PCI QSA Consultant

EA Team
United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Information Systems Security Architecture Professional PCI Data Security Standards Systems Development Life Cycle Strategies of Testing Google Cloud Software Security

Job description

You will act as a trusted PCI DSS advisor, leading:

  • Full-cycle PCI DSS assessments (readiness, gap, and formal audits)
  • Production of Reports on Compliance (RoC) and Attestations of Compliance (AoC)
  • CDE scoping, segmentation, and validation strategies
  • PCI DSS v3.x and v4.0 transition and impact assessments
  • GRC advisory across NIST, ISO 27001, and HIPAA frameworks
  • Executive-level risk and compliance reporting for CISOs and CIOs, You will work on high-impact PCI DSS engagements, advising enterprise clients on complex security and compliance challenges while shaping their long-term risk and compliance posture.

Requirements

We are looking for an experienced PCI Qualified Security Assessor (QSA) to lead enterprise PCI DSS compliance, assessment, and advisory engagements across complex environments.

This is a senior consulting role focused on delivering end-to-end PCI DSS assessments, guiding clients through RoC/AoC validation, and advising security leadership on compliance strategy, risk reduction, and secure architecture design., * Active PCI QSA certification (mandatory)

  • Strong hands-on experience delivering PCI DSS assessments and RoCs
  • Deep understanding of PCI DSS requirements, especially v4.0
  • Experience with enterprise security and compliance programs
  • Ability to translate technical findings into business and risk outcomes
  • Strong client-facing consulting and communication skills

Nice to Have

  • CISA, CISM, CRISC, CISSP certifications
  • Experience with AWS, Azure, or Google Cloud Platform security assessments
  • Knowledge of FAIR risk quantification
  • Application security or SDLC governance experience

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:06 min

Elevating the QA engineering role for complex challenges

Ondřej Gróf Ondřej Gróf · WWC Europe 2026

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar · WWC 2024

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · WWC 2022

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 · WWC 2025

5:13 min

Audience Q&A on maturity assessments and external consultants

Mathias Tausig · LIVE

4:42 min

Container hosting options available on Google Cloud Platform

Federico Fregosi · WWC 2022

Videos

See all

Related articles

See all