> Markdown version of [/jobs/ext/1918443-lead-pci-dss-consultant-qualified-security-assessor-qsa](https://www.wearedevelopers.com/jobs/ext/1918443-lead-pci-dss-consultant-qualified-security-assessor-qsa). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead PCI DSS Consultant / Qualified Security Assessor (QSA) - **Company:** Golden, LLC - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $187,200.0 - $312,000.0 - **Contract:** Temporary contract - **Skills:** Payment Systems, Intrusion Detection Systems, Network Architecture, Payment Gateway, PCI Data Security Standards, Software Vulnerability Management, Vulnerability Analysis - **Published:** August 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=5612cd6226cf361e ## About the Role * At least 10 years of relevant experience providing PCI DSS compliance consulting services. * Extensive knowledge of current PCI DSS requirements, including PCI DSS 4.x. * Demonstrated experience conducting PCI DSS assessments, gap analyses, control validation, and remediation planning. * Experience supporting complex organizations with multiple merchants, campuses, business units, or payment environments. * Ability to provide at least three relevant client references who may be contacted. * Ability to provide at least two higher-education references involving similar PCI DSS or payment-security services. * Experience with SAQs, AOCs, ROCs, third-party service providers, payment gateways, vulnerability management, P2PE, tokenization, and payment-security controls. * Authorization to perform professional consulting services in New York State. * Ability to provide documentation verifying all claimed credentials and the qualifications of proposed key personnel. * Ability to comply with confidentiality, cybersecurity, privacy, background-screening, and data-protection requirements. * Strong written, verbal, technical, training, and stakeholder-management skills., * Active Qualified Security Assessor credential issued through the PCI Security Standards Council. * Employment by or affiliation with a PCI SSC-recognized Qualified Security Assessor Company. * Experience serving colleges, universities, government agencies, or public-sector institutions. * Experience with decentralized or multi-campus merchant environments. * Knowledge of FERPA, the Gramm-Leach-Bliley Act, applicable privacy requirements, and government cybersecurity standards. * Relevant credentials such as QSA, PCIP, ISA, CISSP, CISA, CISM, CRISC, or comparable certifications. * Experience evaluating payment gateways, merchant processors, P2PE solutions, tokenization, EMV, NFC, e-commerce, and mobile-payment technologies. * Professional liability, errors-and-omissions, cyber, security, and privacy insurance coverage of at least $1 million per occurrence., * A summary of relevant PCI DSS experience * Details of higher-education or government experience * Availability and proposed hourly rate Authorized representatives of established PCI DSS or QSA consulting firms may also apply through Indeed. Firm representatives should provide: * A company capability statement * Total years of organizational PCI DSS experience * PCI SSC company and personnel credentials * At least three relevant client references, including two higher-education references * Proposed project team and key-personnel résumés * Preferred engagement structure * Proposed hourly, monthly, or project-based pricing * Evidence of applicable insurance, if available ## Description The selected consultant or consulting partner will help assess, improve, and maintain PCI DSS compliance across complex payment-card environments. The work may include gap assessments, remediation guidance, policies and procedures, training, merchant-account support, payment-gateway evaluation, third-party compliance reviews, and ongoing advisory services., * Conduct PCI DSS gap analyses across cardholder data environments. * Review payment-card devices, network infrastructure, security controls, system inventories, network diagrams, and payment-data flows. * Perform control observation, testing, review, and validation. * Identify compliance risks and develop practical remediation recommendations. * Develop and update PCI DSS policies, procedures, checklists, and training materials. * Support Self-Assessment Questionnaires, Attestations of Compliance, Reports on Compliance, third-party service-provider reviews, and other PCI compliance documentation. * Review merchant accounts, merchant IDs, payment gateways, processors, and payment solutions. * Assist with onboarding, configuration, testing, maintenance, and troubleshooting of payment systems. * Evaluate card-present, online, and mobile payment solutions. * Recommend validated P2PE, tokenization, EMV, NFC, and other PCI scope-reduction solutions. * Review internal and external vulnerability-scanning processes and resulting remediation activities. * Review third-party agreements for appropriate PCI DSS requirements. * Develop reusable templates and maintain version-controlled compliance documentation. * Prepare management reports, technical findings, project updates, meeting summaries, and other required deliverables. * Provide PCI DSS training and ongoing advisory support to technical and nontechnical stakeholders. * Participate in meetings and coordinate with university, technology, finance, procurement, and merchant stakeholders. ## Related Videos - [Migrating half a million users to a new payment service provider](https://www.wearedevelopers.com/videos/730-migrating-half-a-million-users-to-a-new-payment-service-provider) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [​Road to Web3](https://www.wearedevelopers.com/videos/584-road-to-web3) - [AI-Augmented DevOps with Platform Engineering](https://www.wearedevelopers.com/videos/1614-ai-augmented-devops-with-platform-engineering) - [HTTP 402: Teaching the Web to Let Agents Pay](https://www.wearedevelopers.com/videos/100232-http-402-teaching-the-web-to-let-agents-pay) - [200 OK: Payment settled, resource delivered](https://www.wearedevelopers.com/videos/100063-200-ok-payment-settled-resource-delivered) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany)