... e.g., PCI DSS, HIPAA, Data Privacy). * Execute enterprise compliance governance frameworks ... risk appetite with business needs and translating findings into actionable steps. * Assess ...
... e.g., PCI DSS, HIPAA, Data Privacy). * Execute enterprise compliance governance frameworks ... risk appetite with business needs and translating findings into actionable steps. * Assess ...
Sr. Analyst, Technology Compliance
Richmond, VA · On-site
$99K - $148K/yr
... e.g., PCI DSS, HIPAA, Data Privacy). * Execute enterprise compliance governance frameworks ... risk appetite with business needs and translating findings into actionable steps. * Assess ...
Sr. Analyst, Technology Compliance
Richmond, VA · On-site
$99K - $148K/yr
... e.g., PCI DSS, HIPAA, Data Privacy). * Execute enterprise compliance governance frameworks ... risk appetite with business needs and translating findings into actionable steps. * Assess ...
Guide customers through vendor risk assessments, architecture reviews, penetration tests, and compliance validation (SOC2, ISO, PCI-DSS, HIPAA) * Build compelling business cases: Quantify value ...
Guide customers through vendor risk assessments, architecture reviews, penetration tests, and compliance validation (SOC2, ISO, PCI-DSS, HIPAA) * Build compelling business cases: Quantify value ...
Guide customers through vendor risk assessments, architecture reviews, penetration tests, and compliance validation (SOC2, ISO, PCI-DSS, HIPAA) * Build compelling business cases: Quantify value ...
Guide customers through vendor risk assessments, architecture reviews, penetration tests, and compliance validation (SOC2, ISO, PCI-DSS, HIPAA) * Build compelling business cases: Quantify value ...
Perform security assessments and reviews of tolling systems for vulnerabilities, misconfigurations ... Familiarity with PCI DSS 4.0+ security requirements. * Working knowledge of networking protocols ...
Quick apply
Perform security assessments and reviews of tolling systems for vulnerabilities, misconfigurations ... Familiarity with PCI DSS 4.0+ security requirements. * Working knowledge of networking protocols ...
IT Cybersecurity Architect
Chesapeake, VA · On-site
Ensure compliance with PCI DSS 4.0 and NIST Cybersecurity Framework (CSF) * Support audit readiness, risk assessments, and remediation planning * Design scalable architectures supporting divestitures ...
IT Cybersecurity Architect
Chesapeake, VA · On-site
Ensure compliance with PCI DSS 4.0 and NIST Cybersecurity Framework (CSF) * Support audit readiness, risk assessments, and remediation planning * Design scalable architectures supporting divestitures ...
IT Cybersecurity Architect
Chesapeake, VA · On-site
Ensure compliance with PCI DSS 4.0 and NIST Cybersecurity Framework (CSF) * Support audit readiness, risk assessments, and remediation planning * Design scalable architectures supporting divestitures ...
IT Cybersecurity Architect
Chesapeake, VA · On-site
Ensure compliance with PCI DSS 4.0 and NIST Cybersecurity Framework (CSF) * Support audit readiness, risk assessments, and remediation planning * Design scalable architectures supporting divestitures ...
Senior Security Engineer, GRC
Reston, VA · On-site +1
$119K - $163K/yr
... 27001, HIPAA, PCI-DSS, or FedRAMP), including direct involvement in audits and assessments ... Solid understanding of risk management principles, with hands-on experience performing risk ...
Senior Security Engineer, GRC
Reston, VA · On-site +1
$119K - $163K/yr
... 27001, HIPAA, PCI-DSS, or FedRAMP), including direct involvement in audits and assessments ... Solid understanding of risk management principles, with hands-on experience performing risk ...
PS_GRC Security Consultant
Ashburn, VA · On-site
Relevant work experience related to Cyber Security assessment. * Experience of supporting the ... such as PCI-DSS, ISO27001, NIST-CSF, CIS and/or CoBIT. * Demonstrated effective communication ...
PS_GRC Security Consultant
Ashburn, VA · On-site
Relevant work experience related to Cyber Security assessment. * Experience of supporting the ... such as PCI-DSS, ISO27001, NIST-CSF, CIS and/or CoBIT. * Demonstrated effective communication ...
Relevant work experience related to Cyber Security assessment. * Experience in supporting the ... such as PCI-DSS, ISO27001, NIST-CSF, CIS, and/or CoBIT. * Demonstrated effective communication ...
