Draft or review PCI-related auditor, QSA, processor, or requesting-entity responses.Support ... Required qualifications8+ years of cybersecurity, GRC, IT audit, compliance, security consulting ...
Quick apply
Draft or review PCI-related auditor, QSA, processor, or requesting-entity responses.Support ... Required qualifications8+ years of cybersecurity, GRC, IT audit, compliance, security consulting ...
Quick apply
Draft or review PCI-related auditor, QSA, processor, or requesting-entity responses.Support ... Required qualifications8+ years of cybersecurity, GRC, IT audit, compliance, security consulting ...
Payment Card Industry Qualified Security Assessor (PCI QSA) credential. * Experience providing consulting, assessment, or implementation services associated with federal cyber compliance frameworks ...
Payment Card Industry Qualified Security Assessor (PCI QSA) credential. * Experience providing consulting, assessment, or implementation services associated with federal cyber compliance frameworks ...
... QSA, OSCP, etc.) Factors for Promotion Consideration * Respected by peers and superiors as ... management or consulting and/or risk consulting, including years of service at Schellman
... QSA, OSCP, etc.) Factors for Promotion Consideration * Respected by peers and superiors as ... management or consulting and/or risk consulting, including years of service at Schellman
... consulting experience is considered an advantage Additional Information Certifications (preferred, but not required): PCI Qualified Security Assessor (QSA) or Internal Security Assessor (ISA ...
... consulting experience is considered an advantage Additional Information Certifications (preferred, but not required): PCI Qualified Security Assessor (QSA) or Internal Security Assessor (ISA ...
Atlanta, GA ยท On-site
ISO/IEC 27001 * Experience working in a public accounting, cybersecurity consulting, or ... PCI Qualified Security Assessor (QSA) * Certified CMMC Professional (CCP) * Certified CMMC Assessor ...
Atlanta, GA ยท On-site
ISO/IEC 27001 * Experience working in a public accounting, cybersecurity consulting, or ... PCI Qualified Security Assessor (QSA) * Certified CMMC Professional (CCP) * Certified CMMC Assessor ...
ISO/IEC 27001 * Experience working in a public accounting, cybersecurity consulting, or ... PCI Qualified Security Assessor (QSA) * Certified CMMC Professional (CCP) * Certified CMMC Assessor ...
ISO/IEC 27001 * Experience working in a public accounting, cybersecurity consulting, or ... PCI Qualified Security Assessor (QSA) * Certified CMMC Professional (CCP) * Certified CMMC Assessor ...
Downey, CA ยท On-site
Downey, CA Duration: 6 Months The Consultant will perform the following tasks: 1. Provide security ... Qualified Security Assessor (QSA), Certified Information Systems Auditor (CISA), Certified ...
Downey, CA ยท On-site
Downey, CA Duration: 6 Months The Consultant will perform the following tasks: 1. Provide security ... Qualified Security Assessor (QSA), Certified Information Systems Auditor (CISA), Certified ...
Job Summary : InterSources Inc. is a Small Business Enterprise specializing in IT Consulting, ... โข Current or past QSA or ISA โข CISSP, CEH, CISM, CISA, CRISC (or other top InfoSec ...
Job Summary : InterSources Inc. is a Small Business Enterprise specializing in IT Consulting, ... โข Current or past QSA or ISA โข CISSP, CEH, CISM, CISA, CRISC (or other top InfoSec ...
$98K - $128K/yr
... consultations. * May perform other job duties as assigned. What to Bring: * Minimum of 5 years of experience in a PCI DSS compliance role. * At least one relevant certification (e.g., PCIP, QSA ...
$98K - $128K/yr
... consultations. * May perform other job duties as assigned. What to Bring: * Minimum of 5 years of experience in a PCI DSS compliance role. * At least one relevant certification (e.g., PCIP, QSA ...
$41.75 - $55.75/hr
CURRENT EMPLOYEES, CONSULTANTS, AND AGENCY PARTNERS: If you currently work for Brown-Forman, please ... Information security related training or certifications such as CISA, CRISC, PCI QSA. Experience ...
$41.75 - $55.75/hr
CURRENT EMPLOYEES, CONSULTANTS, AND AGENCY PARTNERS: If you currently work for Brown-Forman, please ... Information security related training or certifications such as CISA, CRISC, PCI QSA. Experience ...
$98K - $128K/yr
... consultations. * May perform other job duties as assigned. What to Bring: * Minimum of 5 years of experience in a PCI DSS compliance role. * At least one relevant certification (e.g., PCIP, QSA ...
$98K - $128K/yr
... consultations. * May perform other job duties as assigned. What to Bring: * Minimum of 5 years of experience in a PCI DSS compliance role. * At least one relevant certification (e.g., PCIP, QSA ...
Chicago, IL ยท On-site
$114K - $154K/yr
This group includes experienced consultants located throughout the country dedicated to helping ... Assessor (QSA), or similar credentials * Direct experience with typical cybersecurity program ...
