1

Pci Dss Risk Assessment Jobs in Delaware (NOW HIRING)

Proactively assess Applications and processes for compliance to and alignment with Fiserv cyber ... PCI DSS, and ITIL * Experience with governance, risk, and compliance tools and practices for ...

... as PCI DSS, CMMC, GDPR, FERPA, HIPAA/HITECH, GLBA, and FTC Red Flags. The Security Advisor will ... Understanding of risk assessments and targeted risk analyses. * Technical understanding of ...

Pci Dss Risk Assessment information

What is a PCI DSS risk assessment?

A PCI DSS risk assessment is a formal process required by the Payment Card Industry Data Security Standard (PCI DSS) to identify, evaluate, and address potential risks that could impact the security of cardholder data. It involves analyzing how sensitive payment information is handled, stored, and transmitted within an organization, and identifying any vulnerabilities that could lead to data breaches or non-compliance. Organizations use the findings from the assessment to implement security controls and processes that help protect cardholder data and maintain PCI DSS compliance.

What are the key skills and qualifications needed to thrive as a PCI DSS risk assessor, and why are they important?

To thrive as a PCI DSS Risk Assessor, you need expertise in information security, risk management, compliance frameworks, and ideally a degree in IT or cybersecurity. Familiarity with PCI DSS standards, risk assessment tools, vulnerability scanners, and certifications like PCI Professional (PCIP) or Certified Information Systems Auditor (CISA) is typically required. Strong analytical thinking, communication, and attention to detail are crucial soft skills for effective risk evaluation and reporting. These skills and qualifications are vital to ensure organizations maintain compliance, reduce risk, and protect sensitive payment card data.

What is the difference between Pci Dss Risk Assessment vs Pci Dss Compliance Analyst?

AspectPci Dss Risk AssessmentPci Dss Compliance Analyst
Primary FocusIdentifying and evaluating security risks related to PCI DSS requirementsEnsuring ongoing compliance with PCI DSS standards and policies
ResponsibilitiesRisk identification, vulnerability assessment, mitigation planningPolicy implementation, audit preparation, compliance documentation
Required SkillsRisk management, security assessment, knowledge of PCI DSSCompliance auditing, documentation, regulatory knowledge
Work EnvironmentSecurity teams, risk management departmentsCompliance teams, audit departments

While both roles involve PCI DSS standards, the Pci Dss Risk Assessment focuses on identifying and evaluating security risks, whereas the Pci Dss Compliance Analyst concentrates on maintaining compliance and preparing for audits. Understanding these differences helps organizations assign the right responsibilities to ensure security and compliance.

What are some common challenges faced during PCI DSS risk assessments, and how can they be addressed?

A frequent challenge in PCI DSS risk assessments is ensuring comprehensive identification and documentation of all systems and processes that store, process, or transmit cardholder data. Overlooking assets or data flows can lead to compliance gaps. Additionally, coordinating with various departments to collect accurate information can be complex. These challenges can be addressed by establishing clear communication channels, using detailed data flow diagrams, and conducting regular cross-functional meetings to maintain up-to-date asset inventories and processes.
What are popular job titles related to Pci Dss Risk Assessment jobs in Delaware? For Pci Dss Risk Assessment jobs in Delaware, the most frequently searched job titles are:
What job categories do people searching Pci Dss Risk Assessment jobs in Delaware look for? The top searched job categories for Pci Dss Risk Assessment jobs in Delaware are:
What cities in Delaware are hiring for Pci Dss Risk Assessment jobs? Cities in Delaware with the most Pci Dss Risk Assessment job openings:
Infographic showing various Pci Dss Risk Assessment job openings in Delaware as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 11% Part Time, and 4% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution.

