Direct hands-on experience supporting PCI DSS assessments. * Direct experience with PCI DSS SAQ D ... PCI remediation tracker updates and risk summaries. * PCI auditor/requesting-entity response drafts.
Direct hands-on experience supporting PCI DSS assessments. * Direct experience with PCI DSS SAQ D ... PCI remediation tracker updates and risk summaries. * PCI auditor/requesting-entity response drafts.
Direct hands-on experience supporting PCI DSS assessments. * Direct experience with PCI DSS SAQ D ... PCI remediation tracker updates and risk summaries. * PCI auditor/requesting-entity response drafts.
Quick apply
Direct hands-on experience supporting PCI DSS assessments. * Direct experience with PCI DSS SAQ D ... PCI remediation tracker updates and risk summaries. * PCI auditor/requesting-entity response drafts.
You will be responsible for conducting internal assessments in partnership with information security officers, application owners, and service owners with PCI-DSS compliance tasks such as evidence ...
Quick apply
You will be responsible for conducting internal assessments in partnership with information security officers, application owners, and service owners with PCI-DSS compliance tasks such as evidence ...
PCI Compliance Consultant (Part time & Remote)
Sterling, VA · On-site +1
$65 - $95/hr
You will be responsible for conducting internal assessments in partnership with information security officers, application owners, and service owners with PCI-DSS compliance tasks such as evidence ...
PCI Compliance Consultant (Part time & Remote)
Sterling, VA · On-site +1
$65 - $95/hr
You will be responsible for conducting internal assessments in partnership with information security officers, application owners, and service owners with PCI-DSS compliance tasks such as evidence ...
You will conduct third-party risk assessments, track control gaps and remediation to closure ... Working knowledge of security and risk frameworks such as NIST CSF, ISO 27001, SOC 2, PCI DSS, and ...
You will conduct third-party risk assessments, track control gaps and remediation to closure ... Working knowledge of security and risk frameworks such as NIST CSF, ISO 27001, SOC 2, PCI DSS, and ...
You will conduct third-party risk assessments, track control gaps and remediation to closure ... Working knowledge of security and risk frameworks such as NIST CSF, ISO 27001, SOC 2, PCI DSS, and ...
You will conduct third-party risk assessments, track control gaps and remediation to closure ... Working knowledge of security and risk frameworks such as NIST CSF, ISO 27001, SOC 2, PCI DSS, and ...
... SOC 2, PCI DSS, and others 2. Enjoy fostering collaboration with multi-disciplinary, cross ... assessments as well as the status of the implementation, effectiveness, and remediation of ...
... SOC 2, PCI DSS, and others 2. Enjoy fostering collaboration with multi-disciplinary, cross ... assessments as well as the status of the implementation, effectiveness, and remediation of ...
... PCI-DSS). Security Measures: Install, configure, and maintain security software and tools, such as firewalls, data encryption programs, and antivirus systems. Risk Assessment: Perform risk analyses ...
... PCI-DSS). Security Measures: Install, configure, and maintain security software and tools, such as firewalls, data encryption programs, and antivirus systems. Risk Assessment: Perform risk analyses ...
... PCI-DSS). • Security Measures: Install, configure, and maintain security software and tools, such as firewalls, data encryption programs, and antivirus systems. • Risk Assessment: Perform risk ...
... PCI-DSS). • Security Measures: Install, configure, and maintain security software and tools, such as firewalls, data encryption programs, and antivirus systems. • Risk Assessment: Perform risk ...
Security Assessor
Mclean, VA · On-site
... PCI DSS, HIPAA, FedRAMP). • Remediation and Collaboration: Collaborate with system owners, IT ... A minimum of 3-5 years of experience in cybersecurity, risk management, or security assessment ...
Security Assessor
Mclean, VA · On-site
... PCI DSS, HIPAA, FedRAMP). • Remediation and Collaboration: Collaborate with system owners, IT ... A minimum of 3-5 years of experience in cybersecurity, risk management, or security assessment ...
Security Assessor
Mclean, VA · On-site
... PCI DSS, HIPAA, FedRAMP). Remediation and Collaboration: Collaborate with system owners, IT teams ... A minimum of 3-5 years of experience in cybersecurity, risk management, or security assessment ...
Security Assessor
Mclean, VA · On-site
... PCI DSS, HIPAA, FedRAMP). Remediation and Collaboration: Collaborate with system owners, IT teams ... A minimum of 3-5 years of experience in cybersecurity, risk management, or security assessment ...
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
Perform regulatory and compliance gap assessments across frameworks such as HIPAA, PCI-DSS, SOX, ... Facilitate risk identification and prioritization workshops with client stakeholders across ...
Quick apply
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
Perform regulatory and compliance gap assessments across frameworks such as HIPAA, PCI-DSS, SOX, ... Facilitate risk identification and prioritization workshops with client stakeholders across ...