New
Relevant work experience related to Cyber Security assessment. * Experience in supporting the ... such as PCI-DSS, ISO27001, NIST-CSF, CIS, and/or CoBIT. * Demonstrated effective communication ...
New
Conduct Enterprise Risk Assessments and analyze potential exposure at a strategic level * Perform ... Learn about National and International standards and frameworks like PCI-DSS, HIPAA, and ISO 27001
Conduct Enterprise Risk Assessments and analyze potential exposure at a strategic level * Perform ... Learn about National and International standards and frameworks like PCI-DSS, HIPAA, and ISO 27001
Conduct Enterprise Risk Assessments and analyze potential exposure at a strategic level * Perform ... Learn about National and International standards and frameworks like PCI-DSS, HIPAA, and ISO 27001
Conduct Enterprise Risk Assessments and analyze potential exposure at a strategic level * Perform ... Learn about National and International standards and frameworks like PCI-DSS, HIPAA, and ISO 27001
Manager, Cyber Risk & Analysis
Mclean, VA · On-site
$112K - $151K/yr
Understand and assess the inventory of technology and cyber risk management related laws and regulations, as well as industry standards such as the NIST, PCI DSS, CSF and FFIEC guidance, and how they ...
Manager, Cyber Risk & Analysis
Mclean, VA · On-site
$112K - $151K/yr
Understand and assess the inventory of technology and cyber risk management related laws and regulations, as well as industry standards such as the NIST, PCI DSS, CSF and FFIEC guidance, and how they ...
Senior Product Manager, GRC
Washington, VA · On-site
$133K - $176K/yr
... or PCI DSS, with artificial intelligence (AI ) and emerging technologies. You will own the end-to ... Risk Officers, and IT Admins and external assessors or auditors, including C3PAOs or 3PAOs, to ...
Senior Product Manager, GRC
Washington, VA · On-site
$133K - $176K/yr
... or PCI DSS, with artificial intelligence (AI ) and emerging technologies. You will own the end-to ... Risk Officers, and IT Admins and external assessors or auditors, including C3PAOs or 3PAOs, to ...
Senior Product Manager, GRC
Mclean, VA · On-site
$127K - $168K/yr
... or PCI DSS, with artificial intelligence (AI ) and emerging technologies. You will own the end-to ... Risk Officers, and IT Admins and external assessors or auditors, including C3PAOs or 3PAOs, to ...
Senior Product Manager, GRC
Mclean, VA · On-site
$127K - $168K/yr
... or PCI DSS, with artificial intelligence (AI ) and emerging technologies. You will own the end-to ... Risk Officers, and IT Admins and external assessors or auditors, including C3PAOs or 3PAOs, to ...
Manager, Cyber Risk & Analysis
Mclean, VA · On-site
$112K - $151K/yr
Understand and assess the inventory of technology and cyber risk management related laws and regulations, as well as industry standards such as the NIST, PCI DSS, CSF and FFIEC guidance, and how they ...
Manager, Cyber Risk & Analysis
Mclean, VA · On-site
$112K - $151K/yr
Understand and assess the inventory of technology and cyber risk management related laws and regulations, as well as industry standards such as the NIST, PCI DSS, CSF and FFIEC guidance, and how they ...
Senior Product Manager, GRC
Mclean, VA · On-site
$127K - $168K/yr
... or PCI DSS, with artificial intelligence (AI ) and emerging technologies. You will own the end-to ... Risk Officers, and IT Admins and external assessors or auditors, including C3PAOs or 3PAOs, to ...
Senior Product Manager, GRC
Mclean, VA · On-site
$127K - $168K/yr
... or PCI DSS, with artificial intelligence (AI ) and emerging technologies. You will own the end-to ... Risk Officers, and IT Admins and external assessors or auditors, including C3PAOs or 3PAOs, to ...
Ability to reimagine and automate security controls alignment and assessment to create agile, risk ... Standard (PCI DSS), and industry-specific regulations, optimizing enterprise practices for ...
Ability to reimagine and automate security controls alignment and assessment to create agile, risk ... Standard (PCI DSS), and industry-specific regulations, optimizing enterprise practices for ...