Director GRC & Security Architecture

University of Delaware

Newark, DE • On-site

Full-time

Re-posted 18 days ago


University Of Delaware rating

5.7

Company rating: 5.7 out of 10

Based on 21 frontline employees who took The Breakroom Quiz

581st of 618 rated colleges and universities


Job description

Job Summary:
The University of Delaware is seeking a Director of GRC and Security Architecture to lead the organization's information security risk, compliance, and architectural security posture. This senior leadership role involves overseeing the enterprise-wide governance, risk management, and security architecture, ensuring compliance with regulations such as HIPAA while partnering with various teams to implement effective security controls.
Responsibilities:
• Lead the enterprise Information Security Governance, Risk, and Compliance (GRC) program.
• Establish and maintain security policies, standards, procedures, and control frameworks aligned with NIST, HITRUST, ISO 27001, and other applicable frameworks.
• Oversee enterprise risk assessments, third-party risk management, and control effectiveness evaluations.
• Translate regulatory, legal, and contractual requirements into actionable security controls and architectural standards.
• Ensure ongoing compliance with applicable regulations and standards, including HIPAA, PCI DSS, FERPA, SOC 2, and FIPS-140, as applicable
• Serve as the organization’s designated HIPAA Security Officer.
• Oversee administrative, technical, and physical safeguards required under the HIPAA Security Rule.
• Partner with Privacy, Legal, Compliance, and Health IT leadership on risk analyses, remediation plans, and regulatory inquiries.
• Support audits, investigations, and compliance reviews related to protected health information (PHI).
• Ensure appropriate security awareness and HIPAA training programs are developed and delivered across the organization.
• Own and lead the security architecture function, defining enterprise security architecture principles, reference architectures, and design standards.
• Review and approve security architecture for new systems, applications, cloud services, and major technology initiatives.
• Ensure security is embedded early in system lifecycle activities through secure-by-design and defense-in-depth principles.
• Partner with infrastructure, cloud, application, and DevOps teams to integrate security requirements into platforms and solutions.
• Guide architectural decisions related to identity, network segmentation, encryption, key management, logging, and data protection.
• Contribute to and lead multi-year security strategy and roadmap development in alignment with organizational objectives.
• Actively participate in enterprise security and risk governance forums, advising executive leadership on risk posture and architectural trade-offs.
• Balance risk reduction with operational efficiency, usability, and institutional mission requirements.
• Serve as a trusted advisor to schools, departments, and business units on risk and architectural security decisions.
• Provide governance and oversight for security technologies supporting risk management, compliance, and architectural controls.
• Ensure alignment between security architecture standards and operational security tooling.
• Evaluate new security technologies and frameworks to address evolving regulatory and threat landscapes.
• Develop and report meaningful risk and compliance metrics to senior leadership and governance committees.
• Communicate complex security and compliance topics clearly to technical and non-technical stakeholders.
• Provide executive-level reporting on risk trends, compliance posture, and architectural maturity.
• Lead and develop GRC and security architecture professionals.
• Establish clear role definitions, performance expectations, and professional development pathways.
• Foster a culture of accountability, continuous improvement, and collaboration across security and IT teams.
• Manage budgets associated with GRC, compliance, and security architecture programs.
• Oversee vendor relationships related to risk management, compliance tooling, and architectural services.
• Ensure responsible financial stewardship and alignment with strategic priorities.
Qualifications:
Required:
• Bachelor’s degree in Information Security, Computer Science, Information Systems, or a related field
• Seven years of progressive experience in information security, risk management, or IT, including leadership roles
• Demonstrated experience leading GRC programs, regulatory compliance efforts, and enterprise risk management
• Strong knowledge of HIPAA Security Rule, PCI DSS, and related regulatory frameworks
• Proven experience defining and governing security architecture across enterprise and cloud environments
• Excellent written and verbal communication skills, including executive-level presentations
Preferred:
• Master’s degree in Information Security, Computer Science, Information Systems, or a related field
• Experience supporting healthcare, higher education, or regulated enterprise environments
• Hands-on experience with NIST, HITRUST CSF, ISO 27001, SOC 2, and third-party risk frameworks
• Professional certifications such as CISSP, CISM, CRISC, or equivalent
• Experience partnering closely with SOC, IR, Privacy, and Legal teams
• Demonstrated success leading organizational change and maturing security governance programs
Company:
The University of Delaware is a private-public research university located in Newark, Delaware. UD is the largest university in Delaware Founded in 1743, the company is headquartered in Newark, USA, with a team of 1001-5000 employees. The company is currently Late Stage.

What University Of Delaware employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom