1

Pci Dss Risk Assessment Jobs in Virginia (NOW HIRING)

You will conduct third-party risk assessments, track control gaps and remediation to closure ... Working knowledge of security and risk frameworks such as NIST CSF, ISO 27001, SOC 2, PCI DSS, and ...

... PCI-DSS). โ€ข Security Measures: Install, configure, and maintain security software and tools, such as firewalls, data encryption programs, and antivirus systems. โ€ข Risk Assessment: Perform risk ...

... PCI DSS, HIPAA, FedRAMP). โ€ข Remediation and Collaboration: Collaborate with system owners, IT ... A minimum of 3-5 years of experience in cybersecurity, risk management, or security assessment ...

... PCI DSS, HIPAA, FedRAMP). Remediation and Collaboration: Collaborate with system owners, IT teams ... A minimum of 3-5 years of experience in cybersecurity, risk management, or security assessment ...

Senior IT Security Engineer

Chesapeake, VA ยท On-site

$92K - $126K/yr

... assessors during compliance audits and certification cycles, and direct remediation of audit ... risk management, governance, and compliance program across PCI DSS, SOC2, and ISO 27001. โ€ข A ...

Senior IT Security Engineer

Chesapeake, VA

$92K - $126K/yr

... assessors during compliance audits and certification cycles, and direct remediation of audit ... risk management, governance, and compliance program across PCI DSS, SOC2, and ISO 27001. โ€ข A ...

... Security (PCI DSS), Threat Monitoring, Threat Detection, Incident Response, Vulnerability Assessment, Risk Analysis, SIEM Tools, Network Security, Web Application Security, Endpoint Security ...

Cybersecurity and Risk Analyst

Arlington, VA ยท On-site

$120K - $135K/yr

The analyst conducts vulnerability assessments, risk evaluations, and red team/threat simulation ... PCI-DSS). * Contribute to incident response readiness, business continuity, and disaster recovery ...

Cybersecurity and Risk Analyst

Arlington, VA ยท On-site

$120K - $135K/yr

The analyst conducts vulnerability assessments, risk evaluations, and red team/threat simulation ... PCI-DSS). * Contribute to incident response readiness, business continuity, and disaster recovery ...

The analyst conducts vulnerability assessments, risk evaluations, and red team/threat simulation ... PCI-DSS). * Contribute to incident response readiness, business continuity, and disaster recovery ...

next page

Showing results 1-20

Pci Dss Risk Assessment information

What is a PCI DSS risk assessment?

A PCI DSS risk assessment is a formal process required by the Payment Card Industry Data Security Standard (PCI DSS) to identify, evaluate, and address potential risks that could impact the security of cardholder data. It involves analyzing how sensitive payment information is handled, stored, and transmitted within an organization, and identifying any vulnerabilities that could lead to data breaches or non-compliance. Organizations use the findings from the assessment to implement security controls and processes that help protect cardholder data and maintain PCI DSS compliance.

What are the key skills and qualifications needed to thrive as a PCI DSS Risk Assessor, and why are they important?

To thrive as a PCI DSS Risk Assessor, you need expertise in information security, risk management, compliance frameworks, and ideally a degree in IT or cybersecurity. Familiarity with PCI DSS standards, risk assessment tools, vulnerability scanners, and certifications like PCI Professional (PCIP) or Certified Information Systems Auditor (CISA) is typically required. Strong analytical thinking, communication, and attention to detail are crucial soft skills for effective risk evaluation and reporting. These skills and qualifications are vital to ensure organizations maintain compliance, reduce risk, and protect sensitive payment card data.

Is PCI compliance legitimate?

PCI compliance is a legitimate standard established by the Payment Card Industry Security Standards Council to ensure secure handling of cardholder data. Achieving PCI DSS (Data Security Standard) compliance involves meeting specific security requirements, which is essential for organizations processing credit card transactions. For a PCI DSS Risk Assessment role, understanding these standards helps evaluate and mitigate security risks effectively.

Who can perform a PCI DSS assessment?

A PCI DSS assessment can be performed by qualified security assessors (QSAs) or internal security teams with appropriate training and expertise in PCI DSS requirements. These professionals must understand payment card industry standards, security controls, and compliance processes to accurately evaluate an organization's adherence to PCI DSS.

What does a PCI compliance specialist do?

A PCI compliance specialist assesses and ensures that organizations meet the Payment Card Industry Data Security Standard (PCI DSS) requirements for protecting cardholder data. They conduct risk assessments, develop compliance strategies, and implement security controls, often using tools like vulnerability scanners and security frameworks. Their role helps prevent data breaches and maintain secure payment environments.

What is the difference between Pci Dss Risk Assessment vs Pci Dss Compliance Analyst?

