1

Pci Dss Risk Assessment Jobs in Florida (NOW HIRING)

Manager, Cybersecurity

Orlando, FL · Hybrid

$103K - $140K/yr

... e.g., PCI-DSS, GDPR, sector-specific rules). * Lead security operations, including threat ... Establish and oversee risk assessment, security audit, and compliance programs across all business ...

Manager, Cybersecurity

Orlando, FL · On-site

$103K - $139K/yr

... g., PCI-DSS, GDPR, sector-specific rules). • Lead security operations, including threat ... risk assessment, security audit, and compliance programs across all business units. • Own ...

... Security, Risk, Finance, and Operations. Payments are mission-critical to Hertz revenue; this ... Own engineering accountability for PCI DSS compliance posture across payment systems. * Partner ...

Interpret and validate contractual and scheme requirements (Visa and Mastercard rulebooks, PCI DSS ... Partner closely with developers, product managers, card operations, fraud and risk, and member ...

next page

Showing results 1-20

Pci Dss Risk Assessment information

What is a PCI DSS risk assessment?

A PCI DSS risk assessment is a formal process required by the Payment Card Industry Data Security Standard (PCI DSS) to identify, evaluate, and address potential risks that could impact the security of cardholder data. It involves analyzing how sensitive payment information is handled, stored, and transmitted within an organization, and identifying any vulnerabilities that could lead to data breaches or non-compliance. Organizations use the findings from the assessment to implement security controls and processes that help protect cardholder data and maintain PCI DSS compliance.

What are the key skills and qualifications needed to thrive as a PCI DSS risk assessor, and why are they important?

To thrive as a PCI DSS Risk Assessor, you need expertise in information security, risk management, compliance frameworks, and ideally a degree in IT or cybersecurity. Familiarity with PCI DSS standards, risk assessment tools, vulnerability scanners, and certifications like PCI Professional (PCIP) or Certified Information Systems Auditor (CISA) is typically required. Strong analytical thinking, communication, and attention to detail are crucial soft skills for effective risk evaluation and reporting. These skills and qualifications are vital to ensure organizations maintain compliance, reduce risk, and protect sensitive payment card data.

What is the difference between Pci Dss Risk Assessment vs Pci Dss Compliance Analyst?

AspectPci Dss Risk AssessmentPci Dss Compliance Analyst
Primary FocusIdentifying and evaluating security risks related to PCI DSS requirementsEnsuring ongoing compliance with PCI DSS standards and policies
ResponsibilitiesRisk identification, vulnerability assessment, mitigation planningPolicy implementation, audit preparation, compliance documentation
Required SkillsRisk management, security assessment, knowledge of PCI DSSCompliance auditing, documentation, regulatory knowledge
Work EnvironmentSecurity teams, risk management departmentsCompliance teams, audit departments

While both roles involve PCI DSS standards, the Pci Dss Risk Assessment focuses on identifying and evaluating security risks, whereas the Pci Dss Compliance Analyst concentrates on maintaining compliance and preparing for audits. Understanding these differences helps organizations assign the right responsibilities to ensure security and compliance.

What are some common challenges faced during PCI DSS risk assessments, and how can they be addressed?

A frequent challenge in PCI DSS risk assessments is ensuring comprehensive identification and documentation of all systems and processes that store, process, or transmit cardholder data. Overlooking assets or data flows can lead to compliance gaps. Additionally, coordinating with various departments to collect accurate information can be complex. These challenges can be addressed by establishing clear communication channels, using detailed data flow diagrams, and conducting regular cross-functional meetings to maintain up-to-date asset inventories and processes.

What job categories do people searching Pci Dss Risk Assessment jobs in Florida look for?

The top searched job categories for Pci Dss Risk Assessment jobs in Florida are:

What cities in Florida are hiring for Pci Dss Risk Assessment jobs?

Cities in Florida with the most Pci Dss Risk Assessment job openings:

Full-time

Re-posted 28 days ago


Job description

Our team members are the key to our company’s success, and their health and well-being, as well as that of their families, is very important to us. We offer a comprehensive benefits package that allows our team members stay healthy, plan for their future and maintain a healthy work-life balance. Benefits may vary with employment status.  To see our fill list of Team Member Benefits please visit our career site: www.gotoworkhappy.com/benefits

Job Description:

The Cyber Risk Assessor III leads cybersecurity risk assessments, control evaluations, and policy oversight across the organization's Governance, Risk, and Compliance program. This strategic role identifies and assesses risks, evaluates control effectiveness, drives regulatory and framework alignment, and strengthens governance processes organization-wide.

