... assessments, third-party risk management, and control effectiveness evaluations. • Translate ... risk management • Strong knowledge of HIPAA Security Rule, PCI DSS, and related regulatory ...
... assessments, third-party risk management, and control effectiveness evaluations. • Translate ... risk management • Strong knowledge of HIPAA Security Rule, PCI DSS, and related regulatory ...
Cyber Risk Controls Officer
$146K - $244K/yr
Proactively assess Applications and processes for compliance to and alignment with Fiserv cyber ... PCI DSS, and ITIL * Experience with governance, risk, and compliance tools and practices for ...
Cyber Risk Controls Officer
$146K - $244K/yr
Proactively assess Applications and processes for compliance to and alignment with Fiserv cyber ... PCI DSS, and ITIL * Experience with governance, risk, and compliance tools and practices for ...
Director GRC & Security Architecture
Newark, DE · On-site
$110 - $145/hr
Oversee enterprise risk assessments, third‑party risk management, and control effectiveness ... risk management. * Strong knowledge of HIPAA Security Rule, PCI DSS, and related regulatory ...
Director GRC & Security Architecture
Newark, DE · On-site
$110 - $145/hr
Oversee enterprise risk assessments, third‑party risk management, and control effectiveness ... risk management. * Strong knowledge of HIPAA Security Rule, PCI DSS, and related regulatory ...
Security Advisor
Dover, DE · On-site
... as PCI DSS, CMMC, GDPR, FERPA, HIPAA/HITECH, GLBA, and FTC Red Flags. The Security Advisor will ... Understanding of risk assessments and targeted risk analyses. * Technical understanding of ...
Security Advisor
Dover, DE · On-site
... as PCI DSS, CMMC, GDPR, FERPA, HIPAA/HITECH, GLBA, and FTC Red Flags. The Security Advisor will ... Understanding of risk assessments and targeted risk analyses. * Technical understanding of ...
Oversee enterprise risk assessments, third-party risk management, and control effectiveness ... Ensure ongoing compliance with applicable regulations and standards, including HIPAA, PCI DSS ...
Oversee enterprise risk assessments, third-party risk management, and control effectiveness ... Ensure ongoing compliance with applicable regulations and standards, including HIPAA, PCI DSS ...
Oversee enterprise risk assessments, third-party risk management, and control effectiveness ... Ensure ongoing compliance with applicable regulations and standards, including HIPAA, PCI DSS ...
Oversee enterprise risk assessments, third-party risk management, and control effectiveness ... Ensure ongoing compliance with applicable regulations and standards, including HIPAA, PCI DSS ...
... such as PCI DSS, and an understanding of authorization risk. • Hands-on experience working with technology teams in an Agile/Scrum environment. • Strong analytical, communication, and ...
... such as PCI DSS, and an understanding of authorization risk. • Hands-on experience working with technology teams in an Agile/Scrum environment. • Strong analytical, communication, and ...
Support SOC 2, PCI DSS, and related audit and compliance activities. * Conduct security reviews of ... Pragmatic, risk-based approach to security. * Comfortably operating independently and remaining ...
Support SOC 2, PCI DSS, and related audit and compliance activities. * Conduct security reviews of ... Pragmatic, risk-based approach to security. * Comfortably operating independently and remaining ...
Assistant Vice President, Cyber Security
Wilmington, DE · On-site
$107K - $145K/yr
Support SOC 2, PCI DSS, and related audit and compliance activities. * Conduct security reviews of ... Pragmatic, risk-based approach to security. * Comfortably operating independently and remaining ...
Quick apply
Assistant Vice President, Cyber Security
Wilmington, DE · On-site
$107K - $145K/yr
Support SOC 2, PCI DSS, and related audit and compliance activities. * Conduct security reviews of ... Pragmatic, risk-based approach to security. * Comfortably operating independently and remaining ...
