1

Pci Isa Jobs (NOW HIRING)

PCI ISA ABOUT WAYSTAR Through a smart platform and better experience, Waystar helps providers simplify healthcare payments and yield powerful results throughout the complete revenue cycle. Waystar ...

PCI DSS Internal Controls, Senior Manager

Chicago, IL · On-site

$87K - $108K/yr

The PCI DSS Internal Controls Senior Manager plays a key role in the continued development ... Knowledge of one of the following areas isa must: computer networking, network security practices ...

Cybersecurity Senior

Houston, TX

$95K - $123K/yr

Industry certifications such as Security+, CySA+, CISSP, CISA, CRISC, PCI ISA, or similar are a plus. Work Quality: * Consistently produces work of the utmost quality Supervisory responsibilities

Cybersecurity Senior

Maplewood, MO

$93K - $120K/yr

Industry certifications such as Security+, CySA+, CISSP, CISA, CRISC, PCI ISA, or similar are a plus. Work Quality: * Consistently produces work of the utmost quality Supervisory responsibilities

Cybersecurity Senior

Saint Louis, MO · On-site

$97K - $125K/yr

Industry certifications such as Security+, CySA+, CISSP, CISA, CRISC, PCI ISA, or similar are a plus. Work Quality: * Consistently produces work of the utmost quality Supervisory responsibilities

Showing results 21-40

Pci Isa information

See salary details

$20

$22

$23

How much do pci isa jobs pay per hour?

As of Aug 17, 2026, the average hourly pay for pci isa in the United States is $22.28, according to ZipRecruiter salary data. Most workers in this role earn between $21.88 and $22.84 per hour, depending on experience, location, and employer.

What is a PCI ISA?

PCI ISAs, or Payment Card Industry Internal Security Assessors, are professionals certified by the PCI Security Standards Council to assess and validate an organization's compliance with PCI Data Security Standards (PCI DSS) from within the organization. Unlike external Qualified Security Assessors (QSAs), ISAs are employees of the organization they assess and help maintain ongoing PCI DSS compliance. They play a critical role in strengthening security practices, preparing for assessments, and acting as a liaison between internal teams and external auditors.

What are the key skills and qualifications needed to thrive as a PCI ISA, and why are they important?

To thrive as a PCI ISA, you need strong knowledge of information security principles, PCI DSS requirements, and related compliance frameworks, usually backed by relevant experience and an official PCI ISA certification. Familiarity with security assessment tools, compliance management systems, and reporting software is vital for effectively identifying and addressing vulnerabilities. Attention to detail, strong analytical thinking, and clear communication are essential soft skills for interpreting standards and collaborating with internal stakeholders. These competencies ensure accurate self-assessments, ongoing PCI DSS compliance, and protection of sensitive payment card data within the organization.

What are some common challenges faced by PCI ISA professionals when ensuring ongoing compliance within an organization?

PCI ISA professionals often encounter challenges such as keeping up with evolving PCI DSS standards, ensuring all departments adhere to security protocols, and managing regular assessments across complex IT environments. They must coordinate with multiple teams—including IT, compliance, and business units—to address vulnerabilities and implement corrective actions promptly. Staying organized and maintaining clear documentation are key, as the role requires balancing day-to-day operations with long-term compliance initiatives.

What is the difference between Pci Isa vs Pci Technician?

AspectPci IsaPci Technician
CertificationsTypically requires Pci-specific certifications and technical trainingRequires Pci certifications, technical skills, and possibly vendor-specific training
Work EnvironmentPrimarily in data centers, server rooms, or IT departmentsIn data centers, network operations, or IT support settings
Employer & IndustryUsed by companies managing Pci infrastructure and complianceEmployers in IT, telecommunications, and data management sectors

Both Pci Isa and Pci Technician roles involve working with Pci systems and require similar certifications. However, Pci Isa often refers to a specialized role focusing on Pci infrastructure setup, while Pci Technician emphasizes hands-on maintenance and troubleshooting. Both roles are vital in IT environments managing Pci hardware and compliance.

More about Pci Isa jobs

What states have the most Pci Isa jobs?

States with the most job openings for Pci Isa jobs include:

Infographic showing various Pci Isa job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 5% Part Time, and 10% Contract. Highlights an 84% Physical, 6% Hybrid, and 10% Remote job distribution, with an average salary of $46,343 per year, or $22.3 per hour.

PCI DSS SAQ D Service Provider Lead

FYI For Your Information Inc

Silver Spring, MD • Remote

Full-time

Retirement

Re-posted 4 hours ago


Job description

FYI - For Your Information, Inc. is an SBA certified, Woman-Owned Small Business and GSA schedule holder that is a premier provider of Human Capital, Training, and Information Technology services. We have won awards for being a Great Place to Work and continue to make ground-breaking advancements. For four years in a row, we have been on Inc. Magazine's 5000 list and were recently named one of Inc.'s 2024 Mid-Atlantic Fastest Growing companies. About the roleFYI is seeking a PCI DSS SAQ D Service Provider Lead to support an active PCI compliance program for a SaaS/cloud/payment-adjacent environment. This role will own the PCI domain in a fractional capacity, including PCI scoping support, evidence sufficiency review, quarterly scan cadence, penetration testing evidence, remediation tracking, and responses to auditors, QSAs, processors, banks, or other requesting entities. The right candidate has done this work before and can drive their lane without constant prompting.Essential responsibilities and dutiesSupport PCI DSS SAQ D Service Provider readiness, scoping, evidence review, and control interpretation.Review PCI scope assumptions, in-scope systems, applications, integrations, service providers, and payment/data-flow considerations.Coordinate and review evidence for quarterly external ASV scans and internal vulnerability scans.Coordinate PCI-relevant penetration testing evidence, including scope, rules of engagement, final report review, remediation, and retest evidence.Review evidence for file integrity monitoring, encryption, MFA, IAM, logging, monitoring, change control, secure development, vulnerability management, and remediation tracking where relevant to PCI DSS.Identify weak, incomplete, stale, unclear, or nonresponsive evidence before submission.Draft or review PCI-related auditor, QSA, processor, or requesting-entity responses.Support tracking of PCI remediation items, exceptions, compensating-control discussions, and risk acceptance needs.Help define and maintain recurring PCI compliance cadence, including quarterly scans and annual validation activities.Provide concise written status updates, blockers, risks, and next actions to the project manager and CISO/vCISO.Required qualifications8+ years of cybersecurity, GRC, IT audit, compliance, security consulting, or related experience.Direct hands-on experience supporting PCI DSS assessments.Direct experience with PCI DSS SAQ D; Service Provider experience is strongly preferred.Experience with SaaS, cloud-hosted, fintech, payment, or payment-adjacent environments.Working knowledge of ASV scanning, internal vulnerability scanning, penetration testing evidence, vulnerability remediation, IAM/MFA, encryption, logging, monitoring, FIM, change control, and secure development requirements.Ability to translate PCI requirements into practical tasks for engineering, IT, security, and business stakeholders.Strong written communication skills and ability to produce audit-ready summaries and responses.Ability to work through ambiguity and distinguish sufficient evidence from weak or incomplete evidence.Nice to havePrior QSA, ISA, or QSA-firm experience.PCI DSS v4.x experience.CISA, CISSP, CISM, Security+, or equivalent certification.Experience with Drata, Vanta, Secureframe, Hyperproof, Jira, Confluence, AWS, Azure, GCP, or similar platforms.SOC 2 familiarity, especially where controls overlap with PCI DSS.Expected deliverablesPCI DSS SAQ D evidence and gap tracker inputs.PCI scope notes, assumptions, and issue summaries.ASV and internal vulnerability scan evidence checklists.Penetration testing evidence checklist and report sufficiency review notes.PCI remediation tracker updates and risk summaries.PCI auditor/requesting-entity response drafts.PCI quarterly and annual compliance calendar inputs.Operating style requiredThis role requires a senior operator who can own the PCI lane in a fractional capacity. The contractor must communicate clearly, document next actions, identify blockers early, and coordinate through the project manager. This is not a casual side task. Responsiveness, ownership, and clean written work product are required.FYI's Benefits/Incentives: What is in it for you?Opportunity to work a hybrid work scheduleA knowledgeable, high-achieving, diverse, experienced, and fun team.The chance to be part of a rapidly growing company and the next success story.A competitive base salary with a loaded benefits package plus 401K.Tuition/education assistance, personal computer allowance, pet insurance.