... HIPAA, PCI-DSS, CIS, NIST, FedRAMP) into secure-by-design AWS implementations. You will work ... risk reduction for customers at scale. You'll write code, ship custom controls, run security ...
... HIPAA, PCI-DSS, CIS, NIST, FedRAMP) into secure-by-design AWS implementations. You will work ... risk reduction for customers at scale. You'll write code, ship custom controls, run security ...
... HIPAA, PCI-DSS, CIS, NIST, FedRAMP) into secure-by-design AWS implementations. You will work ... risk reduction for customers at scale. You'll write code, ship custom controls, run security ...
... HIPAA, PCI-DSS, CIS, NIST, FedRAMP) into secure-by-design AWS implementations. You will work ... risk reduction for customers at scale. You'll write code, ship custom controls, run security ...
Pci Dss Risk Assessment information
What is a PCI DSS risk assessment?
What are the key skills and qualifications needed to thrive as a PCI DSS risk assessor, and why are they important?
What is the difference between Pci Dss Risk Assessment vs Pci Dss Compliance Analyst?
| Aspect | Pci Dss Risk Assessment | Pci Dss Compliance Analyst |
|---|---|---|
| Primary Focus | Identifying and evaluating security risks related to PCI DSS requirements | Ensuring ongoing compliance with PCI DSS standards and policies |
| Responsibilities | Risk identification, vulnerability assessment, mitigation planning | Policy implementation, audit preparation, compliance documentation |
| Required Skills | Risk management, security assessment, knowledge of PCI DSS | Compliance auditing, documentation, regulatory knowledge |
| Work Environment | Security teams, risk management departments | Compliance teams, audit departments |
While both roles involve PCI DSS standards, the Pci Dss Risk Assessment focuses on identifying and evaluating security risks, whereas the Pci Dss Compliance Analyst concentrates on maintaining compliance and preparing for audits. Understanding these differences helps organizations assign the right responsibilities to ensure security and compliance.
What are some common challenges faced during PCI DSS risk assessments, and how can they be addressed?

CarMax rating
8.0
Based on 371 frontline employees who took The Breakroom Quiz
24th of 731 rated retailers
Job description
CarMax, the way your career should be!
About this job
We are looking for a Senior Technology Compliance Analyst who will play a pivotal role in advancing our ComplianceProgram. This unique opportunity allows you to serve as a subject matter expert, collaborating with Technology management teams todesign,evaluate and test internal controls for efficiency and effectiveness. In this role, youwillmonitor regulatoryandtechnologychanges, coordinate with internal and external auditors, and ensure compliance across the organization. Youwilllead control reviews for new business areas,technologies, andevolving processes, identify gaps between policy and practice, and recommend remediation strategies.
What you will do - Essential Responsibilities
Develop and maintain a comprehensive framework for Technology Compliance, including validation, classification, and control testing across IT domains (e.g., PCI DSS, HIPAA, Data Privacy).
Execute enterprise compliance governance frameworks, balancing risk appetite with business needs and translating findings into actionable steps.
Lead compliance assessments and pre-implementation reviews to ensure proper controls are designed, implemented, and documented.
Design, implement, and maintain enterprise-wide General IT Controls (GITCs) and compliance frameworks aligned with regulatory requirements (PCI DSS, SOX, HIPAA, Data Privacy, etc.).
Develop and enforce processes and procedures to ensure adherence to company policies, laws, and industry standards (e.g., NIST, ITIL).
Influence compliance strategy and direction within established standards and guidance.
Act as a trusted advisor and subject matter expert on technology key controls, partnering toevaluate control effectiveness,identifyrisks, and support remediation efforts.
Leverage technical experience toassistmanagementin designingappropriate automationand systemconfigurations to support the enforcement and collection ofcompliance-relatedevidence.
Facilitate internal and external audits, and provide clear, timely communication of findings, recommendations, and remediation plans.
Monitor and validate information security controls, analyze trends in control weaknesses, and recommend enhancements to meet evolving compliance standards.
Collaborate cross-functionally while demonstrating ownership, initiative, and effective communication on compliance matters.
Execute enterprise compliance governance frameworks, balancing risk appetite with business needs and translating findings into actionable steps.
Assess compliance exposure and deficiencies across internal and external systems, recommending effective solutions.
Lead remediation and design review meetings, build consensus on compliance strategies, and influence direction across teams.
