1

Pci Dss Risk Assessment Jobs in Virginia (NOW HIRING)

... PCI DSS * Bachelor's degree in Business, Information Systems, or a related field, or equivalent ... Ability to clearly communicate assessment findings, conclusions, and recommendations to leadership

The Analyst will be responsible for all phases of the assessment and communications with business ... CIS 20, PCI DSS, and other Information Security requirements and frameworks • Experience in ...

Planning & Scoping of Asset Based Assessments to include development of communications, risk ... 27002, SANS/CIS 20, PCI DSS, and other Information Security requirements and frameworks

Planning & Scoping of Asset Based Assessments to include development of communications, risk ... 27002, SANS/CIS 20, PCI DSS, and other Information Security requirements and frameworks

Planning & Scoping of Asset Based Assessments to include development of communications, risk ... 27002, SANS/CIS 20, PCI DSS, and other Information Security requirements and frameworks

Business Risk Analyst

Vienna, VA · On-site

$45 - $55/hr

Planning & Scoping of Asset Based Assessments to include development of communications, risk ... 27002, SANS/CIS 20, PCI DSS, and other Information Security requirements and frameworks

Perform information security risk assessments for new projects, services and initiatives, and drive ... Maintain and expand SES's certification portfolio, including ISO 27001, SOC 2 and PCI DSS, and ...

Perform information security risk assessments for new projects, services and initiatives, and drive ... Maintain and expand SES's certification portfolio, including ISO 27001, SOC 2 and PCI DSS, and ...

Perform information security risk assessments for new projects, services and initiatives, and drive ... Maintain and expand SES's certification portfolio, including ISO 27001, SOC 2 and PCI DSS, and ...

Serve as the primary point of contact for external auditors and assessors during compliance audits ... Ownership of INIT's risk management, governance, and compliance program across PCI DSS, SOC 2, and ...

Senior IT Security Engineer

Chesapeake, VA · On-site

$92K - $126K/yr

... assessors during compliance audits and certification cycles, and direct remediation of audit ... risk management, governance, and compliance program across PCI DSS, SOC2, and ISO 27001. • A ...

Senior IT Security Engineer

Chesapeake, VA

$92K - $126K/yr

... assessors during compliance audits and certification cycles, and direct remediation of audit ... risk management, governance, and compliance program across PCI DSS, SOC2, and ISO 27001. • A ...

Major Account Manager

Fairfax, VA · On-site

$100 - $130/hr

... risk, and compliance (IT-GRC) with confidence. Our innovative Compliance as a Service (CaaS ... across PCI DSS, ISO 27001, HITRUST, SOC 2, GDPR, HIPAA, FedRAMP, CMMC, and over 100 other ...

next page

Showing results 1-20

Pci Dss Risk Assessment information

What is a PCI DSS risk assessment?

A PCI DSS risk assessment is a formal process required by the Payment Card Industry Data Security Standard (PCI DSS) to identify, evaluate, and address potential risks that could impact the security of cardholder data. It involves analyzing how sensitive payment information is handled, stored, and transmitted within an organization, and identifying any vulnerabilities that could lead to data breaches or non-compliance. Organizations use the findings from the assessment to implement security controls and processes that help protect cardholder data and maintain PCI DSS compliance.

What are the key skills and qualifications needed to thrive as a PCI DSS risk assessor, and why are they important?

To thrive as a PCI DSS Risk Assessor, you need expertise in information security, risk management, compliance frameworks, and ideally a degree in IT or cybersecurity. Familiarity with PCI DSS standards, risk assessment tools, vulnerability scanners, and certifications like PCI Professional (PCIP) or Certified Information Systems Auditor (CISA) is typically required. Strong analytical thinking, communication, and attention to detail are crucial soft skills for effective risk evaluation and reporting. These skills and qualifications are vital to ensure organizations maintain compliance, reduce risk, and protect sensitive payment card data.

What are some common challenges faced during PCI DSS risk assessments, and how can they be addressed?

