1

Pci Dss Risk Assessment Jobs in Texas (NOW HIRING)

AWS Cloud Architect

Richardson, TX · On-site

$59.50 - $79/hr

Conduct cloud security assessments, threat modeling, and risk analysis. * Implement security ... Knowledge of NIST, CIS, ISO 27001, SOC 2, PCI DSS * Strong understanding of networking, encryption ...

New

Partner closely with risk, underwriting, product, technology, fraud, operations, legal, and sales ... Lead internal and external audits, sponsor bank reviews, PCI assessments, network examinations ...

Cybersecurity Senior

Houston, TX

$95K - $123K/yr

... risk assessments, policies, evidence review, and control gaps. * Knowledge of key frameworks Experience with NIST CSF, NIST 800-53, NIST 800-171, CMMC, PCI DSS, CIS Controls, or similar standards.

Preferred Qualifications * Knowledge of PCI DSS or other payment security and compliance ... risk. * Experience with cash operations, banking activities, clearing accounts, payment gateways ...

Showing results 21-40

Pci Dss Risk Assessment information

What is a PCI DSS risk assessment?

A PCI DSS risk assessment is a formal process required by the Payment Card Industry Data Security Standard (PCI DSS) to identify, evaluate, and address potential risks that could impact the security of cardholder data. It involves analyzing how sensitive payment information is handled, stored, and transmitted within an organization, and identifying any vulnerabilities that could lead to data breaches or non-compliance. Organizations use the findings from the assessment to implement security controls and processes that help protect cardholder data and maintain PCI DSS compliance.

What are the key skills and qualifications needed to thrive as a PCI DSS risk assessor, and why are they important?

To thrive as a PCI DSS Risk Assessor, you need expertise in information security, risk management, compliance frameworks, and ideally a degree in IT or cybersecurity. Familiarity with PCI DSS standards, risk assessment tools, vulnerability scanners, and certifications like PCI Professional (PCIP) or Certified Information Systems Auditor (CISA) is typically required. Strong analytical thinking, communication, and attention to detail are crucial soft skills for effective risk evaluation and reporting. These skills and qualifications are vital to ensure organizations maintain compliance, reduce risk, and protect sensitive payment card data.

What are some common challenges faced during PCI DSS risk assessments, and how can they be addressed?

A frequent challenge in PCI DSS risk assessments is ensuring comprehensive identification and documentation of all systems and processes that store, process, or transmit cardholder data. Overlooking assets or data flows can lead to compliance gaps. Additionally, coordinating with various departments to collect accurate information can be complex. These challenges can be addressed by establishing clear communication channels, using detailed data flow diagrams, and conducting regular cross-functional meetings to maintain up-to-date asset inventories and processes.

What is the difference between Pci Dss Risk Assessment vs Pci Dss Compliance Analyst?

AspectPci Dss Risk AssessmentPci Dss Compliance Analyst
Primary FocusIdentifying and evaluating security risks related to PCI DSS requirementsEnsuring ongoing compliance with PCI DSS standards and policies
ResponsibilitiesRisk identification, vulnerability assessment, mitigation planningPolicy implementation, audit preparation, compliance documentation
Required SkillsRisk management, security assessment, knowledge of PCI DSSCompliance auditing, documentation, regulatory knowledge
Work EnvironmentSecurity teams, risk management departmentsCompliance teams, audit departments

While both roles involve PCI DSS standards, the Pci Dss Risk Assessment focuses on identifying and evaluating security risks, whereas the Pci Dss Compliance Analyst concentrates on maintaining compliance and preparing for audits. Understanding these differences helps organizations assign the right responsibilities to ensure security and compliance.

What job categories do people searching Pci Dss Risk Assessment jobs in Texas look for?

The top searched job categories for Pci Dss Risk Assessment jobs in Texas are:

What cities in Texas are hiring for Pci Dss Risk Assessment jobs?

Cities in Texas with the most Pci Dss Risk Assessment job openings:

Infographic showing various Pci Dss Risk Assessment job openings in Texas as of August 2026, with employment types broken down into 1% As Needed, 89% Full Time, 8% Part Time, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution.

