> Markdown version of [/jobs/ext/1727297-sr-security-compliance-analyst-pci-dss-soc-2](https://www.wearedevelopers.com/jobs/ext/1727297-sr-security-compliance-analyst-pci-dss-soc-2). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Security Compliance Analyst - PCI DSS & SOC 2... - **Company:** Entrust Corporation - **Location:** Shakopee, MN, United States (Remote available) - **Experience:** Expert - **Salary:** $119,078.0 - $174,648.0 - **Contract:** Permanent contract - **Skills:** Software as a Service, Cloud Computing, PCI Data Security Standards, Software Vulnerability Management, Data Logging, Cloud Platform System, RSA Archer Platform - **Published:** July 10, 2026 - **Apply:** https://www.juju.com/job/00000000gfde1z ## About the Role + 5+ years in security compliance, audit, or GRC with a strong understanding of administrative, technical, and physical controls, including how they support one another + Hands-on technical and audit experience with PCI DSS and SOC 2 compliance + Ability to work across multiple time zones with virtual global teams + Strong technical understanding of: + Cloud environments and shared responsibility models + Access control, change management, logging and altering, and vulnerability management and other security domains + Experience working in SaaS or cloud-native environments + Experience working cross-functionally with engineering and infrastructure teams + Must be a US citizen Preferred Qualifications: + Experience supporting multiple compliance frameworks (PCI DSS, PCI CP, SOC 2, FedRAMP, ISO 27001, etc.) + Experience with modern GRC platforms and control automation + Familiarity with continuous compliance / continuous monitoring models + Certifications such as: CISSP, CISA, CISM, CRISC, PCI ISA/QSA/PCIP (preferred but not required) ## Description Entrust is seeking a highly skilled Senior Security Compliance Analyst to lead and sustain compliance for multiple PCI DSS environments while supporting the maturity and execution of our SOC 2 program. This role is responsible for designing and executing continuous compliance monitoring activities, identifying gaps and leading associated remediation efforts, planning and leading third-party audits, and measuring control effectiveness across cloud-based, on-prem and hybrid environments. The ideal candidate brings deep PCI DSS expertise, strong SOC 2 familiarity, and modern GRC experience that enable scalable, automated, and evidence-driven compliance operations. This position partners closely with Security, Engineering, Product, and third-party providers to ensure controls are designed effectively, operating consistently, and aligned to business, statutory and regulatory expectations. How You Will Make an Impact: Lead and support end-to-end compliance efforts across multiple environments, including readiness assessments, audits, and continuous monitoring activities to ensure sustained security posture and audit readiness. Responsibilities include, but are not limited to: + Leading PCI DSS compliance-related activities and certification; + Supporting the evolution and execution of the SOC 2 program, including control design, testing, and evidence collection; + Maintaining required evidence artifacts and ensuring traceability of evidence; + Interpreting and operationalizing security and compliance requirements into actionable control activities for engineering and operations; + Serving as SME for PCI DSS and SOC 2 compliance, advising internal teams and customers; + Partnering with control owners to ensure controls meet PCI DSS requirements and Trust Services Criteria (Security, Availability, Confidentiality, etc.); + Supporting external audits by preparing evidence, responding to auditor requests, coordinating audit activities, and tracking remediation; + Driving coordination with third parties (e.g., service providers, hosting partners) to ensure shared control alignment; + Ensuring audit readiness through continuous proactive gap assessments and control testing throughout the year; + Identifying, assessing, and communicating compliance and security risks to stakeholders; + Identifying, tracking, and driving closure of audit findings and control deficiencies; and + Contributing to the development and maintenance of security policies, standards, and procedures. ## Related Videos - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [WebAssembly: The Next Frontier of Cloud Computing](https://www.wearedevelopers.com/videos/972-webassembly-the-next-frontier-of-cloud-computing) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)