1

Pci Dss Risk Assessment Jobs in Michigan (NOW HIRING)

Includes design of the cyber organization, governance, and risk assessments. Qualifications ... PCI, HIPAA) using ServiceNow GRC and SecOps modules. * Oversee the delivery of ServiceNow-based ...

Includes design of the cyber organization, governance, and risk assessments. Qualifications ... PCI, HIPAA) using ServiceNow GRC and SecOps modules. * Oversee the delivery of ServiceNow-based ...

Includes design of the cyber organization, governance, and risk assessments. Qualifications ... PCI, HIPAA) using ServiceNow GRC and SecOps modules. * Oversee the delivery of ServiceNow-based ...

Conduct DevSecOps current-state assessments (people/process/technology), facilitate leading ... TM cyber risk programs. Join the team developing the future state of cyber risk solutions. Required ...

Enterprise Architect

Lansing, MI

$70 - $90.25/hr

... assessments and reviews. * Experience identifying, analyzing and implementing security controls based on PCI, SOX, HIPAA, PII, FFIEC and requirements * Knowledge of ISO 27002, COSO, COBIT and NIST ...

Showing results 41-60

Pci Dss Risk Assessment information

What is a PCI DSS risk assessment?

A PCI DSS risk assessment is a formal process required by the Payment Card Industry Data Security Standard (PCI DSS) to identify, evaluate, and address potential risks that could impact the security of cardholder data. It involves analyzing how sensitive payment information is handled, stored, and transmitted within an organization, and identifying any vulnerabilities that could lead to data breaches or non-compliance. Organizations use the findings from the assessment to implement security controls and processes that help protect cardholder data and maintain PCI DSS compliance.

What are the key skills and qualifications needed to thrive as a PCI DSS risk assessor, and why are they important?

To thrive as a PCI DSS Risk Assessor, you need expertise in information security, risk management, compliance frameworks, and ideally a degree in IT or cybersecurity. Familiarity with PCI DSS standards, risk assessment tools, vulnerability scanners, and certifications like PCI Professional (PCIP) or Certified Information Systems Auditor (CISA) is typically required. Strong analytical thinking, communication, and attention to detail are crucial soft skills for effective risk evaluation and reporting. These skills and qualifications are vital to ensure organizations maintain compliance, reduce risk, and protect sensitive payment card data.

What are some common challenges faced during PCI DSS risk assessments, and how can they be addressed?

A frequent challenge in PCI DSS risk assessments is ensuring comprehensive identification and documentation of all systems and processes that store, process, or transmit cardholder data. Overlooking assets or data flows can lead to compliance gaps. Additionally, coordinating with various departments to collect accurate information can be complex. These challenges can be addressed by establishing clear communication channels, using detailed data flow diagrams, and conducting regular cross-functional meetings to maintain up-to-date asset inventories and processes.

What is the difference between Pci Dss Risk Assessment vs Pci Dss Compliance Analyst?

AspectPci Dss Risk AssessmentPci Dss Compliance Analyst
Primary FocusIdentifying and evaluating security risks related to PCI DSS requirementsEnsuring ongoing compliance with PCI DSS standards and policies
ResponsibilitiesRisk identification, vulnerability assessment, mitigation planningPolicy implementation, audit preparation, compliance documentation
Required SkillsRisk management, security assessment, knowledge of PCI DSSCompliance auditing, documentation, regulatory knowledge
Work EnvironmentSecurity teams, risk management departmentsCompliance teams, audit departments

While both roles involve PCI DSS standards, the Pci Dss Risk Assessment focuses on identifying and evaluating security risks, whereas the Pci Dss Compliance Analyst concentrates on maintaining compliance and preparing for audits. Understanding these differences helps organizations assign the right responsibilities to ensure security and compliance.

What job categories do people searching Pci Dss Risk Assessment jobs in Michigan look for?

The top searched job categories for Pci Dss Risk Assessment jobs in Michigan are:

What cities in Michigan are hiring for Pci Dss Risk Assessment jobs?

Cities in Michigan with the most Pci Dss Risk Assessment job openings:

Compliance and Risk Management Specialist

FastTek

Dearborn, MI โ€ข On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 8 days ago


Job description

Compliance and Risk Management Specialist #1062248
Position Description:
  • We are seeking a Cybersecurity Key Provisioning Process Engineer to join our Vehicle Cybersecurity organization.
  • This role sits at the intersection of automotive engineering, cryptographic security architecture, and manufacturing operations — owning the end-to-end process by which cryptographic key material is defined, provisioned, and secured across every Electronic Control Unit (ECU) and vehicle program.
  • The ideal candidate is a systems thinker who can translate cryptographic and security requirements into concrete engineering specifications, drive supplier accountability through audit and integration, and operate our backend Public Key Infrastructure (PKI) and Key Management System (KMS) to deliver secure keys at scale.
  • This is a highly cross-functional role requiring fluency in cybersecurity engineering, supplier quality/manufacturing processes, and product key management systems.
  • This role involves the development and governance of security policies and procedures, review of security controls and their efficiency, and monitoring processes for compliance risk and vulnerabilities.
  • They also specialize in managing third party security risk programs

