Drive PCI-DSS audit readiness and coordinate annual assessments with external QSAs and internal ... Strong understanding of risk assessment methodologies and mitigation planning. Experience with ...
Drive PCI-DSS audit readiness and coordinate annual assessments with external QSAs and internal ... Strong understanding of risk assessment methodologies and mitigation planning. Experience with ...
... risk assessment, and third party supplier risk process and requirements Current or previous ... PCI DSS, and cloud services Professional certification in risk management, and/or audit is ...
... risk assessment, and third party supplier risk process and requirements Current or previous ... PCI DSS, and cloud services Professional certification in risk management, and/or audit is ...
IT Compliance Manager
Phoenix, AZ · On-site
... PCI-DSS audit readiness and coordinate annual assessments with external QSAs and internal ... risk assessment methodologies and mitigation planning. • Experience with change management ...
IT Compliance Manager
Phoenix, AZ · On-site
... PCI-DSS audit readiness and coordinate annual assessments with external QSAs and internal ... risk assessment methodologies and mitigation planning. • Experience with change management ...
... PCI-DSS audit readiness and coordinate annual assessments with external QSAs and internal ... risk assessment methodologies and mitigation planning. · Experience with change management ...
... PCI-DSS audit readiness and coordinate annual assessments with external QSAs and internal ... risk assessment methodologies and mitigation planning. · Experience with change management ...
Associate GRC Security Analyst
San Mateo, CA · On-site
$80K - $105K/yr
Previously supported audits pertaining to SOC2 Type 2 and/or PCI-DSS (Level 1 or hands-on SAQs) * Experience with or exposure to vendor risk assessment processes and third-party risk management
Associate GRC Security Analyst
San Mateo, CA · On-site
$80K - $105K/yr
Previously supported audits pertaining to SOC2 Type 2 and/or PCI-DSS (Level 1 or hands-on SAQs) * Experience with or exposure to vendor risk assessment processes and third-party risk management
IT GRC Analyst
Dunwoody, GA · Hybrid
$44.50 - $59.50/hr
PCI ISA collects and reviews evidence of compliance to validate PCI DSS requirements are met ... logging, risk assessments/reviews and information security policy. * Ability to analyze ...
IT GRC Analyst
Dunwoody, GA · Hybrid
$44.50 - $59.50/hr
PCI ISA collects and reviews evidence of compliance to validate PCI DSS requirements are met ... logging, risk assessments/reviews and information security policy. * Ability to analyze ...
Conduct risk assessments using frameworks like NIST and ISO. * Lead and support PCI-DSS assessments for compliance. * Architect and assess security measures for AWS and Azure environments. * Provide ...
Quick apply
Conduct risk assessments using frameworks like NIST and ISO. * Lead and support PCI-DSS assessments for compliance. * Architect and assess security measures for AWS and Azure environments. * Provide ...
IT GRC Analyst
Richardson, TX · Hybrid
$40.75 - $54.50/hr
PCI ISA collects and reviews evidence of compliance to validate PCI DSS requirements are met ... logging, risk assessments/reviews and information security policy. * Ability to analyze ...
IT GRC Analyst
Richardson, TX · Hybrid
$40.75 - $54.50/hr
PCI ISA collects and reviews evidence of compliance to validate PCI DSS requirements are met ... logging, risk assessments/reviews and information security policy. * Ability to analyze ...
Senior Security GRC Analyst (PCI ISA Specialist)
Austin, TX · Hybrid
$88K - $150K/yr
... Assessor (ISA) , you will serve as the primary Subject Matter Expert (SME) for our global PCI DSS ... Targeted Risk Analyses (TRAs) and the customized approach where applicable. * Scoping ...
Senior Security GRC Analyst (PCI ISA Specialist)
Austin, TX · Hybrid
$88K - $150K/yr
... Assessor (ISA) , you will serve as the primary Subject Matter Expert (SME) for our global PCI DSS ... Targeted Risk Analyses (TRAs) and the customized approach where applicable. * Scoping ...
