1

Pci Qsa Jobs (NOW HIRING)

Senior Cybersecurity Analyst

Washington, DC · Remote

$113K - $146K/yr

CISSP, CISA, PMP, and/or CySA+ certifications PCI QSA certification a plus Cloud Certifications of Note: CCSP (ISC2), CCSK or CCAK (CSA), AWS Cloud Practitioner, MS Azure Fundamentals About Aerstone ...

PCI Qualified Security Assessor (QSA) or Internal Security Assessor (ISA) Certified Information Systems Security Professionals (CISSP) Certified Information Security Manager (CISM) Certified ...

Coordinate audits with external assessors (QSA) and internal stakeholders to streamline assessment process related to collecting evidences * Lead the validation of PCI requirements testing results ...

... Assessor (QSA) (for roles specifically focused on PCI DSS compliance). Benefits At TLA , we build solutions that matter-supporting national security missions through technology innovation ...

... Assessor (QSA) (for roles specifically focused on PCI DSS compliance). Benefits At TLA , we build solutions that matter-supporting national security missions through technology innovation ...

... Assessor (QSA) (for roles specifically focused on PCI DSS compliance). Benefits At TLA , we build solutions that matter-supporting national security missions through technology innovation ...

This Position As a Qualified Security Assessor (QSA) you will provide assessments and consulting to ... Data Security Standard (PCI DSS), ISO 27K series, NIST, or other compliance standards and ...

next page

Showing results 1-20

Pci Qsa information

See salary details

$14

$19

$24

How much do pci qsa jobs pay per hour?

As of Jun 12, 2026, the average hourly pay for pci qsa in the United States is $19.97, according to ZipRecruiter salary data. Most workers in this role earn between $18.27 and $21.15 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in the Pci Qsa position, and why are they important?

To thrive as a PCI QSA (Payment Card Industry Qualified Security Assessor), you need a strong background in information security, auditing, and compliance, often supported by a relevant degree and industry certifications such as CISSP or CISA. Familiarity with payment processing systems, PCI DSS standards, audit tools, and reporting platforms is vital for performing assessments and maintaining documentation. Exceptional communication, analytical thinking, and client management skills help you interpret requirements and effectively guide organizations through compliance processes. These competencies ensure accurate, trustworthy assessments that help organizations secure payment card data and comply with legal and industry regulations.

What jobs in the US pay 300,000 a year?

For a PCI QSA (Payment Card Industry Qualified Security Assessor), salaries can reach or exceed $300,000 annually, especially with extensive experience, certifications, and senior roles in cybersecurity consulting firms. High-paying positions often involve leadership, specialized expertise, or management responsibilities within cybersecurity or compliance sectors.

What are the main challenges PCI QSAs face when conducting PCI DSS assessments?

PCI QSAs often encounter challenges such as interpreting complex or evolving PCI DSS requirements, navigating diverse technical environments, and ensuring consistent documentation across various organizations. Working closely with different client teams, they must balance strict compliance needs with practical business realities, sometimes requiring travel or remote collaboration. Staying current with regulatory updates and technological advancements is also important as standards and threats change. Successful PCI QSAs are proactive problem solvers who communicate clearly, ensuring that clients not only achieve compliance but also improve their overall security posture.

What is a PCI QSA job?

A PCI QSA (Qualified Security Assessor) is a professional certified by the PCI Security Standards Council to assess and validate an organization's compliance with the Payment Card Industry Data Security Standard (PCI DSS). QSAs conduct security audits, evaluate IT systems and controls, and provide guidance on achieving and maintaining PCI DSS compliance. They work with merchants, service providers, and financial institutions to identify security risks and ensure cardholder data protection. Their role involves conducting on-site assessments, preparing reports, and offering recommendations to enhance security posture.

What jobs pay $10,000 a month without a degree?

A PCI QSA (Payment Card Industry Qualified Security Assessor) can potentially earn $10,000 or more per month through consulting, audits, and security assessments, especially with extensive experience and certifications like CISSP or CISA. High-paying roles in cybersecurity, sales, or entrepreneurship also exist without requiring a degree, but they often depend on skills, reputation, and performance rather than formal education.

What jobs pay 2000 a day?

High-paying jobs that can pay around $2,000 a day include specialized consulting roles, senior cybersecurity positions such as a PCI QSA (Payment Card Industry Qualified Security Assessor), and certain freelance or contract work in IT, finance, or legal fields. These roles typically require advanced certifications, extensive experience, and often involve project-based or consulting work with high hourly rates or daily fees.

How much does a PCI QSA make?

