Support control operations for access reviews, vendor risk management, risk assessment, policy ... PCI DSS familiarity, especially where SOC 2 controls overlap with PCI requirements. Expected ...
Support control operations for access reviews, vendor risk management, risk assessment, policy ... PCI DSS familiarity, especially where SOC 2 controls overlap with PCI requirements. Expected ...
Planning and scoping of Asset Based Assessments, including development of communications, risk and ... 27002, SANS/CIS 20, PCI DSS, and other information security requirements and frameworks
Planning and scoping of Asset Based Assessments, including development of communications, risk and ... 27002, SANS/CIS 20, PCI DSS, and other information security requirements and frameworks
Planning and scoping of Asset Based Assessments, including development of communications, risk and ... 27002, SANS/CIS 20, PCI DSS, and other information security requirements and frameworks
Planning and scoping of Asset Based Assessments, including development of communications, risk and ... 27002, SANS/CIS 20, PCI DSS, and other information security requirements and frameworks
Planning and scoping of Asset Based Assessments, including development of communications, risk and ... 27002, SANS/CIS 20, PCI DSS, and other information security requirements and frameworks
Planning and scoping of Asset Based Assessments, including development of communications, risk and ... 27002, SANS/CIS 20, PCI DSS, and other information security requirements and frameworks
Enterprise Cybersecurity GRC Governance Analyst
Mclean, VA ยท On-site
$99 - $225/hr
Ability to reimagine and automate security controls alignment and assessment to create agile, risk ... Standard (PCI DSS), and industry-specific regulations, optimizing enterprise practices for ...
Enterprise Cybersecurity GRC Governance Analyst
Mclean, VA ยท On-site
$99 - $225/hr
Ability to reimagine and automate security controls alignment and assessment to create agile, risk ... Standard (PCI DSS), and industry-specific regulations, optimizing enterprise practices for ...
Ability to reimagine and automate security controls alignment and assessment to create agile, risk ... Standard (PCI DSS), and industry-specific regulations, optimizing enterprise practices for ...
Ability to reimagine and automate security controls alignment and assessment to create agile, risk ... Standard (PCI DSS), and industry-specific regulations, optimizing enterprise practices for ...
Ability to reimagine and automate security controls alignment and assessment to create agile, risk ... Standard (PCI DSS), and industry-specific regulations, optimizing enterprise practices for ...
Ability to reimagine and automate security controls alignment and assessment to create agile, risk ... Standard (PCI DSS), and industry-specific regulations, optimizing enterprise practices for ...
Ability to reimagine and automate security controls alignment and assessment to create agile, risk ... Standard (PCI DSS), and industry-specific regulations, optimizing enterprise practices for ...
Ability to reimagine and automate security controls alignment and assessment to create agile, risk ... Standard (PCI DSS), and industry-specific regulations, optimizing enterprise practices for ...
Systems Administrator I
$64K - $102K/yr
... PCI-DSS). * Drive continuous enhancement and administration of Microsoft 365 products to support ... in vulnerability assessments and patch management cycles to maintain a secure technology ...
Systems Administrator I
$64K - $102K/yr
... PCI-DSS). * Drive continuous enhancement and administration of Microsoft 365 products to support ... in vulnerability assessments and patch management cycles to maintain a secure technology ...
ABA Testing Analyst - 17567
Vienna, VA ยท On-site
$40 - $43/hr
PCI DSS * Strong understanding of IT and Information Security controls, risk management, compliance, and control assessment principles. * Ability to work effectively with employees, management ...
ABA Testing Analyst - 17567
Vienna, VA ยท On-site
$40 - $43/hr
PCI DSS * Strong understanding of IT and Information Security controls, risk management, compliance, and control assessment principles. * Ability to work effectively with employees, management ...
