1

Pci Qsa Jobs (NOW HIRING)

IT Security and Governance Analyst

Louisville, KY · On-site

$43.25 - $57.50/hr

Preferred : • Bachelor's degree within a related area of study. • Information security related training or certifications such as CISA, CRISC, PCI QSA. • Experience working with GRC platforms ...

Senior PCI Analyst

$98K - $128K/yr

At least one relevant certification (e.g., PCIP, QSA, CISSP, ISA) is required. What would be nice ... Excellent understanding of PCI DSS requirements and security frameworks (e.g., PCI DSS 4.0.1, NIST ...

Security certification such as CISSP, CISM, or PCI QSA * MySQL tuning * Server clustering * Significant experience with unit testing Benefits * 18 days PTO * 8 sick days * 12 holidays * Competitive ...

$41.75 - $55.75/hr

Information security related training or certifications such as CISA, CRISC, PCI QSA. Experience working with GRC platforms and tools. Familiarity with third-party risk management and vendor ...

Showing results 21-40

Pci Qsa information

See salary details

$14

$19

$24

How much do pci qsa jobs pay per hour?

As of Aug 16, 2026, the average hourly pay for pci qsa in the United States is $19.97, according to ZipRecruiter salary data. Most workers in this role earn between $18.27 and $21.15 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in the PCI QSA position, and why are they important?

To thrive as a PCI QSA (Payment Card Industry Qualified Security Assessor), you need a strong background in information security, auditing, and compliance, often supported by a relevant degree and industry certifications such as CISSP or CISA. Familiarity with payment processing systems, PCI DSS standards, audit tools, and reporting platforms is vital for performing assessments and maintaining documentation. Exceptional communication, analytical thinking, and client management skills help you interpret requirements and effectively guide organizations through compliance processes. These competencies ensure accurate, trustworthy assessments that help organizations secure payment card data and comply with legal and industry regulations.

What does a PCI QSA do?

A PCI QSA (Payment Card Industry Qualified Security Assessor) is a security professional authorized to assess and validate an organization's compliance with PCI Data Security Standard (PCI DSS) requirements. They conduct security audits, review policies, and test systems to ensure cardholder data protection, often using specialized tools and frameworks. Their work helps organizations maintain secure payment environments and meet industry compliance standards.

What are the main challenges PCI QSAs face when conducting PCI DSS assessments?

PCI QSAs often encounter challenges such as interpreting complex or evolving PCI DSS requirements, navigating diverse technical environments, and ensuring consistent documentation across various organizations. Working closely with different client teams, they must balance strict compliance needs with practical business realities, sometimes requiring travel or remote collaboration. Staying current with regulatory updates and technological advancements is also important as standards and threats change. Successful PCI QSAs are proactive problem solvers who communicate clearly, ensuring that clients not only achieve compliance but also improve their overall security posture.

What is a PCI QSA?

A PCI QSA (Qualified Security Assessor) is a professional certified by the PCI Security Standards Council to assess and validate an organization's compliance with the Payment Card Industry Data Security Standard (PCI DSS). QSAs conduct security audits, evaluate IT systems and controls, and provide guidance on achieving and maintaining PCI DSS compliance. They work with merchants, service providers, and financial institutions to identify security risks and ensure cardholder data protection. Their role involves conducting on-site assessments, preparing reports, and offering recommendations to enhance security posture.

How much does a PCI QSA make?

A PCI QSA (Payment Card Industry Qualified Security Assessor) typically earns between $80,000 and $150,000 annually, depending on experience, certifications, and location. Senior QSAs with extensive expertise and certifications like CISSP or CISA tend to earn higher salaries, often exceeding $150,000.
More about Pci Qsa jobs

What cities are hiring for Pci Qsa jobs?

Cities with the most Pci Qsa job openings:

What states have the most Pci Qsa jobs?

States with the most job openings for Pci Qsa jobs include:

Infographic showing various Pci Qsa job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 5% Part Time, and 10% Contract. Highlights an 84% Physical, 6% Hybrid, and 10% Remote job distribution, with an average salary of $41,534 per year, or $20 per hour.

PCI DSS SAQ D Service Provider Lead

FYI For Your Information Inc

Silver Spring, MD • Remote

Full-time

Retirement

Re-posted 28 days ago


Job description

FYI - For Your Information, Inc. is an SBA certified, Woman-Owned Small Business and GSA schedule holder that is a premier provider of Human Capital, Training, and Information Technology services. We have won awards for being a Great Place to Work and continue to make ground-breaking advancements. For four years in a row, we have been on Inc. Magazine's 5000 list and were recently named one of Inc.'s 2024 Mid-Atlantic Fastest Growing companies. About the roleFYI is seeking a PCI DSS SAQ D Service Provider Lead to support an active PCI compliance program for a SaaS/cloud/payment-adjacent environment. This role will own the PCI domain in a fractional capacity, including PCI scoping support, evidence sufficiency review, quarterly scan cadence, penetration testing evidence, remediation tracking, and responses to auditors, QSAs, processors, banks, or other requesting entities. The right candidate has done this work before and can drive their lane without constant prompting.Essential responsibilities and dutiesSupport PCI DSS SAQ D Service Provider readiness, scoping, evidence review, and control interpretation.Review PCI scope assumptions, in-scope systems, applications, integrations, service providers, and payment/data-flow considerations.Coordinate and review evidence for quarterly external ASV scans and internal vulnerability scans.Coordinate PCI-relevant penetration testing evidence, including scope, rules of engagement, final report review, remediation, and retest evidence.Review evidence for file integrity monitoring, encryption, MFA, IAM, logging, monitoring, change control, secure development, vulnerability management, and remediation tracking where relevant to PCI DSS.Identify weak, incomplete, stale, unclear, or nonresponsive evidence before submission.Draft or review PCI-related auditor, QSA, processor, or requesting-entity responses.Support tracking of PCI remediation items, exceptions, compensating-control discussions, and risk acceptance needs.Help define and maintain recurring PCI compliance cadence, including quarterly scans and annual validation activities.Provide concise written status updates, blockers, risks, and next actions to the project manager and CISO/vCISO.Required qualifications8+ years of cybersecurity, GRC, IT audit, compliance, security consulting, or related experience.Direct hands-on experience supporting PCI DSS assessments.Direct experience with PCI DSS SAQ D; Service Provider experience is strongly preferred.Experience with SaaS, cloud-hosted, fintech, payment, or payment-adjacent environments.Working knowledge of ASV scanning, internal vulnerability scanning, penetration testing evidence, vulnerability remediation, IAM/MFA, encryption, logging, monitoring, FIM, change control, and secure development requirements.Ability to translate PCI requirements into practical tasks for engineering, IT, security, and business stakeholders.Strong written communication skills and ability to produce audit-ready summaries and responses.Ability to work through ambiguity and distinguish sufficient evidence from weak or incomplete evidence.Nice to havePrior QSA, ISA, or QSA-firm experience.PCI DSS v4.x experience.CISA, CISSP, CISM, Security+, or equivalent certification.Experience with Drata, Vanta, Secureframe, Hyperproof, Jira, Confluence, AWS, Azure, GCP, or similar platforms.SOC 2 familiarity, especially where controls overlap with PCI DSS.Expected deliverablesPCI DSS SAQ D evidence and gap tracker inputs.PCI scope notes, assumptions, and issue summaries.ASV and internal vulnerability scan evidence checklists.Penetration testing evidence checklist and report sufficiency review notes.PCI remediation tracker updates and risk summaries.PCI auditor/requesting-entity response drafts.PCI quarterly and annual compliance calendar inputs.Operating style requiredThis role requires a senior operator who can own the PCI lane in a fractional capacity. The contractor must communicate clearly, document next actions, identify blockers early, and coordinate through the project manager. This is not a casual side task. Responsiveness, ownership, and clean written work product are required.FYI's Benefits/Incentives: What is in it for you?Opportunity to work a hybrid work scheduleA knowledgeable, high-achieving, diverse, experienced, and fun team.The chance to be part of a rapidly growing company and the next success story.A competitive base salary with a loaded benefits package plus 401K.Tuition/education assistance, personal computer allowance, pet insurance.