IT GRC Analyst
Bloomington, IL · On-site
$42.75 - $57/hr
PCI ISA collects and reviews evidence of compliance to validate PCI DSS requirements are met ... logging, risk assessments/reviews and information security policy. * Ability to analyze ...
IT GRC Analyst
Bloomington, IL · On-site
$42.75 - $57/hr
PCI ISA collects and reviews evidence of compliance to validate PCI DSS requirements are met ... logging, risk assessments/reviews and information security policy. * Ability to analyze ...
IT GRC Analyst
Tempe, AZ · Hybrid
$43 - $57.50/hr
PCI ISA collects and reviews evidence of compliance to validate PCI DSS requirements are met ... logging, risk assessments/reviews and information security policy. * Ability to analyze ...
IT GRC Analyst
Tempe, AZ · Hybrid
$43 - $57.50/hr
PCI ISA collects and reviews evidence of compliance to validate PCI DSS requirements are met ... logging, risk assessments/reviews and information security policy. * Ability to analyze ...
IT GRC Analyst
Bloomington, IL · Hybrid
$42.75 - $57/hr
PCI ISA collects and reviews evidence of compliance to validate PCI DSS requirements are met ... logging, risk assessments/reviews and information security policy. * Ability to analyze ...
IT GRC Analyst
Bloomington, IL · Hybrid
$42.75 - $57/hr
PCI ISA collects and reviews evidence of compliance to validate PCI DSS requirements are met ... logging, risk assessments/reviews and information security policy. * Ability to analyze ...
Security Architect
OR · Remote
$65 - $84/hr
Conduct regular risk assessments to identify control gaps and ensure technical alignment with SOC2, HITRUST, and PCI DSS requirements. Your Professional Qualifications * Experience: 7+ years of ...
Security Architect
OR · Remote
$65 - $84/hr
Conduct regular risk assessments to identify control gaps and ensure technical alignment with SOC2, HITRUST, and PCI DSS requirements. Your Professional Qualifications * Experience: 7+ years of ...
Sr. Information Security Risk Analyst
Kansas City, MO · On-site +1
$69K - $109K/yr
Support UMB's PCI-DSS compliance and assessment activities while supporting our internal technology ... Strong knowledge of risk and controls, including working knowledge of standards and frameworks such ...
Sr. Information Security Risk Analyst
Kansas City, MO · On-site +1
$69K - $109K/yr
Support UMB's PCI-DSS compliance and assessment activities while supporting our internal technology ... Strong knowledge of risk and controls, including working knowledge of standards and frameworks such ...
Senior Security GRC Analyst (PCI ISA Specialist)
Austin, TX · On-site
$88K - $150K/yr
... Assessor (ISA) , you will serve as the primary Subject Matter Expert (SME) for our global PCI DSS ... Targeted Risk Analyses (TRAs) and the customized approach where applicable. * Scoping ...
Senior Security GRC Analyst (PCI ISA Specialist)
Austin, TX · On-site
$88K - $150K/yr
... Assessor (ISA) , you will serve as the primary Subject Matter Expert (SME) for our global PCI DSS ... Targeted Risk Analyses (TRAs) and the customized approach where applicable. * Scoping ...
Information Security & Compliance Analyst
$100K - $120K/yr
... Risk, and Compliance (GRC) program, with a primary focus on PCI DSS 4.0, SOX/ITGC, and NIST CSF 2.0 ... Support risk assessments across applications, infrastructure, and vendors * Track remediation plans ...
Information Security & Compliance Analyst
$100K - $120K/yr
... Risk, and Compliance (GRC) program, with a primary focus on PCI DSS 4.0, SOX/ITGC, and NIST CSF 2.0 ... Support risk assessments across applications, infrastructure, and vendors * Track remediation plans ...
Sr. Information Security Risk Analyst
Kansas City, MO · On-site
$69K - $109K/yr
Support UMB's PCI-DSS compliance and assessment activities while supporting our internal technology ... Strong knowledge of risk and controls, including working knowledge of standards and frameworks such ...
Sr. Information Security Risk Analyst
Kansas City, MO · On-site
$69K - $109K/yr
Support UMB's PCI-DSS compliance and assessment activities while supporting our internal technology ... Strong knowledge of risk and controls, including working knowledge of standards and frameworks such ...
Information Security & Compliance Analyst
Downers Grove, IL · On-site
$100K - $120K/yr
... Risk, and Compliance (GRC) program, with a primary focus on PCI DSS 4.0, SOX/ITGC, and NIST CSF 2.0 ... Support risk assessments across applications, infrastructure, and vendors * Track remediation plans ...
Information Security & Compliance Analyst
Downers Grove, IL · On-site
$100K - $120K/yr
... Risk, and Compliance (GRC) program, with a primary focus on PCI DSS 4.0, SOX/ITGC, and NIST CSF 2.0 ... Support risk assessments across applications, infrastructure, and vendors * Track remediation plans ...
Project Manager PCI
Seattle, WA · Hybrid
$48.35/hr
... QSA assessment and ongoing compliance. * Apply deep, hands-on PCI DSS expertise to translate ... Experience maintaining well-organized project documentation, decision logs, risk registers ...
Project Manager PCI
Seattle, WA · Hybrid
$48.35/hr
... QSA assessment and ongoing compliance. * Apply deep, hands-on PCI DSS expertise to translate ... Experience maintaining well-organized project documentation, decision logs, risk registers ...
Cybersecurity ServiceNow Application Senior Advisor
Atlanta, GA · On-site
$131K - $131K/yr
... PCI DSS assessment activities, including ROC, SAQ, AOC, gap assessments, evidence collection, control owner attestations, remediation tracking, compensating control documentation, targeted risk ...
Cybersecurity ServiceNow Application Senior Advisor
Atlanta, GA · On-site
$131K - $131K/yr
... PCI DSS assessment activities, including ROC, SAQ, AOC, gap assessments, evidence collection, control owner attestations, remediation tracking, compensating control documentation, targeted risk ...
Pci Dss Risk Assessment information
See salary details
$19.29 is the 25th percentile. Wages below this are outliers.
$14.42 - $19.84
28% of jobs
The median wage is $23.08 / hr.
$19.84 - $25.26
37% of jobs
$25.26 - $30.68
6% of jobs
$34.07 is the 75th percentile. Wages above this are outliers.
$30.68 - $36.10
6% of jobs
$36.10 - $41.52
12% of jobs
$41.52 - $46.94
0% of jobs
$46.94 - $52.36
0% of jobs
$52.36 - $57.78
8% of jobs
$57.78 - $63.20
0% of jobs
$63.20 - $68.62
0% of jobs
$68.62 - $74.04
2% of jobs
$14
$30
$74
How much do pci dss risk assessment jobs pay per hour?
What is a PCI DSS risk assessment?
What are the key skills and qualifications needed to thrive as a PCI DSS Risk Assessor, and why are they important?
What is the difference between Pci Dss Risk Assessment vs Pci Dss Compliance Analyst?
| Aspect | Pci Dss Risk Assessment | Pci Dss Compliance Analyst |
|---|---|---|
| Primary Focus | Identifying and evaluating security risks related to PCI DSS requirements | Ensuring ongoing compliance with PCI DSS standards and policies |
| Responsibilities | Risk identification, vulnerability assessment, mitigation planning | Policy implementation, audit preparation, compliance documentation |
| Required Skills | Risk management, security assessment, knowledge of PCI DSS | Compliance auditing, documentation, regulatory knowledge |
| Work Environment | Security teams, risk management departments | Compliance teams, audit departments |
While both roles involve PCI DSS standards, the Pci Dss Risk Assessment focuses on identifying and evaluating security risks, whereas the Pci Dss Compliance Analyst concentrates on maintaining compliance and preparing for audits. Understanding these differences helps organizations assign the right responsibilities to ensure security and compliance.
What are some common challenges faced during PCI DSS risk assessments, and how can they be addressed?

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 17 days ago
Sprouts Farmers Market rating
6.8
Based on 795 frontline employees who took The Breakroom Quiz
22nd of 114 rated grocery stores
Job description
Please note this position is based in our Phoenix, AZ Support Office. The IT Compliance Manager is responsible for ensuring Sprouts' IT systems, policies, and processes adhere to applicable legal, regulatory, and industry standards. This role owns IT compliance frameworks including PCI DSS, NIST CSF, and SOX, regulatory adherence, and continuous improvement across the organization. The ideal candidate is self-directed, takes initiative to identify and resolve inefficiencies, and operates with confidence and accountability. This role serves as a cybersecurity culture champion, helping cultivate an empowered security culture where security awareness is integrated into the fabric of the organization and each team member is equipped to protect information assets.
Essential FunctionsTeam Leadership
May lead/mentor compliance analysts.
Assign and prioritize workload across compliance initiatives, audits, and remediation efforts.
Conduct performance evaluations and support professional growth and certification goals.
Accountable for prioritization of compliance activities and delivery of audit milestones.
SOX Compliance (ITGC / IT-Dependent Controls)
Own and continuously refine SOX IT control design, documentation, and operating cadence, including control narratives, evidence expectations, and control owner alignment.
Coordinate SOX audit evidence collection, perform quality review, and provide gap analysis and status reporting to stakeholders.
Drive deficiency and remediation management, including action plan tracking, validation of corrective actions, and audit readiness.
Proactively identify and resolve process inefficiencies in evidence collection and audit workflows.
Deliver SOX evidence packages on time with minimal rework.
PCI-DSS Compliance
Coordinate PCI-DSS compliance activities including audit preparedness, evidence management, and cross-functional alignment to maintain PCI-DSS posture.
Maintain PCI-DSS program documentation (policies, standards, and procedures as applicable) and track compliance requirements across IT and security control owners.
Drive PCI-DSS audit readiness and coordinate annual assessments with external QSAs and internal stakeholders.
Policy Maintenance, Lifecycle, and Enforcement
Own the information security policy lifecycle (draft, review, approval, publish, attestation, and exception handling) and ensure policies are maintained, communicated, and measurable.
Coordinate policy enforcement mechanisms with technical owners (standards, baselines, procedural controls, and compliance reporting) and maintain audit-ready documentation.
Security Awareness and Phishing Simulation Program Ownership
Own enterprise security awareness program strategy, annual plan, and compliance tracking, including completion rates, effectiveness measurement, targeted campaigns, and culture alignment.
Own the phishing simulation and testing program, including scenario design cadence, targeting strategy, results reporting, and continuous improvement actions.
Audit and Compliance Program Operations
Coordinate internal and external audits and assessments (SOX, PCI-DSS, NIST-aligned assessments, penetration tests, and targeted control audits), including evidence management and stakeholder coordination.
Build and maintain compliance reporting (dashboards, metrics, KRIs/KPIs, issue tracking) to provide transparency into compliance status, risks, and remediation progress.
Provide gap analysis between security policies, standards, regulations, and actual practices, processes, and solutions. Recommend actions to management and track remediation.
Partner with IT and business partners to prioritize and drive process improvements that remediate or mitigate control gaps and compliance findings.
Change Governance / CAB
Coordinate weekly CAB meetings and drive Change Control processes to ensure SOX and security control requirements are met, including documentation, evidence, and audit alignment with existing change control policy.
Incident Response Support
Support incident response by advising on compliance and control impact, evidence retention, and audit trail requirements, in partnership with Security Operations.
Knowledge, Skills, Abilities and Physical RequirementsFour-year degree or equivalent experience in a related field (e.g., Information Technology, Computer Science, Management Information Systems, or equivalent industry experience).
5+ years of experience in IT compliance, IT audit, or information security, with at least 1-2 years in a supervisory or lead capacity.
Demonstrated working knowledge of PCI DSS, NIST CSF, and SOX requirements.
Hands-on experience with SOX ITGC testing, evidence coordination, and deficiency management.
Experience developing and maintaining IT policies and procedures.
Strong understanding of risk assessment methodologies and mitigation planning.
Experience with change management processes and CAB governance.
Demonstrated ability to work independently, make confident decisions, and drive improvements without constant direction.
Preferred
- Relevant certifications such as CISA or CRISC.
Experience in the retail or grocery industry.
Experience with ServiceNow and KnowBe4.
Experience managing security awareness and phishing simulation platforms.
Familiarity with GRC (Governance, Risk, and Compliance) platforms.
Experience working with Big 4 or external audit firms, including coordinating walkthroughs and evidence requests.
Competencies
Communication: Convey information, ideas, and feedback clearly and concisely in an engaging manner that helps others understand and retain the message; listening actively to others.
Customer Focus: Place a high priority on the customer's perspective when making decisions and taking action; implementing service practices that meet the customers' and own organization's needs.
Driving for Results: Set SMART goals and measure progress; tenaciously working to meet or exceed goals and making continuous improvement. Seeking innovative ways to solve problems that result in unique and differentiated solutions.
Positive Approach: Demonstrate a positive attitude in the face of difficult or challenging situations; provide an uplifting (yet realistic) outlook on what the future holds and the opportunities it might present.
Coaching and Developing Others: Engaging team members and teams in developing and committing to individual development plans that target specific behaviors, skills, or knowledge needed to ensure performance improvement or prepare for success in new responsibilities; planning and supporting the development of individual skills and abilities.
#LI-NA1
BenefitsIn addition to a rewarding career, Sprouts offers a comprehensive program to help support you and your family. These programs include:
- Competitive pay
- Sick time plan that you can use to support you or your immediate families health
- Vacation accrual plan
- Opportunities for career growth
- 15% discount for you and one other family member in your household on all purchases made at Sprouts
- Flexible schedules
- Employee Assistance Program (EAP)
- 401(K) Retirement savings plan with a generous company match
- Company paid life insurance
- Contests and appreciation events throughout the year full of prizes, food and fun!
Eligibility requirements may apply for the following benefits:
- Bonus based on company and/or individual performance
- Affordable benefit coverage, including medical, dental and vision
- Health Savings Account with company match
- Pre-tax Flexible Spending Accounts for healthcare and dependent care
- Company paid short-term disability coverage
- Paid parental leave for both mothers and fathers
- Paid holidays
Get Paid Every Day!
Sprouts Farmers Market offers DailyPay - if you're hired as an eligible employee, you'll be able to transfer the money you've already earned at no extra cost, and get it the next business day, for free. We offer DailyPay so you don't have to wait for payday to access the money you've already worked for. With DailyPay, you can see how much you've made every day and you can transfer your money any time before payday.
You can learn more by visiting https://www.dailypay.com/partners/sprouts-farmers-market/.
Why SproutsGrow with us!
If you have a passion for inspiring people and a flair for fresh food, consider applying for a job at Sprouts! With a focus on customer service, our neighborhood grocery stores offer high-quality, farm fresh produce, natural meats, plenty of scoop-your-own bulk goods and much more in a fun, friendly, old-fashioned farmer's market setting. Come grow your career in healthy living with a fast-paced, rapidly growing company and teams that pride themselves on empowering others along their journey.
The above statements are intended to describe the general nature and level of the work being performed by people assigned to this work. This is not an exhaustive list of all duties, responsibilities, and requirements. Sprouts' management reserves the right to amend and change duties, responsibilities, and requirements to meet business and organizational needs as necessary.
Sprouts will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the Fair Chance in Hiring Ordinance.
California Residents: We collect information in accordance with California law, please see here for more information.
Employment Type: FULL_TIMEWhat Sprouts Farmers Market employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Sprouts
Sourced by ZipRecruiter
Industry
Retail
Company size
10,000+ Employees
Headquarters location
Phoenix, AZ, US
Year founded
2002