1

Pci Dss Risk Assessment Jobs in Florida (NOW HIRING)

Manager, Cybersecurity

Orlando, FL · Hybrid

$103K - $140K/yr

... e.g., PCI-DSS, GDPR, sector-specific rules). * Lead security operations, including threat ... Establish and oversee risk assessment, security audit, and compliance programs across all business ...

Manager, Cybersecurity

Orlando, FL · On-site

$103K - $139K/yr

... g., PCI-DSS, GDPR, sector-specific rules). • Lead security operations, including threat ... risk assessment, security audit, and compliance programs across all business units. • Own ...

Payments Engineer

Estero, FL · On-site

$81 - $99/hr

... Risk and Fraud teams. * Build observability into all payment paths, including structured logs ... Write secure code aligned with PCI DSS and Hertz security standards; participate in threat modeling ...

... Security, Risk, Finance, and Operations. Payments are mission-critical to Hertz revenue; this ... Own engineering accountability for PCI DSS compliance posture across payment systems. * Partner ...

Interpret and validate contractual and scheme requirements (Visa and Mastercard rulebooks, PCI DSS ... Partner closely with developers, product managers, card operations, fraud and risk, and member ...

next page

Showing results 1-20

Pci Dss Risk Assessment information

What is a PCI DSS risk assessment?

A PCI DSS risk assessment is a formal process required by the Payment Card Industry Data Security Standard (PCI DSS) to identify, evaluate, and address potential risks that could impact the security of cardholder data. It involves analyzing how sensitive payment information is handled, stored, and transmitted within an organization, and identifying any vulnerabilities that could lead to data breaches or non-compliance. Organizations use the findings from the assessment to implement security controls and processes that help protect cardholder data and maintain PCI DSS compliance.

What are the key skills and qualifications needed to thrive as a PCI DSS risk assessor, and why are they important?

To thrive as a PCI DSS Risk Assessor, you need expertise in information security, risk management, compliance frameworks, and ideally a degree in IT or cybersecurity. Familiarity with PCI DSS standards, risk assessment tools, vulnerability scanners, and certifications like PCI Professional (PCIP) or Certified Information Systems Auditor (CISA) is typically required. Strong analytical thinking, communication, and attention to detail are crucial soft skills for effective risk evaluation and reporting. These skills and qualifications are vital to ensure organizations maintain compliance, reduce risk, and protect sensitive payment card data.

What are some common challenges faced during PCI DSS risk assessments, and how can they be addressed?

A frequent challenge in PCI DSS risk assessments is ensuring comprehensive identification and documentation of all systems and processes that store, process, or transmit cardholder data. Overlooking assets or data flows can lead to compliance gaps. Additionally, coordinating with various departments to collect accurate information can be complex. These challenges can be addressed by establishing clear communication channels, using detailed data flow diagrams, and conducting regular cross-functional meetings to maintain up-to-date asset inventories and processes.

What is the difference between Pci Dss Risk Assessment vs Pci Dss Compliance Analyst?

AspectPci Dss Risk AssessmentPci Dss Compliance Analyst
Primary FocusIdentifying and evaluating security risks related to PCI DSS requirementsEnsuring ongoing compliance with PCI DSS standards and policies
ResponsibilitiesRisk identification, vulnerability assessment, mitigation planningPolicy implementation, audit preparation, compliance documentation
Required SkillsRisk management, security assessment, knowledge of PCI DSSCompliance auditing, documentation, regulatory knowledge
Work EnvironmentSecurity teams, risk management departmentsCompliance teams, audit departments

While both roles involve PCI DSS standards, the Pci Dss Risk Assessment focuses on identifying and evaluating security risks, whereas the Pci Dss Compliance Analyst concentrates on maintaining compliance and preparing for audits. Understanding these differences helps organizations assign the right responsibilities to ensure security and compliance.

What job categories do people searching Pci Dss Risk Assessment jobs in Florida look for?

The top searched job categories for Pci Dss Risk Assessment jobs in Florida are:

What cities in Florida are hiring for Pci Dss Risk Assessment jobs?

Cities in Florida with the most Pci Dss Risk Assessment job openings:

GRC Analyst - IT Security Risk and Audit Manager

Boca Raton, FL • On-site

Apex Informatics
IT Services • 1 - 10 employees

Other

This job post has expired today. Applications are no longer accepted.


Job description

Job Title: IT Security Risk and Audit Manager - Governance Risk Compliance (GRC) Analyst
Location: Tolls Data Center in Boca Raton, FL. This is an onsite position, not remote.
Job Summary: The IT Security Risk and Audit Manager at the Florida Turnpike Enterprise leads the IT security risk and audit program. This role involves managing, assessing, and mitigating risks as part of the information assurance and cybersecurity program, using standards such as NIST, ISO, PCI, and ISACA. The position entails developing and implementing strategies for IT security risk and audit, conducting risk assessments, and evaluating control effectiveness.
Key Responsibilities:
  • Perform reviews to ensure compliance with PCI, SOC2, ISO, and State of Florida cybersecurity controls.
  • Plan and assess IT security controls' effectiveness and manage remediation efforts.
  • Maintain IT security risk and compliance matrices and perform management reporting.
  • Oversee the Third-Party Risk Management Program (TPRM) and analyze SOC-2 and other reports, mapping to key security controls.
  • Manage IT security vulnerabilities in alignment with PCI and NIST standards.
  • Identify and rank the criticality of operations and assets to prioritize risk mitigation.
  • Estimate potential losses and recovery costs for critical assets if threats materialize.
  • Identify and implement cost-effective risk mitigation actions, including new policies and technical controls.
  • Coordinate and verify the remediation of audit findings.
  • Document results and develop action plans for risk mitigation.
  • Produce formal audit reports based on ISACA Audit Standards.
  • Promote compliance with regulatory requirements (e.g., PCI DSS) and IT best practices.

Skills and Requirements:
  • 7-10 years of IT Audit experience (CISA certification preferred).
  • 3 years of IT Risk Management lifecycle experience.
  • 3 years of hands-on technical experience (e.g., developer, system administrator).
  • Experience with NIST 800-30 Risk Assessment Standard.
  • Extensive experience with IT General Controls evaluation and design.
  • Advanced skills in business process mapping, documentation, and policy development.
  • Up-to-date knowledge of the current threat landscape in Information Security.
  • Solid understanding of PCI DSS standards.

Education and Certifications:
  • Bachelor's Degree in Computer Science, Information Systems, Business Administration, or a related field, or equivalent work experience.
  • Preferred certifications: CISA and CISSP.