PCI QSA Consultant
EA Team
United States
about 1 month ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source
Tech stack
Amazon Web Services
Microsoft Azure
Information Systems Security Architecture Professional
PCI Data Security Standards
Systems Development Life Cycle
Strategies of Testing
Google Cloud
Software Security
Job description
You will act as a trusted PCI DSS advisor, leading:
- Full-cycle PCI DSS assessments (readiness, gap, and formal audits)
- Production of Reports on Compliance (RoC) and Attestations of Compliance (AoC)
- CDE scoping, segmentation, and validation strategies
- PCI DSS v3.x and v4.0 transition and impact assessments
- GRC advisory across NIST, ISO 27001, and HIPAA frameworks
- Executive-level risk and compliance reporting for CISOs and CIOs, You will work on high-impact PCI DSS engagements, advising enterprise clients on complex security and compliance challenges while shaping their long-term risk and compliance posture.
Requirements
We are looking for an experienced PCI Qualified Security Assessor (QSA) to lead enterprise PCI DSS compliance, assessment, and advisory engagements across complex environments.
This is a senior consulting role focused on delivering end-to-end PCI DSS assessments, guiding clients through RoC/AoC validation, and advising security leadership on compliance strategy, risk reduction, and secure architecture design., * Active PCI QSA certification (mandatory)
- Strong hands-on experience delivering PCI DSS assessments and RoCs
- Deep understanding of PCI DSS requirements, especially v4.0
- Experience with enterprise security and compliance programs
- Ability to translate technical findings into business and risk outcomes
- Strong client-facing consulting and communication skills
Nice to Have
- CISA, CISM, CRISC, CISSP certifications
- Experience with AWS, Azure, or Google Cloud Platform security assessments
- Knowledge of FAIR risk quantification
- Application security or SDLC governance experience
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on dice.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
AJ
Austin Joy
over 4 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
6 months ago
LM
Luis Minvielle
7 Cloud Computing Trends Coming in 2025 for Developers
over 2 years ago
DC
Daniel Cranney
Top Must-Visit Developer Conferences in the US in 2026
7 months ago
LM
Luis Minvielle
Fully Remote Software Engineer Jobs
about 2 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
about 2 years ago