AspectPci Dss Risk AssessmentPci Dss Compliance Analyst
Primary FocusIdentifying and evaluating security risks related to PCI DSS requirementsEnsuring ongoing compliance with PCI DSS standards and policies
ResponsibilitiesRisk identification, vulnerability assessment, mitigation planningPolicy implementation, audit preparation, compliance documentation
Required SkillsRisk management, security assessment, knowledge of PCI DSSCompliance auditing, documentation, regulatory knowledge
Work EnvironmentSecurity teams, risk management departmentsCompliance teams, audit departments

While both roles involve PCI DSS standards, the Pci Dss Risk Assessment focuses on identifying and evaluating security risks, whereas the Pci Dss Compliance Analyst concentrates on maintaining compliance and preparing for audits. Understanding these differences helps organizations assign the right responsibilities to ensure security and compliance.

Does PCI DSS require risk assessments?

Yes, PCI DSS requires organizations to perform risk assessments to identify and evaluate security vulnerabilities related to cardholder data. These assessments help ensure that appropriate controls are in place to protect sensitive information and maintain compliance with the standard.

What are some common challenges faced during PCI DSS risk assessments, and how can they be addressed?

A frequent challenge in PCI DSS risk assessments is ensuring comprehensive identification and documentation of all systems and processes that store, process, or transmit cardholder data. Overlooking assets or data flows can lead to compliance gaps. Additionally, coordinating with various departments to collect accurate information can be complex. These challenges can be addressed by establishing clear communication channels, using detailed data flow diagrams, and conducting regular cross-functional meetings to maintain up-to-date asset inventories and processes.
What job categories do people searching Pci Dss Risk Assessment jobs in Virginia look for? The top searched job categories for Pci Dss Risk Assessment jobs in Virginia are:
What cities in Virginia are hiring for Pci Dss Risk Assessment jobs? Cities in Virginia with the most Pci Dss Risk Assessment job openings:
Infographic showing various Pci Dss Risk Assessment job openings in Virginia as of July 2026, with employment types broken down into 3% As Needed, 76% Full Time, 18% Part Time, and 3% Contract. Highlights an 93% Physical, 1% Hybrid, and 6% Remote job distribution.

PCI Compliance Consultant (Part time & Remote)

TestPros

Sterling, VA โ€ข On-site, Remote

$65 - $95/hr

Contractor

Re-posted 18 days ago


Job description

TestPros delivers innovative independent IT assessment solutions to critical challenges facing the nation and the world. We support the U.S. Federal Government and Commercial clients within the continental USA. TestPros is dedicated to making lives better, safer and more secure.
Position Type: Consultant (Project-Based)
Location: Remote
Contract Period: February 2026 - February 2027 (with potential renewals)
Overview
TestPros is seeking a Payment Card Industry (PCI) SME to provide consulting, assessment, and report writing support regarding the PCI Data Security Standard (PCI DSS) and other applicable PCI Council standards. You will be responsible for conducting internal assessments in partnership with information security officers, application owners, and service owners with PCI-DSS compliance tasks such as evidence preparation, evidence gathering and review, aligned to the PCI-DSS requirements.
Required Qualifications & Skills
The ideal candidate will have excellent communication and intrapersonal skills with a solid foundational understanding and experience in process, relationship, and program management - and be a highly-motivated self-starting professional with profound understanding of PCI DSS requirements and testing methodology (version 3.2.1 and above). You must also be detail-oriented, results-focused, and have a proven track record of driving tasks to completion. And, you must be a strong team player with a demonstrated ability to work efficiently with other team members cross-functionally and across the team.
Essential Responsibilities:
Leading end-to-end internal assessments based on PCI DSS requirements
Managing team communications and visibility into status of deliverables
Obtaining ISA certification within 12 months (if not current)
Qualifications:
At least 4 years of experience supporting or leading, a Level 1 or Level 2 organization's PCI-DSS compliance effort, working with ISA or QSA
At least 1 year of experience of direct or indirect work with public Cloud systems and on-premise infrastructure or systems
At least 1 year of experience developing and implementing PCI policies, standards, and procedures
At least 1 year of experience supporting, maintaining, and implementing security for a large organization assessed against PCI-DSS and level 1 or 2
Preferred Qualifications:
Bachelor's Degree
PCI QSA or ISA certification
CISSP, GIAC, CEH, or Security+ certification
AWS Cloud Practitioner or Solutions Architect certification
PROFESSIONAL CERTIFICATIONS:
ISA (PCI SSC Internal Security Assessor),
QSA (PCI Qualified Security Assessor
PCIP (Payment Card Industry Professional),
CISSP (Certified Information Systems Security Professional),
CISM (Certified Information Security Manager),
GX-PT (GIAC Experienced Penetration Tester),
GCIA (GIAC Intrusion Analyst),
Other GIAC certifications...
Rate: $65-95/hr (1099 or Corp. To Corp.). This range represents a good-faith estimate and is not a guarantee; final compensation is determined by factors such as experience, qualifications, and government contract labor rate requirements and may fall outside the stated range.
Equal Opportunity Employer
TestPros is an equal-opportunity employer and does not discriminate in employment based on race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, retaliation, parental status, military service, or any other non-merit factor.
Offer Considerations
TestPros considers several factors when extending an offer, including but not limited to, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, geographic location, education, and certifications.
Federal Compliance
As a federal contractor, TestPros is subject to all federal and state mandates and/or other customer requirements.