Support SOC 2, PCI DSS, and related audit and compliance activities. * Conduct security reviews of ... Pragmatic, risk-based approach to security. * Comfortably operating independently and remaining ...
Quick apply
Support SOC 2, PCI DSS, and related audit and compliance activities. * Conduct security reviews of ... Pragmatic, risk-based approach to security. * Comfortably operating independently and remaining ...
Support SOC 2, PCI DSS, and related audit and compliance activities. * Conduct security reviews of ... Pragmatic, risk-based approach to security. * Comfortably operating independently and remaining ...
Support SOC 2, PCI DSS, and related audit and compliance activities. * Conduct security reviews of ... Pragmatic, risk-based approach to security. * Comfortably operating independently and remaining ...
Demonstrated experience supporting audits and controls for financial regulations and frameworks, such as: * SOX, GLBA, PCI DSS, SOC 2 * Internal risk management and model governance requirements
Demonstrated experience supporting audits and controls for financial regulations and frameworks, such as: * SOX, GLBA, PCI DSS, SOC 2 * Internal risk management and model governance requirements
Demonstrated experience supporting audits and controls for financial regulations and frameworks, such as: * SOX, GLBA, PCI DSS, SOC 2 * Internal risk management and model governance requirements
Demonstrated experience supporting audits and controls for financial regulations and frameworks, such as: * SOX, GLBA, PCI DSS, SOC 2 * Internal risk management and model governance requirements
Assistant Vice President - Cyber Security
Wilmington, DE · On-site
$120 - $150/hr
The ideal candidate is a builder and operator who can balance practical risk management with ... Support SOC 2, PCI DSS, and related audit and compliance activities. * Conduct security reviews of ...
Assistant Vice President - Cyber Security
Wilmington, DE · On-site
$120 - $150/hr
The ideal candidate is a builder and operator who can balance practical risk management with ... Support SOC 2, PCI DSS, and related audit and compliance activities. * Conduct security reviews of ...
Pci Dss Risk Assessment information
What is a PCI DSS risk assessment?
What are the key skills and qualifications needed to thrive as a PCI DSS risk assessor, and why are they important?
What is the difference between Pci Dss Risk Assessment vs Pci Dss Compliance Analyst?
| Aspect | Pci Dss Risk Assessment | Pci Dss Compliance Analyst |
|---|---|---|
| Primary Focus | Identifying and evaluating security risks related to PCI DSS requirements | Ensuring ongoing compliance with PCI DSS standards and policies |
| Responsibilities | Risk identification, vulnerability assessment, mitigation planning | Policy implementation, audit preparation, compliance documentation |
| Required Skills | Risk management, security assessment, knowledge of PCI DSS | Compliance auditing, documentation, regulatory knowledge |
| Work Environment | Security teams, risk management departments | Compliance teams, audit departments |
While both roles involve PCI DSS standards, the Pci Dss Risk Assessment focuses on identifying and evaluating security risks, whereas the Pci Dss Compliance Analyst concentrates on maintaining compliance and preparing for audits. Understanding these differences helps organizations assign the right responsibilities to ensure security and compliance.
What are some common challenges faced during PCI DSS risk assessments, and how can they be addressed?

Full-time
Re-posted 18 days ago
University Of Delaware rating
5.7
Based on 21 frontline employees who took The Breakroom Quiz
581st of 618 rated colleges and universities
Job description
The University of Delaware is seeking a Director of GRC and Security Architecture to lead the organization's information security risk, compliance, and architectural security posture. This senior leadership role involves overseeing the enterprise-wide governance, risk management, and security architecture, ensuring compliance with regulations such as HIPAA while partnering with various teams to implement effective security controls.
Responsibilities:
• Lead the enterprise Information Security Governance, Risk, and Compliance (GRC) program.
• Establish and maintain security policies, standards, procedures, and control frameworks aligned with NIST, HITRUST, ISO 27001, and other applicable frameworks.
