1

Pci Dss Qsa Jobs (NOW HIRING)

PCI Compliance Engineer

Cupertino, CA

$65/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

PCI Compliance Engineer - must have recent PCI DSS engineering experience Description Our client is ... QSA, CIPM/CIPP, or AWS certifications. • Experience working in large-scale enterprise ...

PCI Compliance Engineer

Cupertino, CA

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

PCI Compliance Engineer - must have recent PCI DSS engineering experience Description Our client is ... QSA, CIPM/CIPP, or AWS certifications. • Experience working in large-scale enterprise ...

Senior GRC Analyst

Pittsburgh, PA

$114K - $163K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Run our annual PCI DSS v4.0.1 Level 1 service provider assessment and SOC 2 Type II examination end to end -- scope validation, evidence collection, QSA and auditor coordination, gap remediation ...

cybersecurity analyst senior, PCI compliance

Seattle, WA · On-site

$109K - $142K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Translate PCI DSS requirements into technical requirements and control implementations * Support PCI assessments (QSA-facing), including evidence validation, control testing, and remediation planning

Senior GRC Analyst

Pittsburgh, PA · On-site

$114K - $163K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Run our annual PCI DSS v4.0.1 Level 1 service provider assessment and SOC 2 Type II examination end to end - scope validation, evidence collection, QSA and auditor coordination, gap remediation ...

Showing results 21-40

Pci Dss Qsa information

See salary details

$69.5K

$90.6K

$116K

How much do pci dss qsa jobs pay per year?

As of Aug 17, 2026, the average yearly pay for pci dss qsa in the United States is $90,605.00, according to ZipRecruiter salary data. Most workers in this role earn between $81,000.00 and $98,000.00 per year, depending on experience, location, and employer.

What is a PCI DSS QSA?

A PCI DSS QSA, or Qualified Security Assessor, is a professional who has been certified by the PCI Security Standards Council to assess and validate an organization’s compliance with the Payment Card Industry Data Security Standard (PCI DSS). QSAs conduct official PCI assessments, help organizations understand the requirements, and produce the necessary documentation to demonstrate compliance. Their role is crucial for businesses that handle payment card data and must maintain secure environments to protect cardholder information.

What are the key skills and qualifications needed to thrive as a PCI DSS QSA, and why are they important?

To thrive as a PCI DSS QSA, you need expert knowledge of information security, risk assessment, and compliance, typically supported by relevant degrees and the official QSA certification from the PCI Security Standards Council. Familiarity with security assessment tools, vulnerability scanning software, and PCI DSS reporting systems is essential. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for translating complex requirements to clients and stakeholders. These skills and qualifications ensure accurate compliance assessments, effective guidance, and the protection of sensitive payment data.

What are some common challenges PCI DSS QSAs face when working with clients to achieve compliance?

PCI DSS QSAs often encounter challenges such as interpreting complex requirements for unique business environments, addressing gaps in clients' existing security controls, and managing tight project timelines. They also need to communicate technical requirements to non-technical stakeholders, ensuring everyone understands the compliance process. Effective QSAs develop strong problem-solving skills and adaptability, which are crucial for tailoring solutions that fit each client's operational realities while maintaining strict compliance standards.

What is the difference between Pci Dss Qsa vs Pci Dss Auditor?

AspectPci Dss QsaPci Dss Auditor
CertificationsQSA certification, PCI DSS knowledgeAuditor certification, PCI DSS expertise
Work EnvironmentConsulting, assessing merchants and service providersAuditing organizations, conducting PCI DSS assessments
Employer & Industry UsagePayment card industry, security consulting firmsAudit firms, compliance organizations

The Pci Dss Qsa is a certified professional authorized to assess merchants' PCI DSS compliance, often working in consulting roles. The Pci Dss Auditor, while similar, typically refers to professionals conducting formal audits within organizations or audit firms. Both roles require PCI DSS knowledge and certifications but differ mainly in their scope and work environment.

How to become a PCI DSS QSA?

To become a PCI DSS Qualified Security Assessor (QSA), candidates must have relevant security experience, typically in information security or compliance, and complete the PCI SSC QSA training program. They must also pass the PCI SSC QSA exam and undergo a rigorous background check, after which they can be certified and authorized to assess organizations for PCI DSS compliance.

What is the role of PCI DSS QSA in PCI DSS?