Skills Required:
  • Embedded Systems, Auditing, Cyber Security, Compliance Professional

Skills Preferred:
  • ISO 27001, Supply Chain Operations

Experience Required:
  • Own and facilitate the process for defining, documenting, and approving cryptographic key requirements (algorithms, key lengths, key hierarchies, usage policies, rotation/expiry rules) for each ECU type and vehicle program.
  • Serve as the central point of coordination between vehicle program teams, ECU feature owners, and cybersecurity architecture to ensure requirements are complete, consistent, and traceable across program timelines.
  • Conduct technical audits of Tier-1 supplier manufacturing sites and processes to validate conformance to our cybersecurity requirements.
  • Assess supplier readiness against our cryptographic and secure manufacturing requirements; identify gaps and drive corrective action plans.
  • Establish and monitor supplier compliance metrics, escalating non-conformances through appropriate governance channels.
  • Partner with cybersecurity architects, ECU/software engineering teams, vehicle program management, procurement, and manufacturing to define cryptographic key requirements tailored to each ECU's function, threat model, and program constraints.
  • Orchestrate the technical implementation of approved key requirements within our backend PKI and KMS infrastructure, coordinating with platform/IT teams responsible for these systems.
  • Define and manage key lifecycle workflows within the KMS in alignment with program and supplier timelines.
  • Troubleshoot and resolve issues in the key delivery pipeline between backend systems and supplier manufacturing lines.
  • Author clear, precise technical documentation, specifications, and work instructions covering cryptographic key requirements, provisioning processes, and PKI/KMS interfaces.
  • Cascade approved requirements to relevant internal teams and external suppliers, ensuring proper acknowledgment and implementation.
  • Enforce compliance with documented requirements through audits, design reviews, and program gate reviews; maintain version control and change management for all specifications.

Experience Preferred:
  • Familiarity with automotive cybersecurity standards (ISO/SAE 21434, UNECE R155/R156).
  • Hands-on experience with commercial or in-house PKI/KMS platforms (e.g., Thales, Entrust, HashiCorp Vault, AWS KMS, or automotive-specific secure provisioning platforms).
  • Experience with ECU/embedded systems development lifecycle and vehicle program timing
  • Knowledge of secure manufacturing/provisioning protocols (e.g., SHE, HSM-based key injection, secure flashing).
  • Project or process management experience (e.g., Agile, Six Sigma, or similar).
  • Experience with relevant control frameworks (e.g., NIST 800-53/800-57, ISO 27001, PCI-HSM, or automotive-specific key management security standards) is a plus.

Education Required:
  • Bachelor's Degree

Additional Info:
At FastTek Global, Our Purpose is Our People and Our Planet. We come to work each day and are reminded we are helping people find their success stories. Also, Doing the right thing is our mantra. We act responsibly, give back to the communities we serve and have a little fun along the way.
We have been doing this with pride, dedication and plain, old-fashioned hard work for 24 years!
FastTek Global is financially strong, privately held company that is 100% consultant and client focused.
We've differentiated ourselves by being fast, flexible, creative and honest. Throw out everything you've heard, seen, or felt about every other IT Consulting company. We do unique things and we do them for Fortune 10, Fortune 500, and technology start-up companies.
Our benefits are second to none and thanks to our flexible benefit options you can choose the benefits you need or want, options include:
  • Medical and Dental (FastTek pays majority of the medical program)
  • Vision
  • Personal Time Off (PTO) Program
  • Long Term Disability (100% paid)
  • Life Insurance (100% paid)
  • 401(k) with immediate vesting and 3% (of salary) dollar-for-dollar match

Plus, we have a lucrative employee referral program and an employee recognition culture.
FastTek Global was named one of the Top Work Places in Michigan by the Detroit Free Press in 2013, 2014, 2015, 2016, 2017, 2018, 2019, 2020, 2021, 2022, and 2023!
To view all of our open positions go to: https://www.fasttek.com/fastswitch/findwork
Follow us on Twitter: https://twitter.com/fasttekglobal
Follow us on Instagram: https://www.instagram.com/fasttekglobal
Find us on LinkedIn: https://www.linkedin.com/company/fasttek
You can become a fan of FastTek on Facebook: https://www.facebook.com/fasttekglobal/
AI & Hiring Disclosure
We use AI tools to support parts of our hiring process, such as reviewing applications and identifying potential matches. These tools are designed to promote efficiency, consistency, and fairness, and they are always used under human oversight.
All personal data collected is used solely for recruitment purposes, and you have the right to know, access, or request deletion of your data at any time, subject to legal limits.
If AI will be used in a video interview, you'll be informed in advance and asked for your consent, with the option to opt out.
Our tools are regularly reviewed to detect potential bias and to ensure compliance with all applicable laws and our commitment to inclusive hiring.
To learn more or exercise your rights, please contact us at info@fasttek.com.