• Oversee enterprise risk assessments, third-party risk management, and control effectiveness evaluations.
• Translate regulatory, legal, and contractual requirements into actionable security controls and architectural standards.
• Ensure ongoing compliance with applicable regulations and standards, including HIPAA, PCI DSS, FERPA, SOC 2, and FIPS-140, as applicable
• Serve as the organization’s designated HIPAA Security Officer.
• Oversee administrative, technical, and physical safeguards required under the HIPAA Security Rule.
• Partner with Privacy, Legal, Compliance, and Health IT leadership on risk analyses, remediation plans, and regulatory inquiries.
• Support audits, investigations, and compliance reviews related to protected health information (PHI).
• Ensure appropriate security awareness and HIPAA training programs are developed and delivered across the organization.
• Own and lead the security architecture function, defining enterprise security architecture principles, reference architectures, and design standards.
• Review and approve security architecture for new systems, applications, cloud services, and major technology initiatives.
• Ensure security is embedded early in system lifecycle activities through secure-by-design and defense-in-depth principles.
• Partner with infrastructure, cloud, application, and DevOps teams to integrate security requirements into platforms and solutions.
• Guide architectural decisions related to identity, network segmentation, encryption, key management, logging, and data protection.
• Contribute to and lead multi-year security strategy and roadmap development in alignment with organizational objectives.
• Actively participate in enterprise security and risk governance forums, advising executive leadership on risk posture and architectural trade-offs.
• Balance risk reduction with operational efficiency, usability, and institutional mission requirements.
• Serve as a trusted advisor to schools, departments, and business units on risk and architectural security decisions.
• Provide governance and oversight for security technologies supporting risk management, compliance, and architectural controls.
• Ensure alignment between security architecture standards and operational security tooling.
• Evaluate new security technologies and frameworks to address evolving regulatory and threat landscapes.
• Develop and report meaningful risk and compliance metrics to senior leadership and governance committees.
• Communicate complex security and compliance topics clearly to technical and non-technical stakeholders.
• Provide executive-level reporting on risk trends, compliance posture, and architectural maturity.
• Lead and develop GRC and security architecture professionals.
• Establish clear role definitions, performance expectations, and professional development pathways.
• Foster a culture of accountability, continuous improvement, and collaboration across security and IT teams.
• Manage budgets associated with GRC, compliance, and security architecture programs.
• Oversee vendor relationships related to risk management, compliance tooling, and architectural services.
• Ensure responsible financial stewardship and alignment with strategic priorities.
Qualifications:
Required:
• Bachelor’s degree in Information Security, Computer Science, Information Systems, or a related field
• Seven years of progressive experience in information security, risk management, or IT, including leadership roles
• Demonstrated experience leading GRC programs, regulatory compliance efforts, and enterprise risk management
• Strong knowledge of HIPAA Security Rule, PCI DSS, and related regulatory frameworks
• Proven experience defining and governing security architecture across enterprise and cloud environments
• Excellent written and verbal communication skills, including executive-level presentations
Preferred:
• Master’s degree in Information Security, Computer Science, Information Systems, or a related field
• Experience supporting healthcare, higher education, or regulated enterprise environments
• Hands-on experience with NIST, HITRUST CSF, ISO 27001, SOC 2, and third-party risk frameworks
• Professional certifications such as CISSP, CISM, CRISC, or equivalent
• Experience partnering closely with SOC, IR, Privacy, and Legal teams
• Demonstrated success leading organizational change and maturing security governance programs
Company:
The University of Delaware is a private-public research university located in Newark, Delaware. UD is the largest university in Delaware Founded in 1743, the company is headquartered in Newark, USA, with a team of 1001-5000 employees. The company is currently Late Stage.
What University Of Delaware employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About University of Delaware
Sourced by ZipRecruiter
Industry
Colleges, universities, and professional schools
Company size
1,001 - 5,000 Employees
Headquarters location
Newark, DE, US
Year founded
1743