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
Perform regulatory and compliance gap assessments across frameworks such as HIPAA, PCI-DSS, SOX, ... Facilitate risk identification and prioritization workshops with client stakeholders across ...
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
Perform regulatory and compliance gap assessments across frameworks such as HIPAA, PCI-DSS, SOX, ... Facilitate risk identification and prioritization workshops with client stakeholders across ...
... risk management, including NY DFS, PCI DSS, NIST CSF, ISO 27001, SOC Type II and CCPA/CPRA. * Experience conducting cybersecurity maturity assessments, control effectiveness reviews, and building ...
... risk management, including NY DFS, PCI DSS, NIST CSF, ISO 27001, SOC Type II and CCPA/CPRA. * Experience conducting cybersecurity maturity assessments, control effectiveness reviews, and building ...
... PCI DSS) * ISO Standards (e.g., ISO 27001/27002, 22301 * GDPR * HITRUST * Risk Assessments * Risk Management * Cyber Threats and Cybersecurity * Agreed Upon Procedures * Internal Audit Co-Sourcing
... PCI DSS) * ISO Standards (e.g., ISO 27001/27002, 22301 * GDPR * HITRUST * Risk Assessments * Risk Management * Cyber Threats and Cybersecurity * Agreed Upon Procedures * Internal Audit Co-Sourcing
The ideal candidate will have a strong understanding of regulatory frameworks such as PCI-DSS ... Able to manage risk assessments and security briefings to advise them of critical issues that may ...
The ideal candidate will have a strong understanding of regulatory frameworks such as PCI-DSS ... Able to manage risk assessments and security briefings to advise them of critical issues that may ...
Cybersecurity and Risk Analyst
Arlington, VA · On-site
$110K - $183K/yr
Vulnerability Assessment & Risk Evaluation * Conduct vulnerability assessments across systems ... PCI-DSS). * Contribute to incident response readiness, business continuity, and disaster recovery ...
Cybersecurity and Risk Analyst
Arlington, VA · On-site
$110K - $183K/yr
Vulnerability Assessment & Risk Evaluation * Conduct vulnerability assessments across systems ... PCI-DSS). * Contribute to incident response readiness, business continuity, and disaster recovery ...
Cybersecurity and Risk Analyst
Arlington, VA · On-site
$110K - $183K/yr
Vulnerability Assessment & Risk Evaluation * Conduct vulnerability assessments across systems ... PCI-DSS). * Contribute to incident response readiness, business continuity, and disaster recovery ...
New
Cybersecurity and Risk Analyst
Arlington, VA · On-site
$110K - $183K/yr
Vulnerability Assessment & Risk Evaluation * Conduct vulnerability assessments across systems ... PCI-DSS). * Contribute to incident response readiness, business continuity, and disaster recovery ...
New
Security Governance Risk & Compliance (GRC) Analyst with Security Clearance
Washington, DC · On-site
$130K - $170K/yr
You will also play a vital role in supporting our existing FedRAMP, SOC2, and PCI DSS compliance ... Conduct risk assessments across business units and processes. Identify risk findings and recommend ...
New
Security Governance Risk & Compliance (GRC) Analyst with Security Clearance
Washington, DC · On-site
$130K - $170K/yr
You will also play a vital role in supporting our existing FedRAMP, SOC2, and PCI DSS compliance ... Conduct risk assessments across business units and processes. Identify risk findings and recommend ...
New
Evaluate adherence to standards such as GDPR, HIPAA, PCI DSS, and SOX through detailed compliance assessments. * Risk Assessment and Mitigation: Conduct risk assessments to identify and prioritize ...
Evaluate adherence to standards such as GDPR, HIPAA, PCI DSS, and SOX through detailed compliance assessments. * Risk Assessment and Mitigation: Conduct risk assessments to identify and prioritize ...
Pci Dss Risk Assessment information
See Reston, VA salary details
$20.07 is the 25th percentile. Wages below this are outliers.
$15.01 - $20.64
28% of jobs
The median wage is $24.01 / hr.
$20.64 - $26.28
37% of jobs
$26.28 - $31.92
6% of jobs
$35.44 is the 75th percentile. Wages above this are outliers.
$31.92 - $37.56
6% of jobs
$37.56 - $43.20
12% of jobs
$43.20 - $48.84
0% of jobs
$48.84 - $54.47
0% of jobs
$54.47 - $60.11
8% of jobs
$60.11 - $65.75
0% of jobs
$65.75 - $71.39
0% of jobs
$71.39 - $77.03
2% of jobs
$15
$31
$77
How much do pci dss risk assessment jobs pay per hour?
What is a PCI DSS risk assessment?
What are the key skills and qualifications needed to thrive as a PCI DSS Risk Assessor, and why are they important?
Is PCI compliance legitimate?
Who can perform a PCI DSS assessment?
What does a PCI compliance specialist do?
