1

Pci Dss Risk Assessment Jobs in Reston, VA (NOW HIRING)

... PCI-DSS). • Security Measures: Install, configure, and maintain security software and tools, such as firewalls, data encryption programs, and antivirus systems. • Risk Assessment: Perform risk ...

... PCI DSS, HIPAA, FedRAMP). • Remediation and Collaboration: Collaborate with system owners, IT ... A minimum of 3-5 years of experience in cybersecurity, risk management, or security assessment ...

... PCI DSS, HIPAA, FedRAMP). Remediation and Collaboration: Collaborate with system owners, IT teams ... A minimum of 3-5 years of experience in cybersecurity, risk management, or security assessment ...

next page

Showing results 1-20

Pci Dss Risk Assessment information

See Reston, VA salary details

$15

$31

$77

How much do pci dss risk assessment jobs pay per hour?

As of Jul 25, 2026, the average hourly pay for pci dss risk assessment in Reston, VA is $31.56, according to ZipRecruiter salary data. Most workers in this role earn between $20.24 and $40.24 per hour, depending on experience, location, and employer.

What is a PCI DSS risk assessment?

A PCI DSS risk assessment is a formal process required by the Payment Card Industry Data Security Standard (PCI DSS) to identify, evaluate, and address potential risks that could impact the security of cardholder data. It involves analyzing how sensitive payment information is handled, stored, and transmitted within an organization, and identifying any vulnerabilities that could lead to data breaches or non-compliance. Organizations use the findings from the assessment to implement security controls and processes that help protect cardholder data and maintain PCI DSS compliance.

What are the key skills and qualifications needed to thrive as a PCI DSS Risk Assessor, and why are they important?

To thrive as a PCI DSS Risk Assessor, you need expertise in information security, risk management, compliance frameworks, and ideally a degree in IT or cybersecurity. Familiarity with PCI DSS standards, risk assessment tools, vulnerability scanners, and certifications like PCI Professional (PCIP) or Certified Information Systems Auditor (CISA) is typically required. Strong analytical thinking, communication, and attention to detail are crucial soft skills for effective risk evaluation and reporting. These skills and qualifications are vital to ensure organizations maintain compliance, reduce risk, and protect sensitive payment card data.

Is PCI compliance legitimate?

PCI compliance is a legitimate standard established by the Payment Card Industry Security Standards Council to ensure secure handling of cardholder data. Achieving PCI DSS (Data Security Standard) compliance involves meeting specific security requirements, which is essential for organizations processing credit card transactions. For a PCI DSS Risk Assessment role, understanding these standards helps evaluate and mitigate security risks effectively.

Who can perform a PCI DSS assessment?

A PCI DSS assessment can be performed by qualified security assessors (QSAs) or internal security teams with appropriate training and expertise in PCI DSS requirements. These professionals must understand payment card industry standards, security controls, and compliance processes to accurately evaluate an organization's adherence to PCI DSS.

What does a PCI compliance specialist do?

A PCI compliance specialist assesses and ensures that organizations meet the Payment Card Industry Data Security Standard (PCI DSS) requirements for protecting cardholder data. They conduct risk assessments, develop compliance strategies, and implement security controls, often using tools like vulnerability scanners and security frameworks. Their role helps prevent data breaches and maintain secure payment environments.

What is the difference between Pci Dss Risk Assessment vs Pci Dss Compliance Analyst?

AspectPci Dss Risk AssessmentPci Dss Compliance Analyst
Primary FocusIdentifying and evaluating security risks related to PCI DSS requirementsEnsuring ongoing compliance with PCI DSS standards and policies
ResponsibilitiesRisk identification, vulnerability assessment, mitigation planningPolicy implementation, audit preparation, compliance documentation
Required SkillsRisk management, security assessment, knowledge of PCI DSSCompliance auditing, documentation, regulatory knowledge
Work EnvironmentSecurity teams, risk management departmentsCompliance teams, audit departments

While both roles involve PCI DSS standards, the Pci Dss Risk Assessment focuses on identifying and evaluating security risks, whereas the Pci Dss Compliance Analyst concentrates on maintaining compliance and preparing for audits. Understanding these differences helps organizations assign the right responsibilities to ensure security and compliance.

Does PCI DSS require risk assessments?

Yes, PCI DSS requires organizations to perform risk assessments to identify and evaluate security vulnerabilities related to cardholder data. These assessments help ensure that appropriate controls are in place to protect sensitive information and maintain compliance with the standard.

What are some common challenges faced during PCI DSS risk assessments, and how can they be addressed?

