> Markdown version of [/jobs/ext/582864-pci-dss-saq-d-service-provider-lead](https://www.wearedevelopers.com/jobs/ext/582864-pci-dss-saq-d-service-provider-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # PCI DSS SAQ D Service Provider Lead - **Company:** FYI-For Your Information, Inc. - **Location:** Silver Spring, MD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Confluence, JIRA, Microsoft Azure, Software as a Service, CompTIA Security+, Cyber Security, Multi-Factor Authentication, Data Flow Control, Identity and Access Management, Information Technology Audit, PCI Data Security Standards, Secure Coding, Software Vulnerability Management, Data Logging, Google Cloud, Vulnerability Analysis - **Published:** June 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=1532386f92a9ce25 ## About the Role Do you have experience in Vuls?, * 8+ years of cybersecurity, GRC, IT audit, compliance, security consulting, or related experience. * Direct hands-on experience supporting PCI DSS assessments. * Direct experience with PCI DSS SAQ D; Service Provider experience is strongly preferred. * Experience with SaaS, cloud-hosted, fintech, payment, or payment-adjacent environments. * Working knowledge of ASV scanning, internal vulnerability scanning, penetration testing evidence, vulnerability remediation, IAM/MFA, encryption, logging, monitoring, FIM, change control, and secure development requirements. * Ability to translate PCI requirements into practical tasks for engineering, IT, security, and business stakeholders. * Strong written communication skills and ability to produce audit-ready summaries and responses. * Ability to work through ambiguity and distinguish sufficient evidence from weak or incomplete evidence. Nice to have * Prior QSA, ISA, or QSA-firm experience. * PCI DSS v4.x experience. * CISA, CISSP, CISM, Security+, or equivalent certification. * Experience with Drata, Vanta, Secureframe, Hyperproof, Jira, Confluence, AWS, Azure, GCP, or similar platforms. * SOC 2 familiarity, especially where controls overlap with PCI DSS. ## Description FYI is seeking a PCI DSS SAQ D Service Provider Lead to support an active PCI compliance program for a SaaS/cloud/payment-adjacent environment. This role will own the PCI domain in a fractional capacity, including PCI scoping support, evidence sufficiency review, quarterly scan cadence, penetration testing evidence, remediation tracking, and responses to auditors, QSAs, processors, banks, or other requesting entities. The right candidate has done this work before and can drive their lane without constant prompting., * Support PCI DSS SAQ D Service Provider readiness, scoping, evidence review, and control interpretation. * Review PCI scope assumptions, in-scope systems, applications, integrations, service providers, and payment/data-flow considerations. * Coordinate and review evidence for quarterly external ASV scans and internal vulnerability scans. * Coordinate PCI-relevant penetration testing evidence, including scope, rules of engagement, final report review, remediation, and retest evidence. * Review evidence for file integrity monitoring, encryption, MFA, IAM, logging, monitoring, change control, secure development, vulnerability management, and remediation tracking where relevant to PCI DSS. * Identify weak, incomplete, stale, unclear, or nonresponsive evidence before submission. * Draft or review PCI-related auditor, QSA, processor, or requesting-entity responses. * Support tracking of PCI remediation items, exceptions, compensating-control discussions, and risk acceptance needs. * Help define and maintain recurring PCI compliance cadence, including quarterly scans and annual validation activities. * Provide concise written status updates, blockers, risks, and next actions to the project manager and CISO/vCISO., Expected deliverables * PCI DSS SAQ D evidence and gap tracker inputs. * PCI scope notes, assumptions, and issue summaries. * ASV and internal vulnerability scan evidence checklists. * Penetration testing evidence checklist and report sufficiency review notes. * PCI remediation tracker updates and risk summaries. * PCI auditor/requesting-entity response drafts. * PCI quarterly and annual compliance calendar inputs. Operating style required This role requires a senior operator who can own the PCI lane in a fractional capacity. The contractor must communicate clearly, document next actions, identify blockers early, and coordinate through the project manager. This is not a casual side task. Responsiveness, ownership, and clean written work product are required. ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [42 x 2 Canvases Later: Two Years, Two Minds, Many Lessons](https://www.wearedevelopers.com/videos/1458-42-x-2-canvases-later-two-years-two-minds-many-lessons) - [A Founder's Journey : From Startup Chaos to Purposeful Growth](https://www.wearedevelopers.com/videos/1926-a-founder-s-journey-from-startup-chaos-to-purposeful-growth) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 119 - ❤️ === ❤️](https://www.wearedevelopers.com/magazine/454-dev-digest-119) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)