1

Pci Dss Auditor Jobs (NOW HIRING)

The ideal candidate brings deep PCI DSS expertise, strong SOC 2 familiarity, and modern GRC ... Supporting external audits by preparing evidence, responding to auditor requests, coordinating ...

PCI Compliance Lead

Lafayette, IN · On-site

$98K - $199K/yr

This position ensures compliance with PCI Standards and PCI-DSS requirements to protect cardholder ... Serve as the primary point of contact across stakeholders, auditors, third parties, and regulators ...

PCI Compliance Lead

Lafayette, IN · On-site

$98K - $199K/yr

This position ensures compliance with PCI Standards and PCI-DSS requirements to protect cardholder ... Serve as the primary point of contact across stakeholders, auditors, third parties, and regulators ...

$98.40 - $199/hr

This position ensures compliance with PCI Standards and PCI-DSS requirements to protect cardholder ... Serve as the primary point of contact across stakeholders, auditors, third parties, and regulators ...

New

Knowledge of security audits, system hardening, auditing, forensic investigation, ISO 27001 compliance, ISO 20000 certification, SAS 70 / SSAE16 Audits, PCI DSS auditing. Benefits: * Competitive Base ...

Lead GovRAMP and PCI DSS readiness, including control mapping, evidence collection, remediation ... Coordinate audit evidence collection, control testing, remediation tracking, auditor communication ...

next page

Showing results 1-20

Pci Dss Auditor information

See salary details

$10

$19

$46

How much do pci dss auditor jobs pay per hour?

As of Aug 7, 2026, the average hourly pay for pci dss auditor in the United States is $19.21, according to ZipRecruiter salary data. Most workers in this role earn between $14.42 and $19.23 per hour, depending on experience, location, and employer.

What is a PCI DSS auditor?

A PCI DSS Auditor is a professional responsible for assessing an organization's compliance with the Payment Card Industry Data Security Standard (PCI DSS). These auditors review and evaluate the security of cardholder data environments to ensure that businesses meet industry requirements for protecting payment information. Auditors typically perform on-site assessments, examine processes and systems, and provide recommendations for remediation if necessary. Their work is crucial for organizations that handle credit card transactions, as maintaining PCI DSS compliance helps prevent data breaches and avoids potential fines.

What are the key skills and qualifications needed to thrive as a PCI DSS auditor?

To thrive as a PCI DSS Auditor, you need a solid understanding of information security principles, risk assessment, and regulatory compliance, typically underpinned by a degree in IT or cybersecurity and relevant certifications like PCI Qualified Security Assessor (QSA). Familiarity with tools such as vulnerability scanners, security information and event management (SIEM) systems, and audit management software is essential. Strong attention to detail, analytical thinking, and effective communication skills help auditors interpret complex standards and relay findings clearly to clients. These skills ensure organizations achieve and maintain PCI DSS compliance, safeguarding sensitive payment card data and minimizing security risks.

What are some common challenges faced by PCI DSS auditors during an assessment, and how can they be addressed?

PCI DSS Auditors often encounter challenges such as incomplete documentation, inconsistent security controls across departments, and varying levels of staff awareness about compliance requirements. To address these issues, auditors typically conduct thorough pre-assessment reviews, communicate expectations clearly with stakeholders, and provide guidance on remediation steps. Establishing open lines of communication with technical teams and management also helps ensure that any gaps are promptly identified and resolved, resulting in a smoother and more effective compliance process.

What is the difference between Pci Dss Auditor vs Pci Dss Qualified Security Assessor (QSA)?

AspectPci Dss AuditorPci Dss Qualified Security Assessor (QSA)
CertificationsTypically certified as a PCI DSS Internal or External AssessorMust hold PCI QSA certification from PCI SSC
Work EnvironmentConducts audits for organizations to verify PCI DSS complianceAuthorized to perform official PCI DSS assessments and validate compliance
Employer & Industry UsageEmployed by consulting firms or as independent assessorsEmployed by PCI SSC-approved QSA companies or as independent QSAs

The main difference is that a Pci Dss Auditor may perform internal or preliminary assessments, while a Pci Dss Qualified Security Assessor (QSA) is authorized to conduct official PCI DSS compliance validations for merchants and service providers. QSAs have specific certification from PCI SSC, making them the primary professionals for formal compliance validation.

How to become a PCI DSS auditor?

To become a PCI DSS auditor, you typically need relevant experience in information security or IT auditing, along with knowledge of PCI DSS requirements. Earning certifications such as PCI Professional (PCIP) or Certified Information Systems Auditor (CISA) can enhance credibility. Many auditors also undergo specialized training and gain practical experience in assessing payment card security controls.
More about Pci Dss Auditor jobs
What cities are hiring for Pci Dss Auditor jobs? Cities with the most Pci Dss Auditor job openings:
What states have the most Pci Dss Auditor jobs? States with the most job openings for Pci Dss Auditor jobs include:
What job categories do people searching Pci Dss Auditor jobs look for? The top searched job categories for Pci Dss Auditor jobs are:
Infographic showing various Pci Dss Auditor job openings in the United States as of August 2026, with employment types broken down into 84% Full Time, 11% Part Time, 1% Temporary, 3% Contract, and 1% Nights. Highlights an 89% Physical, 4% Hybrid, and 7% Remote job distribution, with an average salary of $39,947 per year, or $19.2 per hour.

