1

Pci Dss Risk Assessment Jobs (NOW HIRING)

Deep expertise in risk assessment methodologies and control evaluation concepts * Experience with cybersecurity frameworks: NIST CSF, ISO 27001, PCI DSS, SOC 2, and/or CIS Controls * Proven ...

Senior PCI Analyst

$98K - $128K/yr

Conducts PCI DSS compliance assessments to identify gaps and risks supporting ongoing security and ... Strong risk management capabilities including the ability to identify, assess, and mitigate ...

next page

Showing results 1-20

Pci Dss Risk Assessment information

See salary details

$14

$30

$74

How much do pci dss risk assessment jobs pay per hour?

As of Sep 5, 2026, the average hourly pay for pci dss risk assessment in the United States is $30.34, according to ZipRecruiter salary data. Most workers in this role earn between $19.47 and $38.70 per hour, depending on experience, location, and employer.

What is a PCI DSS risk assessment?

A PCI DSS risk assessment is a formal process required by the Payment Card Industry Data Security Standard (PCI DSS) to identify, evaluate, and address potential risks that could impact the security of cardholder data. It involves analyzing how sensitive payment information is handled, stored, and transmitted within an organization, and identifying any vulnerabilities that could lead to data breaches or non-compliance. Organizations use the findings from the assessment to implement security controls and processes that help protect cardholder data and maintain PCI DSS compliance.

What are the key skills and qualifications needed to thrive as a PCI DSS risk assessor, and why are they important?

To thrive as a PCI DSS Risk Assessor, you need expertise in information security, risk management, compliance frameworks, and ideally a degree in IT or cybersecurity. Familiarity with PCI DSS standards, risk assessment tools, vulnerability scanners, and certifications like PCI Professional (PCIP) or Certified Information Systems Auditor (CISA) is typically required. Strong analytical thinking, communication, and attention to detail are crucial soft skills for effective risk evaluation and reporting. These skills and qualifications are vital to ensure organizations maintain compliance, reduce risk, and protect sensitive payment card data.

What are some common challenges faced during PCI DSS risk assessments, and how can they be addressed?

A frequent challenge in PCI DSS risk assessments is ensuring comprehensive identification and documentation of all systems and processes that store, process, or transmit cardholder data. Overlooking assets or data flows can lead to compliance gaps. Additionally, coordinating with various departments to collect accurate information can be complex. These challenges can be addressed by establishing clear communication channels, using detailed data flow diagrams, and conducting regular cross-functional meetings to maintain up-to-date asset inventories and processes.

What is the difference between Pci Dss Risk Assessment vs Pci Dss Compliance Analyst?

AspectPci Dss Risk AssessmentPci Dss Compliance Analyst
Primary FocusIdentifying and evaluating security risks related to PCI DSS requirementsEnsuring ongoing compliance with PCI DSS standards and policies
ResponsibilitiesRisk identification, vulnerability assessment, mitigation planningPolicy implementation, audit preparation, compliance documentation
Required SkillsRisk management, security assessment, knowledge of PCI DSSCompliance auditing, documentation, regulatory knowledge
Work EnvironmentSecurity teams, risk management departmentsCompliance teams, audit departments

While both roles involve PCI DSS standards, the Pci Dss Risk Assessment focuses on identifying and evaluating security risks, whereas the Pci Dss Compliance Analyst concentrates on maintaining compliance and preparing for audits. Understanding these differences helps organizations assign the right responsibilities to ensure security and compliance.

More about Pci Dss Risk Assessment jobs

What cities are hiring for Pci Dss Risk Assessment jobs?

Cities with the most Pci Dss Risk Assessment job openings:

What states have the most Pci Dss Risk Assessment jobs?

States with the most job openings for Pci Dss Risk Assessment jobs include:

Infographic showing various Pci Dss Risk Assessment job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 89% Full Time, 8% Part Time, and 2% Contract. Highlights an 87% Physical, 4% Hybrid, and 9% Remote job distribution, with an average salary of $63,100 per year, or $30.3 per hour.

