Back to List

The Payment Security & Compliance Engineer is responsible for ensuring the security, compliance, and integrity of products and services, including IoT devices, payment applications, and terminal management systems. This role requires expertise in the Payment Card Industry Data Security Standard (PCI DSS), security best practices, and addressing the specific challenges of the payment industry. The engineer will collaborate with cross-functional teams, including IT, development, compliance, and operations, to implement, maintain, and enforce security measures, address customer security concerns, and ensure adherence to regulatory requirements.

 

What You Wil Do:
  • Lead efforts to implement processes and controls that mitigate security risks and ensure compliance with PCI DSS and related security standards.
  • Act as the primary point of contact for security compliance inquiries, providing guidance on how products meet industry standards such as PCI PTS, PTS PIN, PCI DSS, PCI-SSS, and PCI-P2PE.
  • Provide expert consulting to merchants undergoing security assessments, audits, and forensic investigations, offering guidance throughout the entire process.
  • Identify, manage, and safeguard sensitive and confidential information, ensuring compliance with security requirements.
  • Provide legal guidance on contract language related to security and compliance obligations, particularly focusing on managing legal risks and liabilities, especially in the event of a data breach.
  • Educate internal stakeholders on forensic processes, security best practices, and potential risks that could lead to data compromises, ensuring teams are aware of vulnerabilities and necessary preventative measures.

 

What You Bring:

  • Bachelor’s degree in computer science, information security, or a related field.
  • At least five years of experience in information security engineering, with a focus on payment card industry security.
  • Relevant certifications such as PCI DSS (e.g., PCI DSS Qualified Security Assessor (QSA), CISSP, CISM), or similar.
  • Experience with vulnerability assessments, penetration testing, incident response, and implementing effective mitigation strategies.
  • Proficiency in network security, cryptography, and access control systems.
  • Proven experience conducting security assessments, audits, and forensic investigations.
  • Strong ability to communicate complex security concepts and compliance requirements clearly to both internal teams and external clients.
Apply to this Job
First Name *
Last Name *
Email

Phone

Yes
No