> Markdown version of [/jobs/ext/2296194-lead-grc-security-analyst](https://www.wearedevelopers.com/jobs/ext/2296194-lead-grc-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead GRC Security Analyst - **Company:** Robert Half - **Location:** Appleton, WI, United States - **Experience:** Expert - **Contract:** Temporary contract - **Skills:** Cyber Security, PCI Data Security Standards, Information Technology, RSA Archer Platform, CIS Benchmarks, Servicenow - **Published:** August 29, 2026 - **Apply:** https://www.juju.com/job/00000000gpmqv3 ## About the Role + 5-8 years of experience in Information Security GRC, with at least 3 years of hands-on PCI DSS experience. + Demonstrated experience owning or leading an enterprise PCI DSS program. + Strong experience with CDE scoping and PCI DSS control requirements. + Experience managing QSA relationships and leading PCI assessments through preparation, assessment, remediation, and closure. + Experience with GRC platforms such as ServiceNow, LogicGate, Archer, or similar. + Experience supporting internal/external audits, regulatory examinations, evidence collection, and remediation. + Working knowledge of NIST CSF 2.0 and CIS Controls v8, including the ability to map controls across security and compliance frameworks. + Experience developing and presenting KRIs, KPIs, OKRs, and security/risk metrics. + Strong communication skills with the ability to explain complex PCI and security control gaps to non-technical audiences and executive leadership. + Bachelor's degree in Information Security, Computer Science, Risk Management, or a related field., All applicants applying for U.S. job openings must be legally authorized to work in the United States. Benefits are available to contract/temporary professionals, including medical, vision, dental, and life and disability insurance. Hired contract/temporary professionals are also eligible to enroll in our company 401(k) plan. Visit roberthalf.gobenefits.net for more information. ## Description We are seeking an experienced Information Security GRC professional with strong PCI DSS expertise to lead the design, implementation, and ongoing execution of an enterprise PCI DSS v4.0 compliance program within a highly regulated environment. This role will serve as the organization's PCI subject matter expert (SME), responsible for ensuring accurate Cardholder Data Environment (CDE) scoping, sustainable control implementation, continuous compliance, and effective governance. The successful candidate will work cross-functionally with Security, IT, Risk, Compliance, Audit, and business stakeholders to embed PCI requirements into technology and operational processes. This is a highly visible role requiring someone who can operate strategically while also being comfortable getting into the details of controls, evidence, assessments, remediation, and audit readiness. Key Responsibilities + Lead the enterprise PCI DSS v4.0 program, including governance, compliance, assessment, and continuous improvement activities. + Validate and maintain accurate Cardholder Data Environment (CDE) scope. + Serve as the primary PCI DSS subject matter expert across the organization. + Partner with Security, IT, Risk, Compliance, Audit, and business teams to drive cross-functional accountability for PCI requirements. + Manage relationships with Qualified Security Assessors (QSAs) and coordinate PCI assessments from preparation through remediation and closure. + Develop and manage remediation strategies for PCI and security control gaps. + Support risk acceptance processes and ensure appropriate documentation and governance. + Test and evaluate control effectiveness and maintain clear control traceability. + Manage evidence collection, assessment walkthroughs, findings, remediation, and closure activities. + Support internal and external audits as well as regulatory examinations. + Conduct security risk and control assessments. + Develop and report KRIs, KPIs, OKRs, and other security/compliance metrics. + Present security, risk, and control findings to both technical stakeholders and executive leadership. + Lead reviews, updates, and approvals of security policies, standards, and related governance documentation. + Embed PCI requirements into technology and operational lifecycles. + Drive ongoing improvements to the organization's security compliance and risk management processes. Technical Environment + PCI DSS v4.0 + Information Security Governance, Risk & Compliance (GRC) + ServiceNow, LogicGate, Archer, or similar GRC platforms + NIST Cybersecurity Framework (CSF) 2.0 + CIS Controls v8 + Security controls and compliance management + Risk assessments ## Related Videos - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)