Maintain awareness of emergingtechnologytrends and evolving external regulations to proactively adapt compliance processes.
Purpose of the role
As aSeniorTechnology Compliance Analyst, you will play apivotalrole in strengthening our IT control environment by driving innovation, collaboration, and continuous improvement. Youwillwork closely with product, technology, and compliance teams to design controls, assist with control execution, and perform testing and validation. This role is ideal for someone who thrives in a fast-paced environment, is passionate about technology and compliance, and embraces automation and data-driven insights to modernize practices. Success in this role requires strong communication skills, attention to detail, a proactive mindset, and a commitment to delivering high-impact solutions that enhance operational resilience and ensure regulatory alignment.
Qualifications and Requirements
Bachelor's degree(or equivalent experience),with solid IT audit or compliance experience.
Familiarity withTechnology Compliance management industry frameworks and standards: NIST, OWASP, SANS, ISO-27001/2, SANS, andCobit
5+yearsworking experience with enterprise technology compliance management programs, orauditing experience, controls testing, conducting ITGC and PCI assessments
Possession of industry certifications required: CISAand/orCISSP. Desired CRISC, CIA, CISM, PCI
StrongCommunication skillswith the ability toclearlycommunicatethrough tailored messaging, organized presentations, and group facilitation.
Strong technical skills with the ability to design IT controls and system functions that enforceor collect compliance evidence.
Demonstratesexpertisein mentoring colleagues on compliance principles andleadseffective training and awareness programs.
Demonstrates strong analytical, problem-solving, and organizational skills under pressure, with a commitment to world-class service, flexibility, and continuous improvement.
Effectiveorganization and time management skillswithstrongattention to detail.
Work Location and Arrangement:This role will be based out of the Richmond, VA Technology Innovation Center. Associates based in Richmond work onsite 5 days per week.
Work Authorization: Applicants must be currently authorized to work in the United States on a full-time basis.
About CarMax
CarMax disrupted the auto industry by delivering the honest, transparent and high-integrity experience customers want and deserve. This innovative thinkingaround the way cars are bought and soldhas helped us become the nation's largest retailer of used cars, with over 200 locations nationwide.
Ouramazing team of more than 25,000 associates work together to deliver iconic customer experiences.Along the way,we help every associate grow their career and achieve their best, at work and in their community. We are recognized for our commitment to training and diversity and areone of the FORTUNE 100 Best Companies to Work For.
Our Commitment to Diversity and Inclusion:
CarMax is committed to bringing together people from different backgrounds and perspectives, providing employees with a safe, welcoming, and inclusive work environment.
CarMax is an equal opportunity employer, and all qualified candidates will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, protected veteran status, disability status, or any other characteristic protected by law.
The annual salary for this position is:
$99,200.00 - $148,800.00May be eligible for bonus and equity.
Benefits:
Except as otherwise required by state law, CarMax Associates are entitled to the following paid sick, vacation, and holiday time.
Associates that are considered full-time hourly or commission/incentive eligible:
- To earn up to 48 hours of sick time per year accrued on a per pay period basis and between 80 hours and 200 hours per year of vacation time after a 90 day waiting period depending on years of continuous service with the Company.
- For 8 hours of pay for each of a total of 6 paid scheduled holidays per year plus 1 floating holiday. If such an Associate does work on a scheduled holiday due to business need, they are eligible for Holiday Premium Pay.
Associates considered full-time salaried are entitled to paid time away with no specified limit as needed for sick, vacation, bereavement, jury duty, holidays, floating holiday, etc. subject to manager approval.
For more details about benefits, please visit our CarMax Benefits website.
Upon an applicant's request, CarMax will consider reasonable accommodation to complete the CarMax Job Application.
About CarMax
Sourced by ZipRecruiter
CarMax disrupted the auto industry by delivering the honest, transparent and high-integrity experience customers want and deserve. This innovative thinking around the way cars are bought and sold has helped us become the nation's largest retailer of used cars, with over 200 locations nationwide. Our amazing team of more than 25,000 associates work together to deliver iconic customer experiences. Along the way, we help every associate grow their career and achieve their best, at work and in their community. We are recognized for our commitment to training and diversity and are one of the FORTUNE 100 Best Companies to Work For®.
Industry
Automobile dealers and finance and insurance
Company size
10,000+ Employees
Headquarters location
Henrico, VA, US