PCI QSA Sr. Consultant - Japan

Insight Assurance
Pacific, MO, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Information Systems Data Auditing Network Security PCI Data Security Standards Information Technology

Job description

The PCI-QSA Senior Consultant is responsible for executing PCI DSS compliance assessments and audits, ensuring that client environments meet applicable security standards. This role combines technical expertise, audit execution, and client advisory to identify risks, assess controls, and support organizations in achieving and maintaining compliance., * Perform PCI DSS assessments, including on-site and remote audits.

  • Evaluate the design and operating effectiveness of security controls.
  • Review client documentation, systems, and processes for compliance readiness.
  • Document audit procedures, findings, and recommendations.
  • Identify compliance gaps and provide remediation guidance.
  • Prepare clear and structured audit reports and deliverables.
  • Maintain regular communication with clients throughout engagements.
  • Ensure adherence to internal quality standards and audit methodologies.
  • Support clients in understanding compliance requirements and next steps.
  • Stay current with PCI DSS standards and evolving security practices., * Deliver audit engagements on time and with high quality.
  • Maintain accurate, complete, and audit-ready documentation.
  • Provide clear, actionable remediation recommendations.
  • Demonstrate ownership of assigned engagements and deliverables.
  • Maintain effective communication with clients and internal teams.
  • Adhere to internal methodologies and quality standards.
  • Continuously enhance technical and compliance knowledge.

Requirements

Do you have experience in Relationship management?, Do you have a Bachelor’s degree?, * Minimum 3 years of experience in information security.

  • Minimum 3 years of experience in PCI DSS assessments (internal, external or

QSA).

  • Experience performing security audits or compliance engagements.

Certification

  • Active QSA certification (required).
  • Additional certifications such as CISSP, CISA, or CISM are a plus., * Strong knowledge of PCI DSS and compliance requirements.
  • Solid understanding of network security, segmentation, access controls, and

encryption.

  • Strong analytical and problem-solving skills.
  • Excellent written and verbal communication skills.
  • Ability to explain technical concepts to non-technical stakeholders.
  • High attention to detail and documentation discipline.
  • Ability to work independently and manage multiple priorities.
  • Strong client-facing and relationship management skills.

Performance Expectations, Bachelor’s degree (Master’s preferred) in:

  • Cybersecurity
  • Information Systems / MIS
  • Computer Science
  • Business or related field

Benefits & conditions

  • Paid Time Off and Paid Holidays
  • Performance Bonuses
  • 100% Remote

About the company

Insight Assurance is a global audit firm on a mission to transform how organizations achieve cybersecurity and compliance. Founded by former Big 4 (EY) professionals, we deliver next-generation audit services across SOC 2, ISO 27001, PCI DSS (QSA), HITRUST, CMMC (C3PAO), and FedRAMP (3PAO) frameworks.

We’re not your traditional audit firm - we’re tech-enabled, leveraging compliance automation and advanced collaboration tools to make audits faster, smarter, and more impactful for our clients.

Recognized on the Inc. 5000 and Fast 50 lists, Insight Assurance is one of the fastest-growing global audit firms, with 170+ professionals supporting nearly 2,000 clients across the Americas, EMEA, and APAC.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:13 min

Audience Q&A on maturity assessments and external consultants

Mathias Tausig · LIVE

1:16 min

Securing internal pod communication with network security policies

Marc Nimmerrichter · WWC 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:16 min

Advantages of reproducible configurations and instantaneous rollbacks

Álvaro Martín Lozano · LIVE

2:43 min

Auditing third-party technical quality and team skill profiles

Loïc Carbonne Loïc Carbonne · WWC 2024

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all