A PCI QSA (Payment Card Industry Qualified Security Assessor) typically earns between $80,000 and $150,000 annually, depending on experience, certifications, and location. Senior QSAs with extensive expertise can earn higher salaries, especially when working for consulting firms or in high-demand regions.
More about Pci Qsa jobs
What cities are hiring for Pci Qsa jobs? Cities with the most Pci Qsa job openings:
What states have the most Pci Qsa jobs? States with the most job openings for Pci Qsa jobs include:
Senior Cybersecurity Analyst

Senior Cybersecurity Analyst

Aerstone

Washington, DC • Remote

$113K - $146K/yr

Full-time

Posted 24 days ago


Job description

Aerstone seeksa Senior Cybersecurity Analyst to lead independent assessments of customer security controls based on the NIST Risk Management Framework (RMF). Assessed boundaries vary and typically include applications, cloud systems, general support systems, infrastructure, service delivery offerings, and other enterprise information systems.


Quest Consultants LLC DBA Aerstone is a cybersecurity firm based in the D.C area that supports a work-from-home model with team members based anywhere in the United States. The majority of engagements are remote-based and anticipated travel is estimated at less than 20%.


The ideal candidate will have the ability to blend technical, organizational, business, and cyber security skillsets to lead security control assessments. Duties will include:

  • Project planning
  • Coordination with customers and peers
  • Review of system security plans and related documentation
  • Interviewing subject matter experts and other key personnel
  • Performing in-depth risk analysis
  • Reporting


The successful candidate will possess:


  • 7+ years of experience working with security related concepts across different system tiers including applications, operating systems, databases, network infrastructure, and cloud services
  • Experience with risk-based control assessment methodologies, including risk identification (threats sources and threat events), risk analysis (likelihoods and impacts), evaluation, and remediation
  • Excellent writing skills and reporting capabilities.
  • CISSP certified or the ability to work towards obtaining the certification
  • Demonstrated ability to lead multiple projects simultaneously and to work in a highly dynamic, rapidly changing environment
  • Knowledge of threat modeling techniques and methodologies
  • Experience developing assessment reports that effectively and concisely communicate results and risks to a variety of stakeholders
  • Excellent interpersonal, communication (written and verbal), organizational, and analytical skills
  • Excellent consultative skills and the proven ability to work effectively with business partners, internal management and staff, vendors and consultants
  • Proven ability to communicate technical issues to technical and non-technical business partners
  • Experience preparing and leading assessment interviews of highly-technical information systems
  • Strong attention to detail, both in reviewing system documentation and creating reports
  • Experience leading or assisting with security risk assessments or cyber security related initiatives/projects
  • Strong project management skills with experience managing a portfolio of engagements
  • Demonstrated ability to serve as risk assessment subject matter expert (SME)

Preferred skills and knowledge:

  • 7+ years of experience in the security aspects of multiple platforms, operating systems, software, communications, and network protocols
  • Expert knowledge of NIST SP 800-53 Rev 4 and experience executing assessments against it
  • Subject matter expertise of one or more industry risk management frameworks, such as NIST SP 800-30, NIST SP 800-39, ISO 27005/31000, CMMC, & PCI
  • Familiarity with cloud platforms and the customer shared responsibility model
  • Familiarity with FISMA, FedRAMP, and NIST SP 800-series publications
  • Experience assessing cloud-based information systems
  • Strong technical experience, including reporting and representing findings from technical tests
  • Experience with MS Project or other project management tools

Other tasks may include:

  • Representing the company in formal customer interactions
  • Coordinating with other cybersecurity teams as necessary
  • Performing other duties as assigned

Years of Experience Required: 7+ years

Education Requirements:Bachelor's degree

Clearance Requirements: Ability to gain and maintain an agency public trust clearance. TS clearance a plus.


Desired Certifications:

CISSP, CISA, PMP, and/or CySA+ certifications

PCI QSA certification a plus


Cloud Certifications of Note:

CCSP (ISC2), CCSK or CCAK (CSA), AWS Cloud Practitioner, MS Azure Fundamentals


About Aerstone

Aerstone is a Service-Disabled Veteran-Owned Small Business (SDVOSB) with office locations in Maryland and Northern Virginia. Aerstone provides work from home opportunities, excellent health benefits, and certification & training opportunities for its employees.


EEOC:

Equal Employment Opportunity has been, and will continue to be, a fundamental principle at Aerstone, where employment is based upon personal capabilities and qualifications without discrimination because of race, color, religion, sex, age, national origin, familial status, disability, veteran status, sexual orientation, health/genetic information, or any other protected characteristic as established by law.


In compliance with federal EEOC regulations, the selected employee will work on a cleared contract and therefore be required to hold U.S. citizenship.