Senior Sales Engineer
Herndon, VA ยท On-site
Familiarity with BSA/AML, OFAC, GLBA, FFIEC guidance, PCI DSS 4.0.1, SOC 2 controls, model risk concepts, and audit evidence. Experience with REST, SOAP, SFTP, message queues, Kafka, data warehouses ...
Senior Sales Engineer
Herndon, VA ยท On-site
Familiarity with BSA/AML, OFAC, GLBA, FFIEC guidance, PCI DSS 4.0.1, SOC 2 controls, model risk concepts, and audit evidence. Experience with REST, SOAP, SFTP, message queues, Kafka, data warehouses ...
At least 5 years of experience performing security risk assessments and security architecture ... FFIEC, or PCI-DSS) At this time, Capital One will not sponsor a new applicant for employment ...
At least 5 years of experience performing security risk assessments and security architecture ... FFIEC, or PCI-DSS) At this time, Capital One will not sponsor a new applicant for employment ...
At least 5 years of experience performing security risk assessments and security architecture ... FFIEC, or PCI-DSS) At this time, Capital One will not sponsor a new applicant for employment ...
At least 5 years of experience performing security risk assessments and security architecture ... FFIEC, or PCI-DSS) At this time, Capital One will not sponsor a new applicant for employment ...
Associate Cybersecurity Analyst, Applied Cryptography - Local Candidates Only
Ashburn, VA ยท Hybrid
$88K/yr
Support the team to help analyze risk assessments and recommend acceptable use of encryption ... TR39, EMV, PCI-PIN, PCI-P2PE, PCI DSS, SSAE 18, etc.) Familiar/Skilled in identifying and ...
Associate Cybersecurity Analyst, Applied Cryptography - Local Candidates Only
Ashburn, VA ยท Hybrid
$88K/yr
Support the team to help analyze risk assessments and recommend acceptable use of encryption ... TR39, EMV, PCI-PIN, PCI-P2PE, PCI DSS, SSAE 18, etc.) Familiar/Skilled in identifying and ...
At least 2 years of experience building or operating automated security assessment or threat ... NIST CSF, PCI DSS, SOX ITGC, and FFIEC compliance frameworks * 2+ years experience with graph ...
At least 2 years of experience building or operating automated security assessment or threat ... NIST CSF, PCI DSS, SOX ITGC, and FFIEC compliance frameworks * 2+ years experience with graph ...
Principal Associate, Cyber Risk & Analysis
Mclean, VA ยท On-site
$131 - $150/hr
At least 2 years of experience building or operating automated security assessment or threat ... NIST CSF, PCI DSS, SOX ITGC, and FFIEC compliance frameworks * 2+ years experience with graph ...
Principal Associate, Cyber Risk & Analysis
Mclean, VA ยท On-site
$131 - $150/hr
At least 2 years of experience building or operating automated security assessment or threat ... NIST CSF, PCI DSS, SOX ITGC, and FFIEC compliance frameworks * 2+ years experience with graph ...
At least 2 years of experience building or operating automated security assessment or threat ... NIST CSF, PCI DSS, SOX ITGC, and FFIEC compliance frameworks * 2+ years experience with graph ...
At least 2 years of experience building or operating automated security assessment or threat ... NIST CSF, PCI DSS, SOX ITGC, and FFIEC compliance frameworks * 2+ years experience with graph ...
Account Executive - Federal Sales
Fairfax, VA ยท On-site
$60 - $100/hr
... PCI DSS, HITRUST, SOC 2 Type II, ISO 27001, PCI PIN, PCI P2PE, PCI TSP, PA DSS, CSA STAR, CMMC ... risk clients. * Maintain sales forecasts, key contacts & roles, account notes, and other related ...
Account Executive - Federal Sales
Fairfax, VA ยท On-site
$60 - $100/hr
... PCI DSS, HITRUST, SOC 2 Type II, ISO 27001, PCI PIN, PCI P2PE, PCI TSP, PA DSS, CSA STAR, CMMC ... risk clients. * Maintain sales forecasts, key contacts & roles, account notes, and other related ...
Systems Administrator I
$64K - $102K/yr
... in vulnerability assessments and patch management cycles to maintain a secure technology ... Familiarity with fintech or financial services compliance frameworks (e.g., SOC 2, PCI-DSS, FFIEC ...
Quick apply
Systems Administrator I
$64K - $102K/yr
... in vulnerability assessments and patch management cycles to maintain a secure technology ... Familiarity with fintech or financial services compliance frameworks (e.g., SOC 2, PCI-DSS, FFIEC ...
Systems Administrator I
Arlington, VA ยท On-site
$64K - $102K/yr
... in vulnerability assessments and patch management cycles to maintain a secure technology ... Familiarity with fintech or financial services compliance frameworks (e.g., SOC 2, PCI-DSS, FFIEC ...
Systems Administrator I
Arlington, VA ยท On-site
$64K - $102K/yr
... in vulnerability assessments and patch management cycles to maintain a secure technology ... Familiarity with fintech or financial services compliance frameworks (e.g., SOC 2, PCI-DSS, FFIEC ...
Pci Dss Risk Assessment information
See Reston, VA salary details
$20.07 is the 25th percentile. Wages below this are outliers.
$15.01 - $20.64
28% of jobs
The median wage is $24.01 / hr.
$20.64 - $26.28
37% of jobs
$26.28 - $31.92
6% of jobs
$35.44 is the 75th percentile. Wages above this are outliers.
$31.92 - $37.56
6% of jobs
$37.56 - $43.20
12% of jobs
$43.20 - $48.84
0% of jobs
$48.84 - $54.47
0% of jobs
$54.47 - $60.11
8% of jobs
$60.11 - $65.75
0% of jobs
$65.75 - $71.39
0% of jobs
$71.39 - $77.03
2% of jobs
$15
$31
$77
How much do pci dss risk assessment jobs pay per hour?
What is a PCI DSS risk assessment?
What are the key skills and qualifications needed to thrive as a PCI DSS risk assessor, and why are they important?
What are some common challenges faced during PCI DSS risk assessments, and how can they be addressed?
What is the difference between Pci Dss Risk Assessment vs Pci Dss Compliance Analyst?
| Aspect | Pci Dss Risk Assessment | Pci Dss Compliance Analyst |
|---|---|---|
| Primary Focus | Identifying and evaluating security risks related to PCI DSS requirements | Ensuring ongoing compliance with PCI DSS standards and policies |
| Responsibilities | Risk identification, vulnerability assessment, mitigation planning | Policy implementation, audit preparation, compliance documentation |
| Required Skills | Risk management, security assessment, knowledge of PCI DSS | Compliance auditing, documentation, regulatory knowledge |
| Work Environment | Security teams, risk management departments | Compliance teams, audit departments |
While both roles involve PCI DSS standards, the Pci Dss Risk Assessment focuses on identifying and evaluating security risks, whereas the Pci Dss Compliance Analyst concentrates on maintaining compliance and preparing for audits. Understanding these differences helps organizations assign the right responsibilities to ensure security and compliance.
What are popular job titles related to Pci Dss Risk Assessment jobs in Reston, VA?
For Pci Dss Risk Assessment jobs in Reston, VA, the most frequently searched job titles are:
What job categories do people searching Pci Dss Risk Assessment jobs in Reston, VA look for?
The top searched job categories for Pci Dss Risk Assessment jobs in Reston, VA are:
What cities near Reston, VA are hiring for Pci Dss Risk Assessment jobs?
Cities near Reston, VA with the most Pci Dss Risk Assessment job openings:
SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead
Silver Spring, MD โข On-site
Full-time
Retirement
Re-posted 21 days ago
Job description
About the role
FYI is seeking a SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead to support an active SOC 2 Type 2 program across Security, Availability, Processing Integrity, Confidentiality, and Privacy. This role will own the SOC 2 domain in a fractional capacity, including evidence review, control operation support, auditor communication support, recurring compliance cadence, and SaaS/cloud control maturity. The right candidate has supported real SOC 2 Type 2 audits and can work with engineering, IT, security, HR, operations, leadership, and auditors.
