 17 hours ago


Job description

Welcome to the Agentic Commerce Era

At Commerce, our mission is to empower businesses to innovate, grow, and thrive with our open, AI-driven commerce ecosystem. As the parent company of BigCommerce, Feedonomics, and Makeswift, we connect the tools and systems that power growth, enabling businesses to unlock the full potential of their data, deliver seamless and personalized experiences across every channel, and adapt swiftly to an ever-changing market. We believe in harnessing AI responsibly to unlock new possibilities, and we're looking for individuals who use it intentionally to solve problems, accelerate outcomes, and expand what's possible in their role. Our purpose is to help businesses confidently solve complex commerce challenges so they can build smarter, adapt faster, and grow on their own terms. If you want to be part of a team of bold builders, sharp thinkers, and technical trailblazers who shape the future of commerce, this is the place for you.

As a Senior Security GRC Analyst and Internal Security Assessor (ISA), you will serve as the primary Subject Matter Expert (SME) for our global PCI DSS program at Commerce. We operate a highly mature PCI DSS 4.0 environment; your mission is to lead the continuous evolution of this program, ensuring that compliance is integrated into our "business as usual" (BAU) operations.

While your primary focus is PCI, you will be a key player in our broader GRC function, supporting our SOC2 and ISO 27001 certifications. You will act as the technical bridge between our Engineering, Infrastructure, and IT teams and external auditors, ensuring that our high-security standards are documented, validated, and maintained.

What You'll Do:PCI SME & Internal Security Assessor (ISA)
  • ISA Leadership: Serve as the officially designated PCI ISA for the organization. Manage the annual assessment lifecycle, including scoping, evidence collection, and validation of controls.

  • PCI 4.0 Evolution: Direct the ongoing maintenance of our PCI 4.0 program, with a specific focus on managing Targeted Risk Analyses (TRAs) and the customized approach where applicable.

  • Scoping & Segmentation: Partner with Cloud Engineering to validate PCI scope across our global footprint, ensuring effective network segmentation and data flow isolation.

  • QSA Liaison: Act as the primary point of contact for our external QSA, defending our control environment and streamlining the audit process to minimize disruption to technical teams.

  • Continuous Compliance: Operationalize PCI requirements (e.g., quarterly scans, penetration test remediation) into automated workflows.

Multi-Framework Audit Management
  • Unified Control Framework: Support the broader GRC team in managing our SOC2 Type 2, ISO 27001, and other regulatory audits (as seen on https://www.google.com/search?q=security.commerce.com).

  • Technical Advisory: Provide GRC perspective on architectural designs, product launches, and infrastructure changes to ensure "compliance by design."

  • Remediation Management: Track and drive the remediation of audit findings and security gaps, working closely with asset owners to find pragmatic, secure solutions.

Who You Are:
  • Experience: 6+ years in an Information Security or IT Audit role, with at least 3 years of deep focus on PCI DSS within a major cloud-native environment.

  • Certification: Active PCI ISA (Internal Security Assessor) or PCI QSA certification is mandatory.

  • Regulatory Expertise: Thorough understanding of PCI DSS 4.0 requirements and the practical application of the standard in modern environments.

  • Audit Fluency: Proven experience leading Level 1 Service Provider assessments.

  • Communication: Ability to explain complex compliance requirements to developers and business leaders in a way that emphasizes enablement rather than "blockage."

Preferred Qualifications
  • Broad Framework Knowledge: Experience with SOC2 and ISO 27001:2022.

  • Cloud Security: Experience with GRC automation and familiarity with modern cloud-native security and observability tools.

  • Automation Mindset: Experience using GRC platforms and a desire to automate manual evidence collection to reduce audit fatigue.

About You
  • You understand the "Why": You don't just "do compliance"; you understand the security intent behind every control and can help teams meet the requirement in a way that actually improves our security posture.

  • Technical Curiosity: You are comfortable diving into technical configurations (IAM policies, VPC flow logs, etc.) to verify control effectiveness yourself.

  • Adaptable: You enjoy the challenge of a high-paced environment where scale and security must coexist and evolve together.

This is a Hybrid role - Beginning March 1, 2026, employees who live within commuting distance of a Dedicated Office will be expected to be in the office three days per week.

#LI-KE1

#LIHYBRID

(Pay Transparency Range:$88,951.00 - $150,432.00)

Compensation Transparency


The national base salary range for this role is posted above in this job post.

Final compensation will be determined based on factors such as relevant experience, skills, qualifications and geographic location. We also consider internal equity to help ensure fair and consistent pay practices across our teams.

Where applicable, this role may also be eligible for variable compensation (such as bonus or commission), equity, and benefits in accordance with local policies. Details will be shared during the hiring process. We are committed to equitable and transparent pay practices that align to market data, internal equity, and individual contribution.

Inclusion and Belonging

At Commerce, we believe that celebrating the unique histories, perspectives and abilities of every employee makes a difference for our company, our customers and our community. We are an equal opportunity employer and the inclusive atmosphere we build together will make room for every person to contribute, grow and thrive.

We are committed to creating an inclusive and accessible hiring experience for all candidates. If you require accommodations or adjustments at any stage of the recruitment process, please let us know and we will work with you to meet your needs.

Learn more about the Commerce team, culture and benefits at https://www.commerce.com/careers/

Protect Yourself Against Hiring Scams: Our Corporate Disclaimer

Commerce, along with many other employers, has become the subject of fraudulent job offers to hopeful prospective job seekers.
Be advised:
Commerce does not offer jobs to individuals who do not go through our formal hiring process.
Commerce will never:

  • require payment of recruitment fees from candidates;

  • request personally identifiable information through unsanctioned websites or applications;

  • attempt to solicit money from you as part of the hiring process or as part of an employment offer;

  • solicit money to complete visa requirements as part of a job offer.


If you receive unsolicited offers of employment from Commerce, we urge you to be extremely cautious and avoid engaging or responding.


BigCommerce logo

About BigCommerce

Sourced by ZipRecruiter

BigCommerce's mission is to help merchants sell more at every stage of growth, from small startups, to mid-market businesses to large enterprises. We focus on being the best ecommerce platform so our customers can focus on what matters most: growing their businesses. We are equally passionate about growing our employee's careers and providing them an incredible experience as we rapidly expand across the globe. We are proud to have been recognized numerous times for our product and workplace culture. We empower our people and customers to build, innovate and grow, so together we can redefine the ecommerce industry.

Industry

Technology, communication and media

Company size

501 - 1,000 Employees

Headquarters location

Austin, TX, US

Year founded

2009