Summary of This Role
Proactively protect Global Payments business, contribute to the company’s PCI Compliance and IT Risk Management posture and support client’s ability to comply by assisting in all associated activities which include reviewing internal processes, documents and reports from payment networks and/or other regulatory bodies, and ensuring compliance with internal and external regulatory frameworks. Identify required, discretionary, business and system updates, recommend approaches and solutions that are compliant with applicable regulations while balancing proper investment pursuant to overall corporate, division and department goals. May develop and implement training plans for the effective use of Global Payments Tools & Methodologies. May engage with client and industry stakeholders to educate and influence network/scheme or regulatory strategy.
What Part Will You Play?
PCI Compliance Program Support
- Execute day-to-day activities that support the organization’s PCI DSS compliance program
- Maintain and update evidence repositories for PCI controls and assessments
- Track and monitor compliance status across systems, applications, and business units
- Assist in preparation for internal and external PCI audits and assessments
Control Validation & Monitoring
- Perform control checks and validation activities aligned with established PCI controls
- Review security configurations, access controls, and logging practices for compliance
- Support continuous monitoring processes to ensure sustained compliance posture
- Identify and escalate potential compliance gaps or control deficiencies
Stakeholder Coordination
- Work with internal teams (IT, Security, Operations, Product, Engineering) to collect evidence and resolve compliance issues
- Follow up on remediation actions and track progress to closure
- Support communication of PCI requirements and expectations across business units
Documentation & Reporting
- Maintain organized repository of PCI Compliance evidence
- Assist in generating regular compliance reports, dashboards, and metrics
- Support audit documentation and responses to Qualified Security Assessor (QSA) inquiries
Continuous Improvement & Readiness
- Contribute to initiatives that enhance automation, efficiency, and scalability of PCI processes
- Support efforts to transition from reactive compliance to proactive risk management
- Stay current on PCI DSS updates (e.g., PCI DSS v4.0) and evolving security practices
What Are We Looking For in This Role?
Minimum Qualifications
- Bachelor’s degree in information security, Cybersecurity, IT, Risk Management, or related field (or equivalent experience)
- 4–6 years of experience in IT, security, risk, compliance, or audit (internships or academic projects acceptable)
- Strong attention to detail and organizational skills
- Good written and verbal communication skills
- Ability to follow established processes and procedures
Preferred Qualifications
- Basic understanding of PCI DSS or payment card industry concepts
- Exposure to information security principles (e.g., access control, encryption, logging)
- Familiarity with risk and control frameworks (e.g., ISO 27001, NIST)
- Experience working with documentation, evidence collection, or audit support activities
- Proficiency in Excel and/or data tracking tools
What Are Our Desired Skills and Capabilities?
- Execution Discipline: Ability to follow structured processes in a controlled environment
- Curiosity & Learning Mindset: Interest in developing expertise in payment security and compliance
- Collaboration: Works effectively with global and cross-functional teams
- Accountability: Takes ownership of assigned tasks and follows through to completion
- Risk Awareness: Understands the importance of controls in protecting sensitive payment data
- Skills / Knowledge: Developing professional expertise, applies company policies and procedures to resolve a variety of issues
- Job Complexity: Works on problems of moderate scope where analysis of situations or data requires a review of a variety of factors. Exercises judgment within defined procedures and practices to determine appropriate action. Builds productive internal/external working relationships.
- Supervision: Determines methods and procedures on new assignments and may coordinate activities of other personnel