Essential responsibilities and duties
- Support SOC 2 Type 2 audit readiness and active auditor-response efforts across all five Trust Services Criteria.
- Review evidence requests and determine whether evidence is complete, partial, missing, stale, unclear, or misaligned to the control being tested.
- Draft and review auditor responses, management explanations, control narratives, and evidence summaries.
- Support control operations for access reviews, vendor risk management, risk assessment, policy review, security awareness, incident response, change management, and security steering activities.
- Review evidence for IAM, MFA, logging, monitoring, encryption, vulnerability management, secure SDLC, code review, release approvals, CI/CD security, SAST, DAST, SCA, backups, availability, confidentiality, processing integrity, and privacy controls.
- Coordinate with control owners to obtain timestamped, complete, and audit-ready artifacts.
- Help maintain the recurring compliance calendar for monthly, quarterly, and annual SOC 2 control activities.
- Support policy and documentation management, version control, approvals, and annual review cadence.
- Identify control design gaps, operating effectiveness gaps, evidence issues, and audit risks.
- Provide concise written status updates, blockers, risks, and next actions to the project manager and CISO/vCISO.
Required qualifications
- 8+ years of cybersecurity, GRC, IT audit, compliance, SaaS security, cloud security, security consulting, or related experience.
- GRC platform experience (Drata preferred, others include Vanta or SecureFrame)
- Direct hands-on experience supporting SOC 2 Type 2 audits.
- Experience with SaaS or cloud-hosted application environments.
- Experience reviewing evidence for control design and operating effectiveness.
- Ability to translate audit requirements into operational tasks for engineering, IT, security, HR, legal, operations, and leadership stakeholders.
- Strong written communication skills and ability to produce auditor-ready explanations.
- Ability to drive control owners and follow-ups without constant prompting.
- Ability to work through ambiguity and produce clean, organized, audit-ready documentation.
Nice to have
- Prior SOC 2 auditor, CPA-firm, or audit-support experience.
- Experience with all five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
- CISA, CISSP, CISM, Security+, CPA, ISO 27001 Lead Auditor, or equivalent certification.
- Experience with Drata, Vanta, Secureframe, Hyperproof, Jira, Confluence, AWS, Azure, GCP, CI/CD tooling, SAST, DAST, SCA, vulnerability management, or cloud security tools.
- PCI DSS familiarity, especially where SOC 2 controls overlap with PCI requirements.
Expected deliverables
- SOC 2 Five-TSC evidence and gap tracker inputs.
- Control evidence sufficiency reviews.
- Auditor response drafts and management-response drafts.
- Control narrative and control-description updates.
- Recurring compliance calendar inputs for access reviews, vendor reviews, risk assessments, policy reviews, steering meetings, and evidence refresh cycles.
- Policy, procedure, and documentation review notes.
- SOC 2 blocker, risk, and next-action summaries.
Operating style required
This role requires a senior operator who can own the SOC 2 lane in a fractional capacity. The contractor must communicate clearly, document next actions, identify blockers early, and coordinate through the project manager. This is not a casual side task. Responsiveness, ownership, and clean written work product are required.
FYI's Benefits/Incentives: What is in it for you?
- Opportunity to work a hybrid work schedule
- A knowledgeable, high-achieving, diverse, experienced, and fun team.
- The chance to be part of a rapidly growing company and the next success story.
- A competitive base salary with a loaded benefits package plus 401K.
- Tuition/education assistance, personal computer allowance, pet insurance.
About FYI For Your Information
Sourced by ZipRecruiter
Industry
It services
Company size
51 - 200 Employees
Headquarters location
Beltsville, MD, US
Year founded
1987