1

Pci Dss Risk Assessment Jobs in Washington (NOW HIRING)

Assessment Analyst

Leesburg, VA · On-site +1

$87K - $95K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

AI, we have expanded our capabilities to include advanced cyber risk quantification and analytics ... Key Responsibilities This role will specialize in FedRAMP, PCI, ISO, and other NIST-based ...

... PCI-DSS, and state regulations. • Contribute to annual risk assessments, audits, and security metrics; report on program maturity and gaps. • Maintain evidence repositories and support external ...

... PCI DSS ) Qualifications College degree (relevant field) or equivalent experience; 3-5 years of ... risk management, contingency planning, and data communications networking preferred Additional ...

Application Security Engineer

Washington, DC · On-site

$66.50 - $89/hr

... audit efforts (eg PCI DSS ) Qualifications • College degree (relevant field) or equivalent ... risk management, contingency planning, and data communications networking preferred Additional ...

Manager, Cyber Risk & Analysis

Mclean, VA · On-site

$112K - $151K/yr

Understand and assess the inventory of technology and cyber risk management related laws and regulations, as well as industry standards such as the NIST, PCI DSS, CSF and FFIEC guidance, and how they ...

Senior Product Manager, GRC

Mclean, VA · On-site

$127K - $168K/yr

  • Medical

  • Life

  • Retirement

  • PTO

... or PCI DSS, with artificial intelligence (AI ) and emerging technologies. You will own the end-to ... Risk Officers, and IT Admins and external assessors or auditors, including C3PAOs or 3PAOs, to ...

Manager, Cyber Risk & Analysis

Mclean, VA · On-site

$112K - $151K/yr

Understand and assess the inventory of technology and cyber risk management related laws and regulations, as well as industry standards such as the NIST, PCI DSS, CSF and FFIEC guidance, and how they ...

Senior Product Manager, GRC

Mclean, VA · On-site

$99 - $225/hr

  • Medical

  • Life

  • Retirement

  • PTO

... PCI DSS, with artificial intelligence (AI) and emerging technologies. You will own the ... Risk Officers, and IT Admins and external assessors or auditors, including C3PAOs or 3PAOs, to ...

Senior Product Manager, GRC

Mclean, VA · On-site

$127K - $168K/yr

  • Medical

  • Life

  • Retirement

  • PTO

... or PCI DSS, with artificial intelligence (AI ) and emerging technologies. You will own the end-to ... Risk Officers, and IT Admins and external assessors or auditors, including C3PAOs or 3PAOs, to ...

Showing results 21-40

Pci Dss Risk Assessment information

What is a PCI DSS risk assessment?

A PCI DSS risk assessment is a formal process required by the Payment Card Industry Data Security Standard (PCI DSS) to identify, evaluate, and address potential risks that could impact the security of cardholder data. It involves analyzing how sensitive payment information is handled, stored, and transmitted within an organization, and identifying any vulnerabilities that could lead to data breaches or non-compliance. Organizations use the findings from the assessment to implement security controls and processes that help protect cardholder data and maintain PCI DSS compliance.

What are the key skills and qualifications needed to thrive as a PCI DSS risk assessor, and why are they important?

To thrive as a PCI DSS Risk Assessor, you need expertise in information security, risk management, compliance frameworks, and ideally a degree in IT or cybersecurity. Familiarity with PCI DSS standards, risk assessment tools, vulnerability scanners, and certifications like PCI Professional (PCIP) or Certified Information Systems Auditor (CISA) is typically required. Strong analytical thinking, communication, and attention to detail are crucial soft skills for effective risk evaluation and reporting. These skills and qualifications are vital to ensure organizations maintain compliance, reduce risk, and protect sensitive payment card data.

What is the difference between Pci Dss Risk Assessment vs Pci Dss Compliance Analyst?

AspectPci Dss Risk AssessmentPci Dss Compliance Analyst
Primary FocusIdentifying and evaluating security risks related to PCI DSS requirementsEnsuring ongoing compliance with PCI DSS standards and policies
ResponsibilitiesRisk identification, vulnerability assessment, mitigation planningPolicy implementation, audit preparation, compliance documentation
Required SkillsRisk management, security assessment, knowledge of PCI DSSCompliance auditing, documentation, regulatory knowledge
Work EnvironmentSecurity teams, risk management departmentsCompliance teams, audit departments

While both roles involve PCI DSS standards, the Pci Dss Risk Assessment focuses on identifying and evaluating security risks, whereas the Pci Dss Compliance Analyst concentrates on maintaining compliance and preparing for audits. Understanding these differences helps organizations assign the right responsibilities to ensure security and compliance.

What are some common challenges faced during PCI DSS risk assessments, and how can they be addressed?

A frequent challenge in PCI DSS risk assessments is ensuring comprehensive identification and documentation of all systems and processes that store, process, or transmit cardholder data. Overlooking assets or data flows can lead to compliance gaps. Additionally, coordinating with various departments to collect accurate information can be complex. These challenges can be addressed by establishing clear communication channels, using detailed data flow diagrams, and conducting regular cross-functional meetings to maintain up-to-date asset inventories and processes.

What are popular job titles related to Pci Dss Risk Assessment jobs in Washington?

For Pci Dss Risk Assessment jobs in Washington, the most frequently searched job titles are:

What job categories do people searching Pci Dss Risk Assessment jobs in Washington look for?

The top searched job categories for Pci Dss Risk Assessment jobs in Washington are:

What cities in Washington are hiring for Pci Dss Risk Assessment jobs?