Chicago, IL ยท On-site
$114K - $154K/yr
This group includes experienced consultants located throughout the country dedicated to helping ... Assessor (QSA), or similar credentials * Direct experience with typical cybersecurity program ...
Blue Bell, PA ยท On-site
$106K - $143K/yr
This group includes experienced consultants located throughout the country dedicated to helping ... Assessor (QSA), or similar credentials * Direct experience with typical cybersecurity program ...
Blue Bell, PA ยท On-site
$106K - $143K/yr
This group includes experienced consultants located throughout the country dedicated to helping ... Assessor (QSA), or similar credentials * Direct experience with typical cybersecurity program ...
Philadelphia, PA ยท On-site
$112K - $151K/yr
This group includes experienced consultants located throughout the country dedicated to helping ... Assessor (QSA), or similar credentials * Direct experience with typical cybersecurity program ...
Philadelphia, PA ยท On-site
$112K - $151K/yr
This group includes experienced consultants located throughout the country dedicated to helping ... Assessor (QSA), or similar credentials * Direct experience with typical cybersecurity program ...
Charlotte, NC ยท On-site
$108K - $146K/yr
This group includes experienced consultants located throughout the country dedicated to helping ... Assessor (QSA), or similar credentials * Direct experience with typical cybersecurity program ...
Charlotte, NC ยท On-site
$108K - $146K/yr
This group includes experienced consultants located throughout the country dedicated to helping ... Assessor (QSA), or similar credentials * Direct experience with typical cybersecurity program ...
Charlotte, NC ยท On-site
$108K - $146K/yr
This group includes experienced consultants located throughout the country dedicated to helping ... Assessor (QSA), or similar credentials * Direct experience with typical cybersecurity program ...
Charlotte, NC ยท On-site
$108K - $146K/yr
This group includes experienced consultants located throughout the country dedicated to helping ... Assessor (QSA), or similar credentials * Direct experience with typical cybersecurity program ...
Chicago, IL ยท On-site
$81K - $125K/yr
... and consulting services for multiple clients in data and tech-based industries such as credit ... CISA, CRISC, CIPP, CISSP, CISM, QSA, ISO/IEC 27001, or PCI ISA. * Undergraduate Degree (required ...
Chicago, IL ยท On-site
$81K - $125K/yr
... and consulting services for multiple clients in data and tech-based industries such as credit ... CISA, CRISC, CIPP, CISSP, CISM, QSA, ISO/IEC 27001, or PCI ISA. * Undergraduate Degree (required ...
Lehi, UT ยท On-site +1
$88K - $88K/yr
You will support the organization's cybersecurity, compliance, and consulting practice in ... PCI QSA Certification * Knowledge of HIPAA, HITRUST, ISO 27001, NIST, PCI DSS, or SSAE SOC ...
Lehi, UT ยท On-site +1
$88K - $88K/yr
You will support the organization's cybersecurity, compliance, and consulting practice in ... PCI QSA Certification * Knowledge of HIPAA, HITRUST, ISO 27001, NIST, PCI DSS, or SSAE SOC ...
San Francisco, CA ยท On-site +1
$81K - $125K/yr
... and consulting services for multiple clients in data and tech-based industries such as credit ... CISA, CRISC, CIPP, CISSP, CISM, QSA, ISO/IEC 27001, or PCI ISA. * Undergraduate Degree (required ...
San Francisco, CA ยท On-site +1
$81K - $125K/yr
... and consulting services for multiple clients in data and tech-based industries such as credit ... CISA, CRISC, CIPP, CISSP, CISM, QSA, ISO/IEC 27001, or PCI ISA. * Undergraduate Degree (required ...
San Francisco, CA ยท On-site
$81K - $125K/yr
... and consulting services for multiple clients in data and tech-based industries such as credit ... CISA, CRISC, CIPP, CISSP, CISM, QSA, ISO/IEC 27001, or PCI ISA. * Undergraduate Degree (required ...
San Francisco, CA ยท On-site
$81K - $125K/yr
... and consulting services for multiple clients in data and tech-based industries such as credit ... CISA, CRISC, CIPP, CISSP, CISM, QSA, ISO/IEC 27001, or PCI ISA. * Undergraduate Degree (required ...
$10.10 - $19.97
14% of jobs
$25.74 is the 25th percentile. Wages below this are outliers.
$19.97 - $29.85
19% of jobs
The median wage is $39.73 / hr.
$29.85 - $39.73
17% of jobs
$39.73 - $49.61
16% of jobs
$57.24 is the 75th percentile. Wages above this are outliers.
