Draft or review PCI-related auditor, QSA, processor, or requesting-entity responses. * Support ... Direct experience with PCI DSS SAQ D; Service Provider experience is strongly preferred.
Draft or review PCI-related auditor, QSA, processor, or requesting-entity responses. * Support ... Direct experience with PCI DSS SAQ D; Service Provider experience is strongly preferred.
About the roleFYI is seeking a PCI DSS SAQ D Service Provider Lead to support an active PCI ... Draft or review PCI-related auditor, QSA, processor, or requesting-entity responses.Support ...
Quick apply
About the roleFYI is seeking a PCI DSS SAQ D Service Provider Lead to support an active PCI ... Draft or review PCI-related auditor, QSA, processor, or requesting-entity responses.Support ...
The ideal candidate brings deep PCI DSS expertise, strong knowledge of the Risk Management ... Supporting external audits by preparing evidence, responding to auditor requests, coordinating ...
The ideal candidate brings deep PCI DSS expertise, strong knowledge of the Risk Management ... Supporting external audits by preparing evidence, responding to auditor requests, coordinating ...
The ideal candidate brings deep PCI DSS expertise, strong knowledge of the Risk Management ... Supporting external audits by preparing evidence, responding to auditor requests, coordinating ...
The ideal candidate brings deep PCI DSS expertise, strong knowledge of the Risk Management ... Supporting external audits by preparing evidence, responding to auditor requests, coordinating ...
Sr. Security Compliance Analyst - PCI DSS & SOC 2 (East Coast)
Shakopee, MN · On-site
$102K - $134K/yr
The ideal candidate brings deep PCI DSS expertise, strong SOC 2 familiarity, and modern GRC ... Supporting external audits by preparing evidence, responding to auditor requests, coordinating ...
Sr. Security Compliance Analyst - PCI DSS & SOC 2 (East Coast)
Shakopee, MN · On-site
$102K - $134K/yr
The ideal candidate brings deep PCI DSS expertise, strong SOC 2 familiarity, and modern GRC ... Supporting external audits by preparing evidence, responding to auditor requests, coordinating ...
The ideal candidate brings deep PCI DSS expertise, strong SOC 2 familiarity, and modern GRC ... Supporting external audits by preparing evidence, responding to auditor requests, coordinating ...
The ideal candidate brings deep PCI DSS expertise, strong SOC 2 familiarity, and modern GRC ... Supporting external audits by preparing evidence, responding to auditor requests, coordinating ...
Sr. Security Compliance Analyst - PCI DSS & SOC 2 (East Coast)
Minneapolis, MN · On-site +1
$100K - $131K/yr
The ideal candidate brings deep PCI DSS expertise, strong SOC 2 familiarity, and modern GRC ... Supporting external audits by preparing evidence, responding to auditor requests, coordinating ...
Sr. Security Compliance Analyst - PCI DSS & SOC 2 (East Coast)
Minneapolis, MN · On-site +1
$100K - $131K/yr
The ideal candidate brings deep PCI DSS expertise, strong SOC 2 familiarity, and modern GRC ... Supporting external audits by preparing evidence, responding to auditor requests, coordinating ...
PCI Compliance Lead
Lafayette, IN · On-site
$98K - $199K/yr
This position ensures compliance with PCI Standards and PCI-DSS requirements to protect cardholder ... Serve as the primary point of contact across stakeholders, auditors, third parties, and regulators ...
PCI Compliance Lead
Lafayette, IN · On-site
$98K - $199K/yr
This position ensures compliance with PCI Standards and PCI-DSS requirements to protect cardholder ... Serve as the primary point of contact across stakeholders, auditors, third parties, and regulators ...
PCI Compliance Lead
Lafayette, IN · On-site
$98K - $199K/yr
This position ensures compliance with PCI Standards and PCI-DSS requirements to protect cardholder ... Serve as the primary point of contact across stakeholders, auditors, third parties, and regulators ...
PCI Compliance Lead
Lafayette, IN · On-site
$98K - $199K/yr
This position ensures compliance with PCI Standards and PCI-DSS requirements to protect cardholder ... Serve as the primary point of contact across stakeholders, auditors, third parties, and regulators ...
$98.40 - $199/hr
This position ensures compliance with PCI Standards and PCI-DSS requirements to protect cardholder ... Serve as the primary point of contact across stakeholders, auditors, third parties, and regulators ...
New
$98.40 - $199/hr
This position ensures compliance with PCI Standards and PCI-DSS requirements to protect cardholder ... Serve as the primary point of contact across stakeholders, auditors, third parties, and regulators ...
New
Senior Security Auditor
Houston, TX · On-site
$160K - $220K/yr
Strong understanding of NIST CSF 2.0, NIST 800-53, PCI DSS, and FTC Safeguards, with practical application experience; Experience auditing SDLC, code reviews, CI/CD, and vulnerability management;
Senior Security Auditor
Houston, TX · On-site
$160K - $220K/yr
Strong understanding of NIST CSF 2.0, NIST 800-53, PCI DSS, and FTC Safeguards, with practical application experience; Experience auditing SDLC, code reviews, CI/CD, and vulnerability management;
Support PCI-DSS, Risk, SOC 2, NIST, ISO, CMMC, FedRAMP, Cyber Security Compliance gap analyses and ... Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA ...
Support PCI-DSS, Risk, SOC 2, NIST, ISO, CMMC, FedRAMP, Cyber Security Compliance gap analyses and ... Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA ...
Support PCI-DSS, Risk, SOC 2, NIST, ISO, CMMC, FedRAMP, Cyber Security Compliance gap analyses and ... Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA ...
Support PCI-DSS, Risk, SOC 2, NIST, ISO, CMMC, FedRAMP, Cyber Security Compliance gap analyses and ... Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA ...
Senior Security Assessor
Plano, TX · On-site
Support PCI-DSS, Risk, SOC 2, NIST, ISO, CMMC, FedRAMP, Cyber Security Compliance gap analyses and ... Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA ...
Senior Security Assessor
Plano, TX · On-site
Support PCI-DSS, Risk, SOC 2, NIST, ISO, CMMC, FedRAMP, Cyber Security Compliance gap analyses and ... Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA ...
Senior Security Assessor
Plano, TX · On-site
Support PCI-DSS, Risk, SOC 2, NIST, ISO, CMMC, FedRAMP, Cyber Security Compliance gap analyses and ... Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA ...
Senior Security Assessor
Plano, TX · On-site
Support PCI-DSS, Risk, SOC 2, NIST, ISO, CMMC, FedRAMP, Cyber Security Compliance gap analyses and ... Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA ...
Senior Security Assessor
Plano, TX · On-site
Support PCI-DSS, Risk, SOC 2, NIST, ISO, CMMC, FedRAMP, Cyber Security Compliance gap analyses and ... Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA ...
Senior Security Assessor
Plano, TX · On-site
Support PCI-DSS, Risk, SOC 2, NIST, ISO, CMMC, FedRAMP, Cyber Security Compliance gap analyses and ... Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA ...
Senior Security Governance & Compliance Lead
London, TX · On-site
$140 - $190/hr
... PCI DSS 4.0, SOC 2 Type 2, ISO 27001, and SOX -- across Commerce, Feedonomics, and Makeswift, including scoping, evidence strategy, auditor management, and final report outcomes. • Partner with ...
New
Senior Security Governance & Compliance Lead
London, TX · On-site
$140 - $190/hr
... PCI DSS 4.0, SOC 2 Type 2, ISO 27001, and SOX -- across Commerce, Feedonomics, and Makeswift, including scoping, evidence strategy, auditor management, and final report outcomes. • Partner with ...
New
Knowledge of security audits, system hardening, auditing, forensic investigation, ISO 27001 compliance, ISO 20000 certification, SAS 70 / SSAE16 Audits, PCI DSS auditing. Benefits: * Competitive Base ...
Knowledge of security audits, system hardening, auditing, forensic investigation, ISO 27001 compliance, ISO 20000 certification, SAS 70 / SSAE16 Audits, PCI DSS auditing. Benefits: * Competitive Base ...
Lead GovRAMP and PCI DSS readiness, including control mapping, evidence collection, remediation ... Coordinate audit evidence collection, control testing, remediation tracking, auditor communication ...
Lead GovRAMP and PCI DSS readiness, including control mapping, evidence collection, remediation ... Coordinate audit evidence collection, control testing, remediation tracking, auditor communication ...
Support PCI DSS audits by maintaining accurate documentation and assisting with compliance ... activities for auditing and regulatory purposes. * Guest and IoT Device Management: Support ...
Support PCI DSS audits by maintaining accurate documentation and assisting with compliance ... activities for auditing and regulatory purposes. * Guest and IoT Device Management: Support ...
Pci Dss Auditor information
See salary details
$10.34 - $13.61
15% of jobs
$14.34 is the 25th percentile. Wages below this are outliers.
$13.61 - $16.89
46% of jobs
$18.63 is the 75th percentile. Wages above this are outliers.
$16.89 - $20.17
26% of jobs
$20.17 - $23.45
7% of jobs
$23.45 - $26.73
1% of jobs
$26.73 - $30
1% of jobs
$30 - $33.28
1% of jobs
$33.28 - $36.56
0% of jobs
$36.56 - $39.84
1% of jobs
$39.84 - $43.12
1% of jobs
$43.12 - $46.39
0% of jobs
$10
$19
$46
How much do pci dss auditor jobs pay per hour?
What is a PCI DSS auditor?
What are the key skills and qualifications needed to thrive as a PCI DSS auditor?
What are some common challenges faced by PCI DSS auditors during an assessment, and how can they be addressed?
What is the difference between Pci Dss Auditor vs Pci Dss Qualified Security Assessor (QSA)?
| Aspect | Pci Dss Auditor | Pci Dss Qualified Security Assessor (QSA) |
|---|---|---|
| Certifications | Typically certified as a PCI DSS Internal or External Assessor | Must hold PCI QSA certification from PCI SSC |
| Work Environment | Conducts audits for organizations to verify PCI DSS compliance | Authorized to perform official PCI DSS assessments and validate compliance |
| Employer & Industry Usage | Employed by consulting firms or as independent assessors | Employed by PCI SSC-approved QSA companies or as independent QSAs |
The main difference is that a Pci Dss Auditor may perform internal or preliminary assessments, while a Pci Dss Qualified Security Assessor (QSA) is authorized to conduct official PCI DSS compliance validations for merchants and service providers. QSAs have specific certification from PCI SSC, making them the primary professionals for formal compliance validation.
How to become a PCI DSS auditor?

Full-time
Retirement
Re-posted 21 days ago
Job description
About the role
FYI is seeking a PCI DSS SAQ D Service Provider Lead to support an active PCI compliance program for a SaaS/cloud/payment-adjacent environment. This role will own the PCI domain in a fractional capacity, including PCI scoping support, evidence sufficiency review, quarterly scan cadence, penetration testing evidence, remediation tracking, and responses to auditors, QSAs, processors, banks, or other requesting entities. The right candidate has done this work before and can drive their lane without constant prompting.
Essential responsibilities and duties
- Support PCI DSS SAQ D Service Provider readiness, scoping, evidence review, and control interpretation.
- Review PCI scope assumptions, in-scope systems, applications, integrations, service providers, and payment/data-flow considerations.
- Coordinate and review evidence for quarterly external ASV scans and internal vulnerability scans.
- Coordinate PCI-relevant penetration testing evidence, including scope, rules of engagement, final report review, remediation, and retest evidence.
- Review evidence for file integrity monitoring, encryption, MFA, IAM, logging, monitoring, change control, secure development, vulnerability management, and remediation tracking where relevant to PCI DSS.
- Identify weak, incomplete, stale, unclear, or nonresponsive evidence before submission.
- Draft or review PCI-related auditor, QSA, processor, or requesting-entity responses.
- Support tracking of PCI remediation items, exceptions, compensating-control discussions, and risk acceptance needs.
- Help define and maintain recurring PCI compliance cadence, including quarterly scans and annual validation activities.
- Provide concise written status updates, blockers, risks, and next actions to the project manager and CISO/vCISO.
Required qualifications
- 8+ years of cybersecurity, GRC, IT audit, compliance, security consulting, or related experience.
- Direct hands-on experience supporting PCI DSS assessments.
- Direct experience with PCI DSS SAQ D; Service Provider experience is strongly preferred.
- Experience with SaaS, cloud-hosted, fintech, payment, or payment-adjacent environments.
- Working knowledge of ASV scanning, internal vulnerability scanning, penetration testing evidence, vulnerability remediation, IAM/MFA, encryption, logging, monitoring, FIM, change control, and secure development requirements.
- Ability to translate PCI requirements into practical tasks for engineering, IT, security, and business stakeholders.
- Strong written communication skills and ability to produce audit-ready summaries and responses.
- Ability to work through ambiguity and distinguish sufficient evidence from weak or incomplete evidence.
Nice to have
- Prior QSA, ISA, or QSA-firm experience.
- PCI DSS v4.x experience.
- CISA, CISSP, CISM, Security+, or equivalent certification.
- Experience with Drata, Vanta, Secureframe, Hyperproof, Jira, Confluence, AWS, Azure, GCP, or similar platforms.
- SOC 2 familiarity, especially where controls overlap with PCI DSS.
Expected deliverables
- PCI DSS SAQ D evidence and gap tracker inputs.
- PCI scope notes, assumptions, and issue summaries.
- ASV and internal vulnerability scan evidence checklists.
- Penetration testing evidence checklist and report sufficiency review notes.
- PCI remediation tracker updates and risk summaries.
- PCI auditor/requesting-entity response drafts.
- PCI quarterly and annual compliance calendar inputs.
Operating style required
This role requires a senior operator who can own the PCI lane in a fractional capacity. The contractor must communicate clearly, document next actions, identify blockers early, and coordinate through the project manager. This is not a casual side task. Responsiveness, ownership, and clean written work product are required.
FYI's Benefits/Incentives: What is in it for you?
- Opportunity to work a hybrid work schedule
- A knowledgeable, high-achieving, diverse, experienced, and fun team.
- The chance to be part of a rapidly growing company and the next success story.
- A competitive base salary with a loaded benefits package plus 401K.
- Tuition/education assistance, personal computer allowance, pet insurance.
About FYI For Your Information
Sourced by ZipRecruiter
Industry
It services
Company size
51 - 200 Employees
Headquarters location
Beltsville, MD, US
Year founded
1987