A PCI DSS Qualified Security Assessor (QSA) is a security professional authorized to assess and validate an organization's compliance with PCI DSS standards. They conduct security audits, review controls, and ensure that payment card data is protected according to industry requirements. QSAs play a critical role in helping merchants and service providers maintain secure payment environments and achieve PCI DSS certification.
More about Pci Dss Qsa jobs
Infographic showing various Pci Dss Qsa job openings in the United States as of August 2026, with employment types broken down into 2% As Needed, 83% Full Time, 6% Part Time, and 9% Contract. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution, with an average salary of $90,605 per year, or $43.6 per hour.

Full-time

Posted 19 days ago


Job description

About Specialized Security Services, Inc.

For over two decades, our expert team has successfully assisted organizations with the implementation and oversight of their information security, privacy, and regulatory compliance programs. Our reputation is our own, built upon our steadfast commitment over the years to do the right thing and go above and beyond for our clients.  We pride ourselves on our ability to think outside-the-box, stay nimble and succeed as a team.

About the Senior Assessor role:

The Senior Security Assessor supports PCI Compliance, SOC 1, SOC 2, ISO, NIST, CMMC, Risk Assessment, HIPAA, CCPA, GDPR project initiatives by undertaking risk assessments, advising on implementation of security measures, recommending appropriate risk mitigations, interpreting security policy and standards in the context of projects and business scenarios to help the business operate securely. This role has a significant client consulting and management component in advising, defining client security requirements to industry best practice standards, and ensuring that all projects meet these requirements, or that exceptions and issues are noted and remediated as appropriate.

The ideal candidate combines the technical expertise commonly associated with PCI DSS and cybersecurity assessments with the audit, attestation, and internal control experience often found in SOC and assurance engagements. CPA and/or QSA credentials are highly valued.

.

As a Senior Assessor, you will:

  • Assess existing controls to determine level of compliance to the PCI DSS standard, SOC 2, ISO, HIPAA, GDPR, NIST, CMMC, etc. inclusive of: their maturity, state of compliance, and the risk associated with any findings.
  • Support PCI-DSS, Risk, SOC 2, NIST, ISO, CMMC, FedRAMP, Cyber Security Compliance gap analyses and assessments.
  • Conduct SOC 2 Type I and Type II readiness assessments and examinations, including control design review, testing of controls, evidence evaluation, gap analysis, and reporting.
  • Support compliance privacy client engagements and familiarity with GDPR, CCPA, PIPEDA  or similar privacy frameworks.
  • Support sites in testing, documentation and issue resolution associated with cyber security programs.
  • Perform comprehensive threat/risk assessments and business impact analysis of current system, data, application and technology environments to determine possible internal and external threats to information assets, and identify security measures required to counter such threats.
  • Supports sites in testing, documentation and issue resolution associated with cyber security programs. 
  • Participate in the development and implementation of the enterprise security architecture and supporting security standards to ensure compliance with corporate policies, and relevant legislative and regulatory requirements.
  • Perform technical security reviews or assessments to ensure targeted systems, networks, applications and/or data are in compliance with corporate policies and standards.
  • Understand that, due to the rapidly evolving cybersecurity landscape, maintaining this role will require obtaining additional certifications to keep up with the cybersecurity threat landscape and industry acceptable certifications.

Required Education and Experience:

  • A university degree in Computer Science, Engineering, or a field which relates to the role.
  • Minimum of at least two security certifications from the following (ISC)2 CISSP, ISACA CISM, ISACA CISA, SANS GIAC/GSNA, ISO27001 Certified Lead Implementer/Lead Auditor/Internal Auditor 
  • Possession of a PCI QSA certification or the ability to obtain and maintain QSA status is strongly preferred.
  • Five (5) + years of Information Security experience in Security Governance, Risk and Compliance practices and methodologies.

Preferred Experience that drives success in this role:

  • Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA Certified Internal Auditor (CIA), HITRUST, or similar industry-recognized credentials.
  • Certified Public Accountant (CPA) credential preferred.
  • Demonstrated knowledge of the principles, best practices, architectures, and control frameworks applicable to PCI DSS, NIST, SOC 1, SOC 2, CMMC, and ISO standards.
  • Experience conducting cybersecurity assessments and audits, including the use of industry-standard security and compliance tools.
  • Experience with security hardening, policy development, and secure software development practices.
  • Previous experience performing PCI DSS, NIST, CMMC, and ISO assessments, including readiness assessments, gap analyses, remediation validation, and formal audits.
  • Experience leading or supporting SOC 1 and SOC 2 examinations, including scoping, control testing, evidence review, and report development.
  • Experience evaluating internal controls, business processes, governance frameworks, and risk management practices in support of attestation and assurance engagements.