Robert Half

Lead Info Security Analyst

Robert Half

PCI DSSGRCSecurity EngineeringIT AuditNISTCobitISO 27001ServiceNow IRM

About the Role

We are seeking an experienced PCI Technical Engineer to help build, strengthen, and automate a PCI DSS compliance program within a highly regulated financial services environment.

This is a hands-on role for someone who understands PCI DSS at a deep level and has built and matured a PCI program from the ground up. The ideal candidate will have experience defining PCI scope and boundaries, understanding the Cardholder Data Environment (CDE), establishing and validating controls, supporting audits, remediating findings, and continuously improving the program.

This role is also focused on automation and process improvement. We are looking for someone who is a creator and problem solver—someone who sees a manual process and asks, “How can we make this better and automate it?”

What You’ll Do

  • Build, implement, and mature PCI DSS compliance programs from the ground up.
  • Define and maintain PCI scope and boundaries, including identifying systems, applications, networks, processes, and people that fall within PCI requirements.
  • Develop a strong understanding of the Cardholder Data Environment (CDE) and how payment card data moves through the environment.
  • Establish, document, and validate technical and administrative controls required for PCI DSS compliance.
  • Lead PCI audit preparation, evidence gathering, auditor coordination, remediation, and ongoing compliance activities.
  • Gather and validate technical artifacts and evidence required to demonstrate compliance.
  • Identify control gaps and partner with technical teams to develop and implement remediation plans.
  • Continuously assess and mature the PCI program as the technology environment and business requirements evolve.
  • Automate PCI evidence collection, control validation, reporting, and other repetitive compliance processes.
  • Identify opportunities to automate manual GRC and Information Security processes beyond PCI.
  • Develop repeatable processes and solutions that improve efficiency, accuracy, and audit readiness.
  • Support internal audits and financial services regulatory examinations.
  • Document technical processes and controls in a clear and accurate manner.
  • Develop metrics and reporting that communicate compliance, control effectiveness, risk, and remediation status to leadership.
  • Partner with Information Security, Infrastructure, Application, Risk, Audit, and other technical teams.
  • Help establish and maintain security policies, standards, procedures, and controls related to PCI and Information Security.

Requirements

What We’re Looking For

  • 5–8+ years of experience in PCI DSS, Information Security, GRC, IT Audit, Security Engineering, or a related discipline.
  • Deep, hands-on PCI DSS expertise.
  • Proven experience building a PCI compliance program from the ground up, rather than simply participating in an existing program.
  • Experience defining PCI scope, boundaries, and the Cardholder Data Environment (CDE).
  • Experience taking a PCI program through implementation, audit, remediation, and ongoing maturity.
  • Strong understanding of security controls, control testing, evidence requirements, and audit processes.
  • Experience gathering and validating technical artifacts for PCI audits and compliance requirements.
  • Demonstrated ability to identify manual or inefficient processes and design and implement automation.
  • Experience with GRC platforms such as ServiceNow IRM or LogicGate preferred.
  • Understanding of security frameworks such as NIST, COBIT, MAR, and/or ISO 27001.
  • Financial services or banking experience strongly preferred.
  • Strong analytical and problem-solving skills with exceptional attention to detail.
  • Ability to communicate complex technical and compliance requirements to both technical and non-technical stakeholders.
  • Ability to work independently and take ownership of building solutions rather than simply maintaining existing processes.
  • One or more of the following certifications preferred/required: CISSP, CISM, CRISC, CISA, or PCI-related certification.
  • Bachelor's degree in Information Security, Computer Science, Risk Management, or a related field preferred.

You'll be redirected to Robert Half's application page

Job Details

Salary

$125K–$146K

Location

United States - Middleton WI

Job type

Temporary

Category

ServiceNow Development

Experience

5–8+ years

Posted

5 days ago

Job Highlights

  • $125K–$146K salary
  • 5–8+ years level role
  • 100% Remote — open to candidates in United States

About Robert Half

This job is hosted by Robert Half. Clicking Apply opens their site.

More jobs from Robert Half on RC9

Remote Work Style

Mixed

Mix of flexible and scheduled meetings

Your Match

See how well your skills line up with this role, and what you're missing.

AI Cover Letter

Generate a cover letter tailored to this job from your profile.