PCI DSS SAQ D Service Provider Lead

FYI For Your Information Inc

Silver Spring, MD • On-site

Full-time

Retirement

Re-posted 21 days ago


Job description

FYI - For Your Information, Inc. is an SBA certified, Woman-Owned Small Business and GSA schedule holder that is a premier provider of Human Capital, Training, and Information Technology services. We have won awards for being a Great Place to Work and continue to make ground-breaking advancements. For four years in a row, we have been on Inc. Magazine's 5000 list and were recently named one of Inc.'s 2024 Mid-Atlantic Fastest Growing companies.
About the role
FYI is seeking a PCI DSS SAQ D Service Provider Lead to support an active PCI compliance program for a SaaS/cloud/payment-adjacent environment. This role will own the PCI domain in a fractional capacity, including PCI scoping support, evidence sufficiency review, quarterly scan cadence, penetration testing evidence, remediation tracking, and responses to auditors, QSAs, processors, banks, or other requesting entities. The right candidate has done this work before and can drive their lane without constant prompting.
Essential responsibilities and duties
  • Support PCI DSS SAQ D Service Provider readiness, scoping, evidence review, and control interpretation.
  • Review PCI scope assumptions, in-scope systems, applications, integrations, service providers, and payment/data-flow considerations.
  • Coordinate and review evidence for quarterly external ASV scans and internal vulnerability scans.
  • Coordinate PCI-relevant penetration testing evidence, including scope, rules of engagement, final report review, remediation, and retest evidence.
  • Review evidence for file integrity monitoring, encryption, MFA, IAM, logging, monitoring, change control, secure development, vulnerability management, and remediation tracking where relevant to PCI DSS.
  • Identify weak, incomplete, stale, unclear, or nonresponsive evidence before submission.
  • Draft or review PCI-related auditor, QSA, processor, or requesting-entity responses.
  • Support tracking of PCI remediation items, exceptions, compensating-control discussions, and risk acceptance needs.
  • Help define and maintain recurring PCI compliance cadence, including quarterly scans and annual validation activities.
  • Provide concise written status updates, blockers, risks, and next actions to the project manager and CISO/vCISO.

Required qualifications
  • 8+ years of cybersecurity, GRC, IT audit, compliance, security consulting, or related experience.
  • Direct hands-on experience supporting PCI DSS assessments.
  • Direct experience with PCI DSS SAQ D; Service Provider experience is strongly preferred.
  • Experience with SaaS, cloud-hosted, fintech, payment, or payment-adjacent environments.
  • Working knowledge of ASV scanning, internal vulnerability scanning, penetration testing evidence, vulnerability remediation, IAM/MFA, encryption, logging, monitoring, FIM, change control, and secure development requirements.
  • Ability to translate PCI requirements into practical tasks for engineering, IT, security, and business stakeholders.
  • Strong written communication skills and ability to produce audit-ready summaries and responses.
  • Ability to work through ambiguity and distinguish sufficient evidence from weak or incomplete evidence.

Nice to have
  • Prior QSA, ISA, or QSA-firm experience.
  • PCI DSS v4.x experience.
  • CISA, CISSP, CISM, Security+, or equivalent certification.
  • Experience with Drata, Vanta, Secureframe, Hyperproof, Jira, Confluence, AWS, Azure, GCP, or similar platforms.
  • SOC 2 familiarity, especially where controls overlap with PCI DSS.

Expected deliverables
  • PCI DSS SAQ D evidence and gap tracker inputs.
  • PCI scope notes, assumptions, and issue summaries.
  • ASV and internal vulnerability scan evidence checklists.
  • Penetration testing evidence checklist and report sufficiency review notes.
  • PCI remediation tracker updates and risk summaries.
  • PCI auditor/requesting-entity response drafts.
  • PCI quarterly and annual compliance calendar inputs.

Operating style required
This role requires a senior operator who can own the PCI lane in a fractional capacity. The contractor must communicate clearly, document next actions, identify blockers early, and coordinate through the project manager. This is not a casual side task. Responsiveness, ownership, and clean written work product are required.
FYI's Benefits/Incentives: What is in it for you?
  • Opportunity to work a hybrid work schedule
  • A knowledgeable, high-achieving, diverse, experienced, and fun team.
  • The chance to be part of a rapidly growing company and the next success story.
  • A competitive base salary with a loaded benefits package plus 401K.
  • Tuition/education assistance, personal computer allowance, pet insurance.