> Markdown version of [/jobs/ext/1093192-pci-qualified-security-assessor-qsa-consultant](https://www.wearedevelopers.com/jobs/ext/1093192-pci-qualified-security-assessor-qsa-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # PCI Qualified Security Assessor (QSA) Consultant - **Company:** Danta Technologies - **Location:** New York, NY, United States (Remote available) - **Experience:** Expert - **Salary:** $114,400.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Burp Suite, Cloud Computing, Cyber Security, Information Systems, Factor Analysis, Network Monitoring, Open Web Application Security, PCI Data Security Standards, Systems Development Life Cycle, Traffic Analysis, Google Cloud, Software Security, Operational Systems, Static Application Security Testing, Dynamic Application Security Testing - **Published:** June 30, 2026 - **Apply:** https://www.dice.com/job-detail/896902bd-f649-4c1a-9ec7-df6bc745447b ## About the Role Proven experience as a PCI QSA (Qualified Security Assessor) Must Have Strong working knowledge of: PCI DSS requirements (v3.x and v4.0) documentation Good to have Security audits and compliance assessments Risk management frameworks and control mapping Certifications PCI QSA CISA CRISC Min to Max Experience needed 8 to 12 years of experience, Core PCI Expertise * Proven experience as a PCI QSA (Qualified Security Assessor) * Strong working knowledge of: + PCI DSS requirements (v3.x and v4.0) + Cardholder Data Environment (CDE) scoping and segmentation * Experience producing: + RoC and Client documentation __________________________________________________ GRC & Compliance Skills * Hands-on experience with: + Security audits and compliance assessments + Risk management frameworks and control mapping * Familiarity with: + NIST, ISO 27001, HIPAA, and industry-specific standards, + SAST/DAST testing methodologies + Secure SDLC governance * Exposure to: + Cloud platforms (AWS, Azure, Google Cloud Platform) + Cloud compliance frameworks and risk models, + App security tools (e.g., Burp Suite or equivalent) + Compliance and audit management tools + Risk quantification models (FAIR or similar), * PCI QSA certification (Required) * Preferred: + CISA (Certified Information Systems Auditor) + CISM (Certified Information Security Manager) + CRISC (Certified in Risk and Information Systems Control) + Additional cloud or security certifications are a plus, * Strong stakeholder engagement with CISO, CIO, and board-level stakeholders * Ability to translate regulatory requirements into business-aligned outcomes * Strong technical writing and audit report development skills * Excellent communication and presentation skills * High attention to detail and structured problem-solving approach, * Quality and defensibility of audit outputs * Client satisfaction and repeat advisory engagements * Ability to drive measurable compliance posture improvements ## Description Client is seeking a highly experienced PCI Qualified Security Assessor (QSA) Consultant to lead and deliver end-to-end Payment Card Industry (PCI DSS) advisory, assessment, and validation services. This role focuses on guiding clients through PCI DSS compliance journeys, conducting formal validations (RoC/Client), and providing strategic security advisory across GRC, application security, and cloud risk domains. The ideal candidate will bring deep expertise in PCI DSS standards, audit execution, compliance strategy, and executive advisory, with the ability to translate regulatory requirements into actionable security and business outcomes., 1. PCI DSS Consulting & Assessment (Core Function) * Lead end-to-end PCI DSS compliance engagements, including: + Gap assessments and readiness assessments + Formal audits and validation activities * Conduct PCI DSS assessments and produce: + Reports on Compliance (RoC) + Attestations of Compliance (Client) * Advise clients on: + PCI DSS scoping and segmentation strategies + Compensating controls and requirement interpretation * Perform impact assessments for PCI DSS version upgrades, including: + Resource planning (people, tools, time) + Required architecture and system changes, 2. GRC & Security Framework Assessments * Conduct compliance and maturity assessments across frameworks such as: + PCI DSS (primary focus) + NIST (CSF, 800-53, 800-171) + ISO 27001 / 27002 + HIPAA and other regulatory standards * Perform: + Security program evaluations + Control gap analysis and remediation roadmaps, + Black Box, Gray Box, and Crystal Box testing + SDLC maturity assessments aligned to OWASP SAMM * Conduct cloud risk assessments across: + AWS, Azure, and Google Cloud Platform * Evaluate: + Cloud configurations, identity controls, and data protection mechanisms, 4. Executive Advisory & Cyber Risk Quantification (Optional) * Operate as a Security Program Advisor / Executive Consultant, providing: + Strategic compliance roadmap guidance + Risk posture insights to senior leadership * Utilize frameworks such as: + FAIR (Factor Analysis of Information Risk) for financial risk quantification * Support board-level and C-suite communications, including: + Risk reports + Compliance status dashboards, 5. E-Discovery, Audit Support & Documentation * Support compliance and audit programs with: + Evidence collection and validation + Audit documentation and reporting * Develop: + Policies, standards, and procedures aligned with PCI DSS and GRC frameworks * Deliver high-quality audit artifacts and technical reports, 6. Operational Technology (OT) & Specialized Assessments (Optional) * Conduct security assessments in OT/ICS environments, including: + Passive network monitoring and traffic analysis + Non-intrusive evaluation of control systems and networks ## Related Videos - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How to Write a CV and Interview if You Don't Fully Qualify For The Job](https://www.wearedevelopers.com/magazine/183-how-to-write-a-cv-and-interview-if-you-don-t-fully-qualify-for-the-job) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)