Cities in Washington with the most Pci Dss Risk Assessment job openings:

Infographic showing various Pci Dss Risk Assessment job openings in Washington as of August 2026, with employment types broken down into 1% As Needed, 88% Full Time, 8% Part Time, and 3% Contract. Highlights an 88% Physical, 4% Hybrid, and 8% Remote job distribution.

4554 Security Control Assessor with Security Clearance

Procession Systems

Reston, VA • On-site

Other

Re-posted 25 days ago


Job description

GENERAL DUTIES: This role is responsible for leading Risk Management Framework and other Cyber Security controls evaluations as required for ensuring the effectiveness of security controls within an organization. Serve as the lead SCA and assist the RMF lead in managing the distribution of RMF projects and reporting status on completion efforts of each SCA team member. Their technical functions encompass a range of tasks aimed at assessing, testing, and validating security measures to identify vulnerabilities and enhance overall security posture. Here are the technical functions typically associated with this role: * Security Controls Assessment Planning: Develops comprehensive assessment plans based on established security standards, frameworks (e.g., NIST SP 800-53, ISO 27001), and regulatory requirements. Define assessment scope, objectives, methodologies, and timelines.
* Security Controls Testing: Conduct rigorous technical testing of security controls across various domains such as access control, cryptography, network security, and incident response. Use automated tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities.
* Vulnerability Scanning and Analysis: Perform vulnerability scans using automated scanning tools to identify potential security flaws in systems, networks, and applications. Analyze scan results, prioritize vulnerabilities based on risk, and provide recommendations for remediation.
* Penetration Testing: Conduct simulated cyberattacks to identify exploitable security weaknesses and assess the resilience of defensive measures. Perform network penetration testing, web application testing, wireless network testing, and social engineering assessments.
* Security Configuration Review: Review and analyze security configurations for systems, devices, and applications to ensure compliance with security policies, standards, and best practices. Identify misconfigurations, weaknesses, and deviations from security baselines.
* Security Control Validation: Validate the effectiveness of implemented security controls through rigorous testing and validation procedures. Verify that controls are functioning as intended and providing adequate protection against security threats and vulnerabilities.
* Security Documentation Review: Review security documentation, including policies, procedures, guidelines, and technical documentation, to assess alignment with security requirements and industry standards. Ensure documentation accurately reflects implemented security controls and practices.
* Compliance Assessment: Assess compliance with regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as GDPR, HIPAA, PCI DSS, and SOX through detailed compliance assessments.
* Risk Assessment and Mitigation: Conduct risk assessments to identify and prioritize security risks based on their likelihood and impact. Collaborate with stakeholders to develop risk mitigation strategies and action plans to address identified vulnerabilities.
* Security Reporting and Communication: Prepare comprehensive assessment reports detailing findings, observations, recommendations, and remediation actions. Communicate assessment results to technical and non-technical stakeholders, including senior management, IT teams, and auditors.
* Continuous Improvement Initiatives: Participate in continuous improvement initiatives aimed at enhancing the effectiveness and efficiency of security assessment processes. Identify opportunities for automation, optimization, and enhancement of assessment methodologies and tools.
* Knowledge Sharing and Training: Share knowledge and expertise with team members through training sessions, workshops, and mentoring activities. Stay updated on emerging threats, vulnerabilities, and trends in cybersecurity to continuously improve assessment practices. REQUIRED QUALIFICATIONS: * Bachelor's degree from an accredited institute in an area applicable to the position in Cybersecurity, Computer Science, Software Engineering, Systems Engineering, Information Systems, or a related technical discipline.
* 10 years of cyber-security related experience or the equivalent combination of processional support, education, or professional training.
* Skills: Strong Independent work ethic and Emotional Intelligence, exceptional oral and written communication skills, and the ability to work unsupervised and lead teams. Focuses on the consistent execution and updating of organizational processes and procedures to drive RMF efforts, CONMON, and POA&M efficiencies.
* Maintain IAT Level III Certification in DoD 8570.01-M Cybersecurity workforce, compliance with DoD Directive 8140 Cyberspace Workforce Management, and IAT Level III.
* Certification in DoD 8570.01-M Cybersecurity workforce, compliance with DoD Directive 8140 Cyberspace Workforce Management, and IAT Level III (CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, CCSP). DESIRED QUALIFICATIONS: * Experience working with the most senior members of the client organization to ensure that overall program and project direction, strategy and expectations are met.
* Possesses an understanding of DIA's CIO mission and the impact of managerial practices. - Have a firm understanding of IC and DOD Risk Management Framework (Step 1 through 7), continuous monitoring, risk scoring, and risk management experience.
* SME in one or more of the following specialties: cloud and systems architectures, Zero Trust security architecture, cloud applications and storage, high performance computing, and software development. CLEARANCE: * Top Secret Security Clearance with SCI eligibility

Procession Systems logo

About Procession Systems

Sourced by ZipRecruiter

Procession Systems, based in Reston, Virginia, United States, is an industry leader operating in the Information Technology Services sector. Established to address complex business and technology challenges, the company delivers innovative tech solutions for government entities, primarily focusing on systems integration and software development. Procession Systems takes pride in their commitment to quality, responsiveness, and results, geared towards improving public sector services and saving taxpayer dollars.

Industry

Recruiting and staffing services

Company size

11 - 50 Employees

Headquarters location

Reston, VA, US

Year founded

2016

Social media