Key Responsibilities

Governance, Risk Assessment & Management

  • Lead cybersecurity risk assessments for systems, applications, business processes, and third-party
  • Drive the identification, analysis, and documentation of cybersecurity risks and control gaps using methodologies such as FAIR and NIST RMF
  • Evaluate and assess the risk of cybersecurity issues, findings, and their potential impact to the organization
  • Oversee and maintain the Cybersecurity risk register with clear ownership, accountability, and tracking
  • Develop mitigation strategies, compensating controls, and risk-based remediation plans with business and technical stakeholders
  • Responsible for monitoring and reporting on risk trends, control effectiveness, compliance status, and remediation progress for leadership and stakeholders.
  • Own and manage the Cybersecurity Exception Process, including evaluation, approval workflows, and ongoing monitoring
  • Establish and track key risk indicators (KRIs) and report on risk trends, control effectiveness, and remediation progress to senior leadership
  • Proactively identify, track, and escalate top organizational cybersecurity risks to leadership
  • Lead the development, documentation, and continuous improvement of security and GRC processes to strengthen governance, consistency, and operational effectiveness.
  • Lead the development, review, and maintenance of cybersecurity policies, standards, procedures, and related governance documentation.
  • Support security awareness, governance communications, and continuous improvement initiatives across the GRC program.

Control Evaluation & Maturity Assessment

  • Lead the evaluation of design and operating effectiveness of security controls across the organization
  • Conduct and manage internal cybersecurity maturity assessments to evaluate program effectiveness and identify improvement opportunities
  • Assess control maturity levels and develop roadmaps for enhancement
  • Map controls to frameworks such as NIST, ISO 27001, PCI DSS, and other applicable standards

Stakeholder Engagement & Reporting

  • Serve as the subject matter expert and advisor on complex cybersecurity risk issues
  • Lead and influence cross-functional engagement with IT, Cybersecurity, Audit, Legal, Privacy, and business teams
  • Develop and deliver executive-level cybersecurity risk reports for senior management and board-level stakeholders, highlighting critical risks and mitigation strategies
  • Communicate complex technical and risk information effectively to both technical and non-technical audiences
  • Present risk assessments, findings, and strategic recommendations to executive leadership and board committees
  • Lead and facilitate risk workshops and training sessions to promote risk-aware culture

Required Qualifications

Experience & Expertise

  • 7+ years of progressive experience in cybersecurity, Governance, Risk, and Compliance (GRC), or information security
  • Demonstrated experience leading enterprise-level risk assessments and governance programs
  • Deep expertise in risk assessment methodologies and control evaluation concepts
  • Experience with cybersecurity frameworks: NIST CSF, ISO 27001, PCI DSS, SOC 2, and/or CIS Controls
  • Proven experience developing policies, standards, procedures, and governance documentation
  • Experience assessing risk of cybersecurity issues and developing remediation strategies
  • Experience conducting technical risk assessments and security architecture reviews
  • Proven experience leading and managing cybersecurity maturity assessments

Technical Knowledge

  • Comprehensive knowledge across all cybersecurity domains including infrastructure security, network security, application security, cloud security, identity and access management, data protection, endpoint security, security operations, and emerging technologies such as artificial intelligence
  • Understanding of security control applicability and limitations across different technology environments
  • Current knowledge of the threat landscape and attack vectors

Skills & Competencies

  • Strategic thinking and ability to translate technical vulnerabilities into business risk and impact
  • Excellent analytical skills with ability to synthesize complex information into actionable insights
  • Superior written and verbal communication and report-writing capabilities
  • Proven ability to influence and drive outcomes without direct authority across all organizational levels
  • Critical thinking and problem-solving abilities
  • Attention to detail while maintaining strategic perspective
  • Demonstrated leadership in mentoring and developing team members

Preferred Qualifications

Certifications

  • CISSP (Certified Information Systems Security Professional)
  • CRISC (Certified in Risk and Information Systems Control)
  • CISA (Certified Information Systems Auditor)
  • CISM (Certified Information Security Manager)
  • ISO 27001 Lead Auditor or Lead Implementer
  • FAIR Certification
  • PCI QSA or ISA

Additional Experience

  • Experience with GRC platforms (E.g., Onspring, ServiceNow GRC, Archer, OneTrust, Vanta, Drata)
  • Background in regulated industries (gaming, financial services retail)
  • Bachelor’s degree in Computer Science, Information Security, Cyber Risk Management, or related field (Master's preferred)