A frequent challenge in PCI DSS risk assessments is ensuring comprehensive identification and documentation of all systems and processes that store, process, or transmit cardholder data. Overlooking assets or data flows can lead to compliance gaps. Additionally, coordinating with various departments to collect accurate information can be complex. These challenges can be addressed by establishing clear communication channels, using detailed data flow diagrams, and conducting regular cross-functional meetings to maintain up-to-date asset inventories and processes.

What is the difference between Pci Dss Risk Assessment vs Pci Dss Compliance Analyst?

AspectPci Dss Risk AssessmentPci Dss Compliance Analyst
Primary FocusIdentifying and evaluating security risks related to PCI DSS requirementsEnsuring ongoing compliance with PCI DSS standards and policies
ResponsibilitiesRisk identification, vulnerability assessment, mitigation planningPolicy implementation, audit preparation, compliance documentation
Required SkillsRisk management, security assessment, knowledge of PCI DSSCompliance auditing, documentation, regulatory knowledge
Work EnvironmentSecurity teams, risk management departmentsCompliance teams, audit departments

While both roles involve PCI DSS standards, the Pci Dss Risk Assessment focuses on identifying and evaluating security risks, whereas the Pci Dss Compliance Analyst concentrates on maintaining compliance and preparing for audits. Understanding these differences helps organizations assign the right responsibilities to ensure security and compliance.

What job categories do people searching Pci Dss Risk Assessment jobs in Virginia look for?

The top searched job categories for Pci Dss Risk Assessment jobs in Virginia are:

What cities in Virginia are hiring for Pci Dss Risk Assessment jobs?

Cities in Virginia with the most Pci Dss Risk Assessment job openings:

Infographic showing various Pci Dss Risk Assessment job openings in Virginia as of August 2026, with employment types broken down into 1% As Needed, 87% Full Time, 10% Part Time, and 2% Contract. Highlights an 87% Physical, 4% Hybrid, and 9% Remote job distribution.

Senior Security Consultant, Continuity and Compliance - PCI DSS QSA

Pondurance

Mclean, VA • On-site, Remote

$130K - $155K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 10 days ago


Key responsibilities

  • Lead annual PCI DSS compliance assessments, including SAQs, ROCs, and other validation activities.

  • Assess client security programs, technical controls, and regulatory requirements to identify risks, vulnerabilities, and compliance gaps.

  • Own consulting engagements from initiation through completion, ensuring quality, accuracy, and readiness of assessment deliverables.


Job description

About the Role:
Pondurance is seeking an active PCI DSS Qualified Security Assessor (QSA) for our Senior Security Consultant, Continuity and Compliance position. This is a senior individual-contributor position for an experienced assessor who can independently manage engagements, evaluate technical and procedural controls, produce high-quality assessment documentation, and communicate findings to both technical teams and executive leaders. You'll work primarily independently while collaborating with other consultants and internal subject matter experts as needed.
The ideal candidate will also have strong experience with regulatory and security frameworks, including HIPAA, NIST,
CMMC, and related security frameworks based on experience and business needs.
Responsibilities:
  • Lead annual PCI DSS compliance assessments, including SAQs, ROCs, and other applicable validation activities in accordance with PCI SSC requirements and QSA responsibilities.
  • Serve as a PCI DSS subject-matter expert and trusted advisor to clients throughout the assessment lifecycle.
  • Assess client security programs, technical controls, and regulatory requirements to identify risks, vulnerabilities, compliance gaps, and opportunities for improvement.
  • Develop practical remediation strategies and recommendations aligned with regulatory requirements, industry frameworks, risk, and client business needs.
  • Own assigned consulting engagements from initiation through completion, including the accuracy, quality, documentation, and final readiness of assessment deliverables.
  • Conduct client interviews, strategic advisory sessions, and workshops with executive leadership, technical teams, and key stakeholders to evaluate controls and communicate findings.
  • Establish, review, and advise on client policies, procedures, and controls to support compliance, security, and risk-management objectives.
  • Serve as a trusted security and compliance advisor, providing strategic guidance and applying professional judgment to complex, nuanced, or ambiguous client situations.
  • Review the work of other consultants and provide technical guidance and mentorship regarding PCI DSS interpretation and assessment practices.
  • Support additional security and compliance engagements involving NIST, HIPAA, CMMC, or related frameworks as needed.