What is the difference between Pci Dss Risk Assessment vs Pci Dss Compliance Analyst?
| Aspect | Pci Dss Risk Assessment | Pci Dss Compliance Analyst |
|---|---|---|
| Primary Focus | Identifying and evaluating security risks related to PCI DSS requirements | Ensuring ongoing compliance with PCI DSS standards and policies |
| Responsibilities | Risk identification, vulnerability assessment, mitigation planning | Policy implementation, audit preparation, compliance documentation |
| Required Skills | Risk management, security assessment, knowledge of PCI DSS | Compliance auditing, documentation, regulatory knowledge |
| Work Environment | Security teams, risk management departments | Compliance teams, audit departments |
While both roles involve PCI DSS standards, the Pci Dss Risk Assessment focuses on identifying and evaluating security risks, whereas the Pci Dss Compliance Analyst concentrates on maintaining compliance and preparing for audits. Understanding these differences helps organizations assign the right responsibilities to ensure security and compliance.
Does PCI DSS require risk assessments?
What are some common challenges faced during PCI DSS risk assessments, and how can they be addressed?
Full-time
Retirement
Posted 8 days ago
Job description
About the role
FYI is seeking a PCI DSS SAQ D Service Provider Lead to support an active PCI compliance program for a SaaS/cloud/payment-adjacent environment. This role will own the PCI domain in a fractional capacity, including PCI scoping support, evidence sufficiency review, quarterly scan cadence, penetration testing evidence, remediation tracking, and responses to auditors, QSAs, processors, banks, or other requesting entities. The right candidate has done this work before and can drive their lane without constant prompting.
Essential responsibilities and duties
- Support PCI DSS SAQ D Service Provider readiness, scoping, evidence review, and control interpretation.
- Review PCI scope assumptions, in-scope systems, applications, integrations, service providers, and payment/data-flow considerations.
- Coordinate and review evidence for quarterly external ASV scans and internal vulnerability scans.
- Coordinate PCI-relevant penetration testing evidence, including scope, rules of engagement, final report review, remediation, and retest evidence.
- Review evidence for file integrity monitoring, encryption, MFA, IAM, logging, monitoring, change control, secure development, vulnerability management, and remediation tracking where relevant to PCI DSS.
- Identify weak, incomplete, stale, unclear, or nonresponsive evidence before submission.
- Draft or review PCI-related auditor, QSA, processor, or requesting-entity responses.
- Support tracking of PCI remediation items, exceptions, compensating-control discussions, and risk acceptance needs.
- Help define and maintain recurring PCI compliance cadence, including quarterly scans and annual validation activities.
- Provide concise written status updates, blockers, risks, and next actions to the project manager and CISO/vCISO.
Required qualifications
- 8+ years of cybersecurity, GRC, IT audit, compliance, security consulting, or related experience.
- Direct hands-on experience supporting PCI DSS assessments.
- Direct experience with PCI DSS SAQ D; Service Provider experience is strongly preferred.
- Experience with SaaS, cloud-hosted, fintech, payment, or payment-adjacent environments.
- Working knowledge of ASV scanning, internal vulnerability scanning, penetration testing evidence, vulnerability remediation, IAM/MFA, encryption, logging, monitoring, FIM, change control, and secure development requirements.
- Ability to translate PCI requirements into practical tasks for engineering, IT, security, and business stakeholders.
- Strong written communication skills and ability to produce audit-ready summaries and responses.
- Ability to work through ambiguity and distinguish sufficient evidence from weak or incomplete evidence.
Nice to have
- Prior QSA, ISA, or QSA-firm experience.
- PCI DSS v4.x experience.
- CISA, CISSP, CISM, Security+, or equivalent certification.
- Experience with Drata, Vanta, Secureframe, Hyperproof, Jira, Confluence, AWS, Azure, GCP, or similar platforms.
- SOC 2 familiarity, especially where controls overlap with PCI DSS.
Expected deliverables
- PCI DSS SAQ D evidence and gap tracker inputs.
- PCI scope notes, assumptions, and issue summaries.
- ASV and internal vulnerability scan evidence checklists.
- Penetration testing evidence checklist and report sufficiency review notes.
- PCI remediation tracker updates and risk summaries.
- PCI auditor/requesting-entity response drafts.
- PCI quarterly and annual compliance calendar inputs.
Operating style required
This role requires a senior operator who can own the PCI lane in a fractional capacity. The contractor must communicate clearly, document next actions, identify blockers early, and coordinate through the project manager. This is not a casual side task. Responsiveness, ownership, and clean written work product are required.
FYI's Benefits/Incentives: What is in it for you?
- Opportunity to work a hybrid work schedule
- A knowledgeable, high-achieving, diverse, experienced, and fun team.
- The chance to be part of a rapidly growing company and the next success story.
- A competitive base salary with a loaded benefits package plus 401K.
- Tuition/education assistance, personal computer allowance, pet insurance.
About FYI For Your Information
Sourced by ZipRecruiter
Industry
It services
Company size
51 - 200 Employees
Headquarters location
Beltsville, MD, US
Year founded
1987