This one is closed
Live roles like this one
-
C
20h ago
Senior Security Engineer, Identity and Access Management
HackerOne Netherlands, UK, USA
-
A
1d ago
Sourcegraph Remote 102899-137718 USD/year
-
B
3d ago
Fullbay United States $151k - $186k/yr
- C 3d ago
See every "PCI Internal Security" role →
Get new “PCI Internal Security” roles by email
One email a day with what is new in "PCI Internal Security". Nothing new, no email.
We confirm the address first, and every mail carries an unsubscribe link. Alerts are ours, not a third party's.
Why this grade This listing scored 18/100, which is an F. It lost the most ground on pay transparency. See the breakdown
- Description depth 20 / 20 How much the posting actually says about the work, measured in characters of real text.
- Remote clarity 8 / 15 Whether "remote" means anywhere, or is quietly restricted to one country.
- Corroboration 5 / 10 Whether more than one source carries this listing.
- Role specificity 0 / 10 Whether the listing is tagged well enough to tell what the role actually is.
- Freshness 0 / 15 How recently it was posted. Older postings are likelier to be filled or abandoned.
- Pay transparency 0 / 25 A published salary range, worth more than any other single factor because it is what a candidate cannot find out without applying.
-15 Ghost-job penalty — Deducted for signals that this posting may not be a real, currently-open role — staleness, repeated relisting, or talent-pool language.
Every figure above is arithmetic over the posting itself — its salary field, its text, its age, its tags and how many sources carry it. How the grades work →
Job Description: PCI Internal Security Assessor (ISA)
Department: Enterprise Security & Technology Risk Management Location: Regionwide
Reports To: Chief Information Security Officer (CISO)
Employment Type: Full-time
Job Overview
The PCI Internal Security Assessor (ISA) is responsible for ensuring that our client from banking industry complies with the Payment Card Industry Data Security Standard (PCI DSS). The ISA will assess, monitor, and enforce the security measures necessary to protect cardholder data and maintain PCI compliance across all systems and processes. This role works closely with internal stakeholders and external parties to maintain a secure environment, mitigate risks, and improve overall security posture.
Key Responsibilities:
- PCI DSS Compliance Management:
- Conduct regular internal assessments and audits to ensure the organization's compliance with PCI DSS.
Develop and implement PCI compliance policies, procedures, and controls.
- Serve as the internal point of contact for PCI DSS-related matters and ensure all applicable security controls are in place.
- Collaborate with the external Qualified Security Assessor (QSA) to facilitate annual PCI DSS certification audits.
Documentation and Reporting:
- Prepare and maintain comprehensive documentation, including policies, procedures, and reports required for PCI DSS compliance.
- Maintain comprehensive documentation of assessment findings, corrective actions, and compliance status.
- Manage the submission of the Self-Assessment Questionnaires (SAQs) and Attestation of Compliance documents (AOCs) as needed.
Qualifications:
Education:
- Bachelor’s degree in Information Security, Computer Science, or a related field (or
equivalent work experience).
- Experience:
- Minimum of 3-5 years of experience in information security, PCI compliance, or a related field.
- Previous experience as an ISA, QSA, or a similar role is highly desirable.
- Certifications:
- Certified PCI Internal Security Assessor (ISA) or Certified PCI Professional (PCIP) certifications preferred.
Additional certifications such as CISSP, CISM, CISA, or CEH are a plus.
- Skills and Competencies:
- Deep understanding of PCI DSS requirements and data security best practices.
- Familiarity with security frameworks (NIST, ISO 27001, CIS Controls) and security technologies (firewalls, IDS/IPS, encryption, etc.).
- Strong analytical, problem-solving, and project management skills.
- Excellent communication and interpersonal skills with the ability to work cross- functionally.
- Proficiency in using security assessment tools and techniques (e.g., vulnerability scanners, SIEM).
Other Requirements:
Ability to work independently and handle sensitive information confidentially.
- Detail-oriented with strong organizational skills.
- Occasional travel may be required for audits or compliance reviews.
- Identify and assess potential risks to cardholder data environments and provide recommendations for risk mitigation.
- Implement and enforce necessary security controls to address gaps identified during assessments.
- Ensure vulnerability scanning, penetration testing, and security reviews are conducted to identify weaknesses and ensure continuous compliance.
- Conduct internal PCI DSS training for staff to ensure a deep understanding of the importance of compliance and security measures.
- Provide ongoing guidance and support to departments regarding security best practices related to PCI DSS.
- Work closely with projects, Enterprise Security, Technology, and other relevant departments to align PCI DSS compliance with overall security policies and practices.
- Proactively identify and/or promptly escalate risks and issues affecting PCI compliance status.
- Stay updated on changes in PCI DSS requirements and industry best practices to ensure our client from banking industry remains compliant.
- Present PCI DSS compliance status reports to senior management and external stakeholders.
- Act as a liaison where necessary between our client from banking industry and external vendors or service providers involved in processing or storing cardholder data.
Originally posted on Himalayas
Apply for this role Opens himalayas.app — the link as listed; we have not yet verified it is the employer's own page
Quick question · anonymous · one tap
Would you apply to this job?
Answer to see what other job seekers said.
Your turn · no account needed
Help the next applicant
You may know something about this listing that we cannot see from here. One tap. No account needed. Signed-in reports earn points once the evidence agrees with you.
I know what it pays
Sign in with Google to earn points for reports — 100 confirmed points buy a week of Early Access.
Where this listing came from
- 11 Jul 2026 Himalayas first sighting
Seen on 1 board over 0 days.