Security Compliance Analyst III

Bridgehead IT

San Antonio, TX • On-site

Full-time

Re-posted 16 days ago


Job description

Job Type
Full-time
Description
Position Summary:
As a Security Compliance Analyst III, you will serve as a senior compliance professional responsible for assessing, implementing, and maintaining security and regulatory compliance programs for client environments. You will lead compliance initiatives, perform risk assessments, coordinate audits, and work directly with clients to ensure compliance with industry standards and regulatory requirements.
This role requires a strong understanding of cybersecurity frameworks, governance, risk management, and technical security controls. You will work primarily out of a ticketing system to manage compliance requests, audit activities, remediation efforts, and client deliverables while collaborating closely with security engineers, system administrators, cloud engineers, and executive stakeholders. You will also mentor junior compliance analysts and assist in developing internal compliance processes and best practices.
Participation in after-hours work may be required to support audit deadlines, security incidents, or client engagements.
Key Responsibilities:
  • Work within a structured ticketing system to manage compliance requests, audit activities, remediation tasks, client communications, and documentation.
  • Lead compliance assessments across client environments using frameworks such as ISO 27001, NIST CSF, NIST 800-53, CIS Controls, CMMC, SOC 2, HIPAA, PCI DSS, and other applicable standards.
  • Conduct formal security and compliance gap assessments and develop remediation plans to address identified deficiencies.
  • Perform technical and administrative reviews of security controls to validate compliance with applicable frameworks.
  • Lead and facilitate client readiness assessments for regulatory audits and certification initiatives.
  • Coordinate internal and external audits, including evidence collection, documentation, interviews, and audit response activities.
  • Conduct formal cybersecurity risk assessments and document identified risks, mitigation strategies, and residual risk.
  • Review security policies, standards, procedures, and technical documentation to ensure regulatory alignment.
  • Work closely with cloud, infrastructure, networking, and security engineering teams to validate technical control implementation.
  • Monitor remediation activities and verify corrective actions have been successfully completed.
  • Develop compliance reports, executive summaries, dashboards, and client deliverables.
  • Assist clients with security governance initiatives, including policy development, security awareness recommendations, and compliance roadmaps.
  • Maintain detailed documentation including risk registers, assessment reports, audit evidence, and compliance matrices.
  • Research changes to regulatory requirements and recommend updates to internal processes and client security programs.
  • Mentor Security Compliance Analyst I and II team members by providing guidance on assessment methodologies, framework interpretation, and documentation standards.
  • Participate in client meetings to present assessment findings, explain compliance requirements, and provide remediation guidance.
  • Support security incident response activities when compliance reporting or regulatory notification requirements are involved.
  • Perform additional duties as assigned.

Skills and Qualifications:
  • 5-7 years of experience in cybersecurity, governance, risk management, compliance, IT auditing, or information security.
  • Strong working knowledge of cybersecurity frameworks including ISO 27001, NIST CSF, NIST 800-53, CIS Controls, CMMC, SOC 2, HIPAA, and PCI DSS.
  • Experience conducting security risk assessments, compliance assessments, and audit preparation activities.
  • Understanding of Microsoft 365, Azure, AWS, Active Directory, identity management, networking, endpoint security, vulnerability management, and cloud security concepts.
  • Experience interpreting regulatory requirements and translating them into practical technical and administrative controls.
  • Excellent technical writing, documentation, and report development skills.
  • Strong communication and presentation skills with the ability to communicate effectively with technical teams, executive leadership, auditors, and clients.
  • Experience working in ticketing systems such as ConnectWise, ServiceNow, Autotask, or similar service management platforms.
  • Strong analytical, organizational, and project coordination skills.
  • Ability to manage multiple client engagements simultaneously while meeting deadlines.
  • Preferred certifications include ISC2 Certified Information Systems Security Professional (CISSP), ISACA Certified Information Systems Auditor (CISA), ISACA Certified Information Security Manager (CISM), CompTIA Security+, CompTIA CySA+, ISO 27001 Lead Implementer or Lead Auditor, Certified in Risk and Information Systems Control (CRISC), or CMMC Certified Professional (CCP).

Disclaimer:
The duties and responsibilities described in this job description are not a comprehensive list and additional tasks may be assigned to the employee from time to time. This job description in no way states or implies that these are the only duties to be performed by the employee(s) in this position. Employees will be required to follow any other job-related instructions and to perform any other job-related duties requested by any person authorized to give instructions or assignments. All duties and responsibilities are essential functions and requirements and are subject to possible modification to reasonably accommodate individuals with disabilities. To perform this job successfully, the employees will possess the skills, aptitudes, and abilities to perform each duty proficiently. The requirements listed in this document are the minimum levels of knowledge, skills, or abilities.