About this role
ascio is hiring a PCI DSS Compliance Specialist to support our payment security and compliance work across a range of organizations and payment environments.
This role will help organizations understand and reduce their cardholder data environment, assess compliance with PCI DSS v4.0.1, complete applicable self-assessment requirements and prepare for formal assessment where required. QSA status is not required.
Responsibilities
- Inventory payment channels, merchant accounts and service providers and develop cardholder data flow diagrams.
- Determine and reduce cardholder data environment scope through approaches including segmentation, tokenization, point-to-point encryption and outsourcing.
- Interpret PCI DSS v4.0.1 requirements and conduct gap assessments with practical remediation plans.
- Determine the appropriate Self-Assessment Questionnaire and support completion of the applicable SAQ and Attestation of Compliance.
- Prepare assessment evidence and support coordination with Qualified Security Assessors where a Report on Compliance is required.
- Review remediation activity and support readiness for reassessment.
- Provide guidance and training on ongoing PCI DSS responsibilities and compliance requirements.
Required Skills and Experience
- Five or more years of experience working with PCI DSS in an assessment, compliance, advisory or implementation role.
- Detailed working knowledge of PCI DSS v4.0.1 requirements and appendices.
- Strong experience determining and reducing cardholder data environment scope, including network segmentation.
- Experience determining and working with applicable Self-Assessment Questionnaires, including SAQ A, A-EP, B, B-IP, C, C-VT, D and P2PE.
- Experience conducting PCI DSS gap assessments and developing remediation plans.
- Experience preparing evidence for a Report on Compliance or comparable formal assessment.
- Strong knowledge of payment technologies including tokenization, point-to-point encryption, hosted payment pages, payment terminals and third-party payment services.
- Understanding of PCI DSS vulnerability scanning and penetration testing requirements, including working with Approved Scanning Vendors.
- Strong written and verbal communication skills, with the ability to explain compliance requirements to both technical and non-technical audiences.
Qualifications
- One or more relevant current professional certifications or credentials such as PCIP, ISA, QSA or former QSA status, or CISA or CISSP combined with demonstrable PCI DSS assessment experience.
- Applicants must be able to provide certification or credential status and expiry dates, where applicable.
- Degree or diploma in information systems, accounting, cybersecurity or a related field, or equivalent professional experience.
- PCI Security Standards Council training is considered an asset.
Preferred Experience
- Multi-merchant environments with numerous payment channels.
- Point-of-sale and payment terminal security.
- Cloud-hosted payment environments.
- Integration of PCI DSS controls with ISO/IEC 27001 or other information security management frameworks.
- Experience working with third-party payment processors and service providers.
Location and Work Arrangement
- Remote within Canada.
- Some assignments may require occasional onsite work or travel within Canada.
- Applicants must be based in Canada and legally entitled to work in Canada.
- A criminal record check may be required before access to sensitive systems, information or environments.
Compensation Details
$85.00/hour
Ready to apply?
Pay shown up front. Free for job seekers, always.