PCI Assessment Specialist

JPMorgan Chase & Co

Jersey City, NJ • On-site

Full-time

Medical, Retirement

Posted 4 days ago


JPMorgan Chase & Co. rating

7.9

Company rating: 7.9 out of 10

Based on 500 frontline employees who took The Breakroom Quiz

78th of 175 rated banks


Job description

Data security underpins the trust that millions of clients place in the firm every day, and in this role, you will be at the forefront of protecting it. In this role, you will drive compliance validation across one of the world's most complex financial environments, working at the intersection of regulatory expertise, technical depth, and cross-functional leadership. This is your opportunity to shape how the firm interprets, implements, and demonstrates adherence to PCI DSS requirements at a global scale.

As a PCI Specialist at JPMorganChase in the Cybersecurity Technology and Controls Global Regulatory Assessments team, you will oversee end-to-end PCI assessment processes, serving as the firm's subject matter expert on PCI DSS frameworks. You will partner with external Qualified Security Assessors (QSAs) , internal control owners, and business stakeholders to validate compliance, manage risk, and protect cardholder data across diverse environments. Your work directly supports the firm's commitment to regulatory excellence and the security of its most sensitive systems.

Job responsibilities

  • Oversee and manage multiple concurrent PCI assessments within firm standards and procedures, adhering to time-sensitive deadlines through effective project management and stakeholder coordination.
  • Capture, review, and analyze PCI-required documentation, ensuring quality and suitability that meet PCI SSC requirements while exercising professional judgment on complex technical and compliance matters.
  • Partner with Business Leads and control owners to determine and validate assessment scope across people, processes, systems, and third-party dependencies in accordance with PCI DSS scoping requirements.
  • Collaborate closely with external QSAs to facilitate assessment processes, ensuring alignment with business objectives and regulatory requirements.
  • Proactively monitor key risk indicators to identify non-compliance and support remediation, including the development of compensating controls to address security, risk, and control gaps.
  • Provide guidance on remediation activities, ensuring appropriate resolution of issues and completion of action plans, and support the closure verification process.
  • Develop and maintain strong business and technology relationships, becoming a trusted compliance partner across the firm.
  • Communicate risk and control findings to key stakeholders, develop recommendations, and deliver accurate metrics and management reports on a timely basis.
  • Leverage emerging technologies, including AI and automation, to enhance assessment efficiency, documentation quality, and risk identification processes.

Required qualifications, capabilities, and skills

  • Minimum 5 years of professional experience in technology risk and controls, risk-based consulting, risk assessments, or audit and regulatory activities, with specific emphasis on PCI DSS.
  • Comprehensive knowledge and practical experience across all domains of technology infrastructure and PCI DSS requirements, including implementation and oversight of technology risk and controls, and coordination of audit activities.
  • Proven experience tracking and driving remediation of PCI findings, including validating control closure and documenting compensating controls through the formal PCI SSC process.
  • Detail-oriented with strong conceptual, analytical, decision-making, time management, and prioritization capabilities.
  • Exceptional oral and written communication skills with the ability to articulate complex technical concepts to diverse audiences at all organizational levels and influence without direct authority.
  • Proven experience in planning, coordination, and implementation with the ability to work across teams and functions to deliver quality outcomes.

Preferred qualifications, capabilities, and skills

  • Bachelor's degree or equivalent practical experience in a technology, business, or related discipline; experience within financial services is preferred.
  • Experience reviewing vendor, third-party, or software technical documentation to identify control gaps and assess suitability against defined security and compliance requirements.
  • Experience in a regulated financial services environment subject to external examinations or regulatory oversight.
  • Familiarity with IT risk and process frameworks including COSO, COBIT, NIST CF, and ITIL, as well as process-focused methodologies such as Change Management, Incident Management, and SDLC.
  • Demonstrated application of AI, automation, or emerging technologies to improve compliance workflows, documentation quality, or assessment efficiency.
  • Sound judgment in ambiguous situations, balancing regulatory requirements with business realities to develop pragmatic, risk-informed solutions.

#CTC

JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world's most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.

We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process. 

We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.

JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans

Our professionals in our Corporate Functions cover a diverse range of areas from finance and risk to human resources and marketing. Our corporate teams are an essential part of our company, ensuring that we're setting our businesses, clients, customers and employees up for success.

What JPMorgan Chase & Co. employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom