Lead GRC Security Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
We are seeking an experienced Information Security GRC professional with strong PCI DSS expertise to lead the design, implementation, and ongoing execution of an enterprise PCI DSS v4.0 compliance program within a highly regulated environment.
This role will serve as the organization’s PCI subject matter expert (SME), responsible for ensuring accurate Cardholder Data Environment (CDE) scoping, sustainable control implementation, continuous compliance, and effective governance. The successful candidate will work cross-functionally with Security, IT, Risk, Compliance, Audit, and business stakeholders to embed PCI requirements into technology and operational processes.
This is a highly visible role requiring someone who can operate strategically while also being comfortable getting into the details of controls, evidence, assessments, remediation, and audit readiness.
Key Responsibilities
-
Lead the enterprise PCI DSS v4.0 program, including governance, compliance, assessment, and continuous improvement activities.
-
Validate and maintain accurate Cardholder Data Environment (CDE) scope.
-
Serve as the primary PCI DSS subject matter expert across the organization.
-
Partner with Security, IT, Risk, Compliance, Audit, and business teams to drive cross-functional accountability for PCI requirements.
-
Manage relationships with Qualified Security Assessors (QSAs) and coordinate PCI assessments from preparation through remediation and closure.
-
Develop and manage remediation strategies for PCI and security control gaps.
-
Support risk acceptance processes and ensure appropriate documentation and governance.
-
Test and evaluate control effectiveness and maintain clear control traceability.
-
Manage evidence collection, assessment walkthroughs, findings, remediation, and closure activities.
-
Support internal and external audits as well as regulatory examinations.
-
Conduct security risk and control assessments.
-
Develop and report KRIs, KPIs, OKRs, and other security/compliance metrics.
-
Present security, risk, and control findings to both technical stakeholders and executive leadership.
-
Lead reviews, updates, and approvals of security policies, standards, and related governance documentation.
-
Embed PCI requirements into technology and operational lifecycles.
-
Drive ongoing improvements to the organization’s security compliance and risk management processes.
Technical Environment
-
PCI DSS v4.0
-
Information Security Governance, Risk & Compliance (GRC)
-
ServiceNow, LogicGate, Archer, or similar GRC platforms
-
NIST Cybersecurity Framework (CSF) 2.0
-
CIS Controls v8
-
Security controls and compliance management
-
Risk assessments
Requirements
-
5-8 years of experience in Information Security GRC, with at least 3 years of hands-on PCI DSS experience.
-
Demonstrated experience owning or leading an enterprise PCI DSS program.
-
Strong experience with CDE scoping and PCI DSS control requirements.
-
Experience managing QSA relationships and leading PCI assessments through preparation, assessment, remediation, and closure.
-
Experience with GRC platforms such as ServiceNow, LogicGate, Archer, or similar.
-
Experience supporting internal/external audits, regulatory examinations, evidence collection, and remediation.
-
Working knowledge of NIST CSF 2.0 and CIS Controls v8, including the ability to map controls across security and compliance frameworks.
-
Experience developing and presenting KRIs, KPIs, OKRs, and security/risk metrics.
-
Strong communication skills with the ability to explain complex PCI and security control gaps to non-technical audiences and executive leadership.
-
Bachelor’s degree in Information Security, Computer Science, Risk Management, or a related field., All applicants applying for U.S. job openings must be legally authorized to work in the United States. Benefits are available to contract/temporary professionals, including medical, vision, dental, and life and disability insurance. Hired contract/temporary professionals are also eligible to enroll in our company 401(k) plan. Visit roberthalf.gobenefits.net for more information.
Benefits & conditions
Robert Half works to put you in the best position to succeed. We provide access to top jobs, competitive compensation and benefits, and free online training. Stay on top of every opportunity - whenever you choose - even on the go. Download the Robert Half app (https://www.roberthalf.com/us/en/mobile-app) and get 1-tap apply, notifications of AI-matched jobs, and much more.
About the company
Robert Half is the world’s first and largest specialized talent solutions firm that connects highly qualified job seekers to opportunities at great companies. We offer contract, temporary and permanent placement solutions for finance and accounting, technology, marketing and creative, legal, and administrative and customer support roles.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Fully Remote Software Engineer Jobs
What’s the Difference between a Junior, Mid, and Senior Developer?
Best Paying Jobs in Technology