Required Qualifications:
  • Bachelor's degree and 5+ years of experience in information security compliance, auditing, and assessments; or 7+ years of demonstrated experience in a related information security discipline.
  • Current or recently active PCI DSS Qualified Security Assessor qualification, with the ability to satisfy applicable PCI SSC and Pondurance affiliation or requalification requirements.
  • Demonstrated experience independently leading ROCs for Level 1 merchants, service providers, or similarly complex environments.
  • Strong working knowledge of PCI DSS v4.0.1, including scoping, segmentation, evidence sampling, compensating controls, customized approaches, and reporting requirements.
  • Experience evaluating payment environments, cardholder data flows, cloud infrastructure, networks, operating systems, databases, applications, identity controls, logging, vulnerability management, and security operations.
  • Strong client-facing consulting skills, including the ability to navigate difficult findings and communicate effectively with technical and executive stakeholders.
  • Demonstrated ability to manage multiple assessments and produce accurate, timely, and defensible deliverables.

Preferred Qualifications:
  • CISSP, CISA, CISM, PCIP, ISA, or other relevant security certification.
  • Experience assessing both merchants and service providers.
  • Experience with cloud-based, hybrid, multi-tenant, or highly segmented environments.
  • Experience with NIST, HIPAA, CMMC, SOC 2, or related frameworks.
  • Experience mentoring assessors or performing formal quality reviews of PCI deliverables.

If you meet the QSA requirement but do not meet every preferred qualification, we still encourage you to apply. We value relevant assessment experience, technical depth, sound professional judgment, and strong client-advisory skills.
Work Environment & Schedule:
This is a full-time, U.S.-based remote position open to candidates in all 50 states. Preference will be given to candidates who can consistently work Central or Eastern Time business hours, regardless of where they reside. Team members must be available during established business hours as needed for client collaboration, calls, meetings, and internal teamwork.
Although this is a remote role, if you live close by, you'll have access to our office located in McLean, VA.
Who we are:
At Pondurance, we embrace, educate, and protect people by helping make our world a better and safer place. We believe in inviting good people into our company who are driven to become great!
Every person at Pondurance is encouraged to focus and grow in their individual areas of interest, passion, and career path. We have accessible leaders as Mentors who believe "None of us are as smart as all of us" (R. Pelletier).
We believe everyone has the freedom to be themselves, especially at work, and so we embrace, support, and celebrate each other. Each one of us influences our company's direction through speaking up; you have a voice, and we want you to use it.
Do you want to be a part of something different? Do you want to influence real change? Do you want to be part of the solution? Then join us in redefining the security and cyber risk landscape.
What We Offer:
The opportunity to apply your expertise, take on new challenges, and help customers address their biggest security objectives.
An inclusive culture of teamwork that embraces the diversity of our people and communities in which we work.
Compensation & Benefits
The anticipated base salary range for this position is $130,000 - $155,000 annually. Actual compensation will be determined in good faith based on factors such as relevant experience, technical expertise, certifications, geographic location (where applicable), and internal equity. This position may also be eligible for bonus or other incentive compensation, as well as the benefits described below.
Some of the corporate benefits for full-time employees include:
  • Medical, dental, vision, disability, FSA, HSA, life and AD&D insurance, 401(k) Plan
  • Time off: PTO, sick, holiday, & parental leave details are available

To promote a healthy and safe work community, we require background and drug screenings as part of our hiring process. Details of our process will be provided upon request.
We are an equal opportunity employer focused on celebrating diversity and inclusion. We believe that each individual should be treated equally without regard to race, color, identity, national origin, protected veteran status, religion, sex, including sexual orientation and gender identity, disability, or any other characteristic protected by law.
This job posting describes the general nature and level of work expected for this position and is not intended to be an exhaustive list of all responsibilities, duties, qualifications, or working conditions. Responsibilities and requirements may change based on business needs and applicable law.