$49.61 - $59.48
12% of jobs
$59.48 - $69.36
10% of jobs
$69.36 - $79.24
5% of jobs
$79.24 - $89.12
3% of jobs
$89.12 - $98.99
2% of jobs
$98.99 - $108.87
1% of jobs
$108.87 - $118.75
1% of jobs
$10
$49
$118
| Aspect | Qsa Consultant | Penetration Tester |
|---|---|---|
| Certifications | QSA, CISSP, CEH | CISSP, CEH, OSCP |
| Work Environment | Consulting firms, client sites, compliance audits | Security firms, independent, lab environments |
| Industry Usage | Payment Card Industry (PCI), compliance audits | Cybersecurity, vulnerability assessments |
Qsa Consultants primarily focus on PCI compliance assessments, ensuring organizations meet security standards for payment card data. Penetration Testers simulate cyberattacks to identify vulnerabilities. While both roles require security certifications like CEH or CISSP, Qsa Consultants emphasize compliance and audit processes, whereas Penetration Testers focus on technical vulnerability exploitation. Understanding these differences helps organizations choose the right security professional for their needs.
Cities with the most Qsa Consultant job openings:
For Qsa Consultant jobs, the most frequently searched job titles are:

Silver Spring, MD โข Remote
Full-time
Retirement
Re-posted 24 days ago
FYI - For Your Information, Inc. is an SBA certified, Woman-Owned Small Business and GSA schedule holder that is a premier provider of Human Capital, Training, and Information Technology services. We have won awards for being a Great Place to Work and continue to make ground-breaking advancements. For four years in a row, we have been on Inc. Magazine's 5000 list and were recently named one of Inc.'s 2024 Mid-Atlantic Fastest Growing companies. About the roleFYI is seeking a PCI DSS SAQ D Service Provider Lead to support an active PCI compliance program for a SaaS/cloud/payment-adjacent environment. This role will own the PCI domain in a fractional capacity, including PCI scoping support, evidence sufficiency review, quarterly scan cadence, penetration testing evidence, remediation tracking, and responses to auditors, QSAs, processors, banks, or other requesting entities. The right candidate has done this work before and can drive their lane without constant prompting.Essential responsibilities and dutiesSupport PCI DSS SAQ D Service Provider readiness, scoping, evidence review, and control interpretation.Review PCI scope assumptions, in-scope systems, applications, integrations, service providers, and payment/data-flow considerations.Coordinate and review evidence for quarterly external ASV scans and internal vulnerability scans.Coordinate PCI-relevant penetration testing evidence, including scope, rules of engagement, final report review, remediation, and retest evidence.Review evidence for file integrity monitoring, encryption, MFA, IAM, logging, monitoring, change control, secure development, vulnerability management, and remediation tracking where relevant to PCI DSS.Identify weak, incomplete, stale, unclear, or nonresponsive evidence before submission.Draft or review PCI-related auditor, QSA, processor, or requesting-entity responses.Support tracking of PCI remediation items, exceptions, compensating-control discussions, and risk acceptance needs.Help define and maintain recurring PCI compliance cadence, including quarterly scans and annual validation activities.Provide concise written status updates, blockers, risks, and next actions to the project manager and CISO/vCISO.Required qualifications8+ years of cybersecurity, GRC, IT audit, compliance, security consulting, or related experience.Direct hands-on experience supporting PCI DSS assessments.Direct experience with PCI DSS SAQ D; Service Provider experience is strongly preferred.Experience with SaaS, cloud-hosted, fintech, payment, or payment-adjacent environments.Working knowledge of ASV scanning, internal vulnerability scanning, penetration testing evidence, vulnerability remediation, IAM/MFA, encryption, logging, monitoring, FIM, change control, and secure development requirements.Ability to translate PCI requirements into practical tasks for engineering, IT, security, and business stakeholders.Strong written communication skills and ability to produce audit-ready summaries and responses.Ability to work through ambiguity and distinguish sufficient evidence from weak or incomplete evidence.Nice to havePrior QSA, ISA, or QSA-firm experience.PCI DSS v4.x experience.CISA, CISSP, CISM, Security+, or equivalent certification.Experience with Drata, Vanta, Secureframe, Hyperproof, Jira, Confluence, AWS, Azure, GCP, or similar platforms.SOC 2 familiarity, especially where controls overlap with PCI DSS.Expected deliverablesPCI DSS SAQ D evidence and gap tracker inputs.PCI scope notes, assumptions, and issue summaries.ASV and internal vulnerability scan evidence checklists.Penetration testing evidence checklist and report sufficiency review notes.PCI remediation tracker updates and risk summaries.PCI auditor/requesting-entity response drafts.PCI quarterly and annual compliance calendar inputs.Operating style requiredThis role requires a senior operator who can own the PCI lane in a fractional capacity. The contractor must communicate clearly, document next actions, identify blockers early, and coordinate through the project manager. This is not a casual side task. Responsiveness, ownership, and clean written work product are required.FYI's Benefits/Incentives: What is in it for you?Opportunity to work a hybrid work scheduleA knowledgeable, high-achieving, diverse, experienced, and fun team.The chance to be part of a rapidly growing company and the next success story.A competitive base salary with a loaded benefits package plus 401K.Tuition/education assistance, personal computer allowance, pet insurance.
Sourced by ZipRecruiter
It services
51 - 200 Employees
Beltsville, MD, US
1987