1

Pci Dss Risk Assessment Jobs in Timonium, MD (NOW HIRING)

Security Analyst

Columbia, MD ยท Hybrid

$55 - $60/hr

... PCI-DSS. The role supports risk assessments, audit readiness, control validation, and policy governance. Essential Duties and Responsibilities โ€ข Support compliance initiatives aligned to NIST ...

Cybersecurity Architect

Baltimore, MD ยท On-site

$151.54 - $179.09/hr

Ensure solutions meet internal risk, compliance, and regulatory requirements (e.g., CMMC, ISO 27001, PCI DSS) * Contribute to maturity assessments and continuous improvement efforts for cybersecurity ...

Ensure solutions meet internal risk, compliance, and regulatory requirements (e.g., CCPA, NYDFS, PCI DSS). * Contribute to maturity assessments and continuous improvement efforts for cybersecurity ...

Conduct vulnerability assessments, risk assessments, and security audits. * Manage and support ... Support compliance efforts related to PCI-DSS, HIPAA, SOX, ISO 27001, NIST, or other regulatory ...

Cybersecurity Engineer

Baltimore, MD ยท On-site

$110 - $160/hr

Conduct vulnerability assessments, risk assessments, and security audits. * Manage and support ... Support compliance efforts related to PCI-DSS, HIPAA, SOX, ISO 27001, NIST, or other regulatory ...

New

Maintain compliance documentation, risk assessments, vendor scorecards, policies, and operational ... Familiarity with compliance frameworks (PCI-DSS, SOC 2, BSA/AML, GDPR/CCPA) and comfort operating ...

next page

Showing results 1-20

Pci Dss Risk Assessment information

See Timonium, MD salary details

$13

$29

$71

How much do pci dss risk assessment jobs pay per hour?

As of Sep 6, 2026, the average hourly pay for pci dss risk assessment in Timonium, MD is $29.15, according to ZipRecruiter salary data. Most workers in this role earn between $18.70 and $37.21 per hour, depending on experience, location, and employer.

What is a PCI DSS risk assessment?

A PCI DSS risk assessment is a formal process required by the Payment Card Industry Data Security Standard (PCI DSS) to identify, evaluate, and address potential risks that could impact the security of cardholder data. It involves analyzing how sensitive payment information is handled, stored, and transmitted within an organization, and identifying any vulnerabilities that could lead to data breaches or non-compliance. Organizations use the findings from the assessment to implement security controls and processes that help protect cardholder data and maintain PCI DSS compliance.

What are the key skills and qualifications needed to thrive as a PCI DSS risk assessor, and why are they important?

To thrive as a PCI DSS Risk Assessor, you need expertise in information security, risk management, compliance frameworks, and ideally a degree in IT or cybersecurity. Familiarity with PCI DSS standards, risk assessment tools, vulnerability scanners, and certifications like PCI Professional (PCIP) or Certified Information Systems Auditor (CISA) is typically required. Strong analytical thinking, communication, and attention to detail are crucial soft skills for effective risk evaluation and reporting. These skills and qualifications are vital to ensure organizations maintain compliance, reduce risk, and protect sensitive payment card data.

What are some common challenges faced during PCI DSS risk assessments, and how can they be addressed?

A frequent challenge in PCI DSS risk assessments is ensuring comprehensive identification and documentation of all systems and processes that store, process, or transmit cardholder data. Overlooking assets or data flows can lead to compliance gaps. Additionally, coordinating with various departments to collect accurate information can be complex. These challenges can be addressed by establishing clear communication channels, using detailed data flow diagrams, and conducting regular cross-functional meetings to maintain up-to-date asset inventories and processes.

What is the difference between Pci Dss Risk Assessment vs Pci Dss Compliance Analyst?

AspectPci Dss Risk AssessmentPci Dss Compliance Analyst
Primary FocusIdentifying and evaluating security risks related to PCI DSS requirementsEnsuring ongoing compliance with PCI DSS standards and policies
ResponsibilitiesRisk identification, vulnerability assessment, mitigation planningPolicy implementation, audit preparation, compliance documentation
Required SkillsRisk management, security assessment, knowledge of PCI DSSCompliance auditing, documentation, regulatory knowledge
Work EnvironmentSecurity teams, risk management departmentsCompliance teams, audit departments

While both roles involve PCI DSS standards, the Pci Dss Risk Assessment focuses on identifying and evaluating security risks, whereas the Pci Dss Compliance Analyst concentrates on maintaining compliance and preparing for audits. Understanding these differences helps organizations assign the right responsibilities to ensure security and compliance.

What job categories do people searching Pci Dss Risk Assessment jobs in Timonium, MD look for?

The top searched job categories for Pci Dss Risk Assessment jobs in Timonium, MD are:

What cities near Timonium, MD are hiring for Pci Dss Risk Assessment jobs?

Cities near Timonium, MD with the most Pci Dss Risk Assessment job openings:

Infographic showing various Pci Dss Risk Assessment job openings in Timonium, MD as of August 2026, with employment types broken down into 1% As Needed, 86% Full Time, 11% Part Time, and 2% Contract. Highlights an 84% Physical, 5% Hybrid, and 11% Remote job distribution, with an average salary of $60,631 per year, or $29.1 per hour.

Senior Director, Identity, Cybersecurity Governance & Risk

Sunbelt Beverage Company, LLC

Linthicum, MD โ€ข On-site

$180 - $200/hr

Other

Posted 18 hours ago

Posted today


Job description

Time Type: Full time Remote Type: Job Family Group: Information Technology

Job Description Summary

The Senior Director Identity, Cybersecurity Governance & Risk is a senior cybersecurity leader responsible for enterprise Identity and Access Management (IAM), cybersecurity governance, cyber risk management, third-party risk management, compliance, and security performance measurement. This role owns strategy, implementation, operations, and continuous improvement of IAM capabilities while establishing the governance, policies, controls, risk processes, and metrics required to manage cybersecurity risk effectively across the enterprise. The position partners closely with the IT Vendor Management Function, Enterprise Architecture, Audit, Legal, Compliance, Human Resources, Operations, IT functions, and business leadership. The successful candidate will combine strategic leadership, security program management, technical credibility, operational discipline, and the ability to communicate cybersecurity risk in clear business terms.

Job ResponsibilitiesIdentity and Access Management (IAM)
  • Define and execute a multi-year IAM strategy, roadmap, architecture, operating model, and governance framework that aligns with business priorities, improved operational efficiencies, and technology transformation initiatives.
  • Oversee implementation and ongoing operations of IAM capabilities including IGA, IVIP, SSO, MFA, PAM, access provisioning, recertification, and identity lifecycle management.
  • Establish enterprise standards for authentication, authorization, least privilege, role-based access, privileged access, and joiner/mover/leaver processes.
  • Drive automation and modernization of access administration to improve security, user experience, and operational efficiency.
  • Oversee IAM imitative performance, service levels, application onboarding, policy exceptions, and remediation of excessive, dormant, orphaned, or inappropriate access.
  • Manage IAM technology vendors, implementation partners, and managed service providers.
Cybersecurity Governance, Risk Management & Executive Reporting
  • Establish and maintain the enterprise cybersecurity governance and risk management framework.
  • Develop and maintain cybersecurity policies, standards, control requirements, exception processes, and accountability models.
  • Partner with Enterprise Risk Management and executive leadership to align cybersecurity risk with enterprise risk appetite and tolerance.
  • Maintain the cybersecurity risk register and ensure risks have clear owners, supported remediation plans, and appropriate executive visibility.
  • Lead cybersecurity risk assessments across applications, infrastructure, cloud services, business processes, and major technology initiatives.
  • Translate technical risk into business impact, including financial, operational, regulatory, reputational, and business partner considerations.
  • Establish processes for risk treatment, residual risk assessment, formal risk acceptance, and escalation.
  • Establish a cybersecurity measurement framework focused on risk reduction, control effectiveness, operational performance, and program maturity.
  • Define KPIs, KRIs, service metrics, thresholds, and escalation criteria.
  • Develop executive dashboards and Board reporting on cybersecurity risks, trends, program performance, and priorities.
  • Use trend analysis and leading indicators to identify deteriorating performance or emerging risks.
  • Benchmark cybersecurity maturity and performance against industry standards and peer organizations.
Third-Party Cybersecurity Risk Management
  • Lead the cybersecurity component of the organizationโ€™s third-party risk management program.
  • Establish risk-based due diligence and assessment requirements based on vendor criticality, platform tiering, data classifications, connectivity, and business impact.
  • Oversee cybersecurity reviews during vendor selection, contracting, onboarding, periodic reassessment, renewal, and termination.
  • Partner with IT Vendor Management and Legal to establish appropriate cybersecurity contractual requirements.
  • Ensure significant vendor risks have documented remediation plans, compensating controls, or formally approved risk acceptance.
  • Provide enhanced oversight of critical and high-risk vendors and report significant third-party risks to leadership.
Cybersecurity Compliance & Controls
  • Establish and maintain a cybersecurity control framework supporting the organizational culture and strategic direction, that aligns with applicable standards and regulatory requirements, including frameworks such as NIST CSF, NIST 800-53, ISO 27001/27002, ISO 31000, ISO 27090, CMMC, CIS Controls, SOC 2, and PCI DSS where applicable.
  • Translate cybersecurity standards and regulatory requirements into practical enterprise policies, controls, and evidence requirements.
  • Oversee cybersecurity control assessments, maturity evaluations, audit support, and remediation activities.
  • Partner with Audit, Compliance, Legal, and external assessors during audits, and security reviews.
  • Monitor evolving cybersecurity standards and requirements and assess their impact on the organization.
Strategy, Leadership & Program Execution
  • Develop multi-year strategies and annual operating plans across IAM, governance, risk, compliance, and third-party risk management functions.
  • Translate cybersecurity strategy into prioritized programs, investments, roadmaps, and measurable outcomes.
  • Build business cases for cybersecurity investments and communicate expected risk-reduction and business benefits.
  • Serve as a trusted cybersecurity advisor to the CISO, CIO, executive leadership, and business stakeholders.
  • Represent cybersecurity in major enterprise technology and business transformation initiatives.
  • Other duties, as assigned by the jobholderโ€™s supervisor, may also be required.
Minimum Qualifications
  • Bachelorโ€™s degree in Cybersecurity, Information Technology, Computer Science, Risk Management, or related discipline, or equivalent professional experience.
  • 10+ years of progressive experience in cybersecurity, information security, technology risk, and related disciplines.
  • Significant leadership experience directing enterprise cybersecurity programs in a complex organization.
  • Demonstrated experience developing and executing enterprise cybersecurity strategies, platform implementations, and transformation programs.
  • Strong knowledge of identity governance, authentication, privileged access, access lifecycle management, and modern identity architectures.
  • Demonstrated expertise in cybersecurity governance, risk management, third-party risk, compliance, and control frameworks.
  • Experience with standards such as NIST CSF, NIST 800-53, ISO 27001/27002, CIS Controls, CMMC, SOC 2, or comparable frameworks.
  • Experience supporting audits, compliance assessments, and executive risk reporting.
  • Demonstrated ability to develop meaningful cybersecurity KPIs, KRIs, dashboards, and performance reporting.
  • Strong executive communication and stakeholder-management skills.
  • Experience managing cybersecurity budgets, vendors, consulting partners, and large-scale cross-functional initiatives.
  • Two or more professional certifications such as CISSP, CISM, CISA, or CGEIT.
  • Strong analytical and problem-solving skills, with the ability to diagnose and resolve complex issues across highly distributed environments.
  • Excellent prioritization, organizational, and decision-making skills.
  • Strategic thinking, conceptual problem-solving, and adaptability.
Physical Requirements

While performing the duties of this job, the employee is required to remain in a stationary position at times; communicate, and operate a computer and telephone. Competencies: People management responsibility for pay reviews, performance management, training, and resource planning. Requires conceptual thinking to understand complex issues and their implications, where sufficient information may not be available.

This job description is only a summary of the typical functions of this position, not an exhaustive or comprehensive list of all possible job responsibilities, tasks and duties. Responsibilities, tasks, and duties of individual jobholders may vary from the above description.

Compensation Range: $180, 000 to $200,000 Corporate Bonus: 30% - -

Breakthru Beverage Group is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, genetic information and other legally protected characteristics. The EEO is the Law poster is available here. If you need a reasonable accommodation because of a disability for any part of the employment process, please call (708) 298-3536 and let us know the nature of your request and your contact information.

Weโ€™re driven to be the industry leader in every way, including how we treat our associates. Which is why weโ€™ve built a peopleโ€‘centric, relationshipโ€‘driven culture designed to maximize career advancement, a sense of belonging, and wellness. Focused on enhancing every aspect and phase of your career, the Breakthru experience includes our commitment to your growth, belonging, and wellness. Breakthru Beverage is a familyโ€‘owned and operated company with operations across the U.S. and Canada, and more than $8 billion in annual sales driven by a team of 10,000 associates. We deliver worldโ€‘renowned brands to the doorsteps of North Americaโ€™s retail, bar and restaurant businesses.

#J-18808-Ljbffr