A frequent challenge in PCI DSS risk assessments is ensuring comprehensive identification and documentation of all systems and processes that store, process, or transmit cardholder data. Overlooking assets or data flows can lead to compliance gaps. Additionally, coordinating with various departments to collect accurate information can be complex. These challenges can be addressed by establishing clear communication channels, using detailed data flow diagrams, and conducting regular cross-functional meetings to maintain up-to-date asset inventories and processes.
What job categories do people searching Pci Dss Risk Assessment jobs in Reston, VA look for? The top searched job categories for Pci Dss Risk Assessment jobs in Reston, VA are:
What cities near Reston, VA are hiring for Pci Dss Risk Assessment jobs? Cities near Reston, VA with the most Pci Dss Risk Assessment job openings:
PCI DSS SAQ D Service Provider Lead

PCI DSS SAQ D Service Provider Lead

FYI For Your Information Inc

Silver Spring, MD • On-site

Full-time

Retirement

Posted 8 days ago


Job description

FYI - For Your Information, Inc. is an SBA certified, Woman-Owned Small Business and GSA schedule holder that is a premier provider of Human Capital, Training, and Information Technology services. We have won awards for being a Great Place to Work and continue to make ground-breaking advancements. For four years in a row, we have been on Inc. Magazine's 5000 list and were recently named one of Inc.'s 2024 Mid-Atlantic Fastest Growing companies.
About the role
FYI is seeking a PCI DSS SAQ D Service Provider Lead to support an active PCI compliance program for a SaaS/cloud/payment-adjacent environment. This role will own the PCI domain in a fractional capacity, including PCI scoping support, evidence sufficiency review, quarterly scan cadence, penetration testing evidence, remediation tracking, and responses to auditors, QSAs, processors, banks, or other requesting entities. The right candidate has done this work before and can drive their lane without constant prompting.
Essential responsibilities and duties
  • Support PCI DSS SAQ D Service Provider readiness, scoping, evidence review, and control interpretation.
  • Review PCI scope assumptions, in-scope systems, applications, integrations, service providers, and payment/data-flow considerations.
  • Coordinate and review evidence for quarterly external ASV scans and internal vulnerability scans.
  • Coordinate PCI-relevant penetration testing evidence, including scope, rules of engagement, final report review, remediation, and retest evidence.
  • Review evidence for file integrity monitoring, encryption, MFA, IAM, logging, monitoring, change control, secure development, vulnerability management, and remediation tracking where relevant to PCI DSS.
  • Identify weak, incomplete, stale, unclear, or nonresponsive evidence before submission.
  • Draft or review PCI-related auditor, QSA, processor, or requesting-entity responses.
  • Support tracking of PCI remediation items, exceptions, compensating-control discussions, and risk acceptance needs.
  • Help define and maintain recurring PCI compliance cadence, including quarterly scans and annual validation activities.
  • Provide concise written status updates, blockers, risks, and next actions to the project manager and CISO/vCISO.

Required qualifications
  • 8+ years of cybersecurity, GRC, IT audit, compliance, security consulting, or related experience.
  • Direct hands-on experience supporting PCI DSS assessments.
  • Direct experience with PCI DSS SAQ D; Service Provider experience is strongly preferred.
  • Experience with SaaS, cloud-hosted, fintech, payment, or payment-adjacent environments.
  • Working knowledge of ASV scanning, internal vulnerability scanning, penetration testing evidence, vulnerability remediation, IAM/MFA, encryption, logging, monitoring, FIM, change control, and secure development requirements.
  • Ability to translate PCI requirements into practical tasks for engineering, IT, security, and business stakeholders.
  • Strong written communication skills and ability to produce audit-ready summaries and responses.
  • Ability to work through ambiguity and distinguish sufficient evidence from weak or incomplete evidence.

Nice to have
  • Prior QSA, ISA, or QSA-firm experience.
  • PCI DSS v4.x experience.
  • CISA, CISSP, CISM, Security+, or equivalent certification.
  • Experience with Drata, Vanta, Secureframe, Hyperproof, Jira, Confluence, AWS, Azure, GCP, or similar platforms.
  • SOC 2 familiarity, especially where controls overlap with PCI DSS.

Expected deliverables
  • PCI DSS SAQ D evidence and gap tracker inputs.
  • PCI scope notes, assumptions, and issue summaries.
  • ASV and internal vulnerability scan evidence checklists.
  • Penetration testing evidence checklist and report sufficiency review notes.
  • PCI remediation tracker updates and risk summaries.
  • PCI auditor/requesting-entity response drafts.
  • PCI quarterly and annual compliance calendar inputs.

Operating style required
This role requires a senior operator who can own the PCI lane in a fractional capacity. The contractor must communicate clearly, document next actions, identify blockers early, and coordinate through the project manager. This is not a casual side task. Responsiveness, ownership, and clean written work product are required.
FYI's Benefits/Incentives: What is in it for you?
  • Opportunity to work a hybrid work schedule
  • A knowledgeable, high-achieving, diverse, experienced, and fun team.
  • The chance to be part of a rapidly growing company and the next success story.
  • A competitive base salary with a loaded benefits package plus 401K.
  • Tuition/education assistance, personal computer allowance, pet insurance.