Эта вакансия в архиве
Посмотреть похожие вакансии ↓обновлено 14 дней назад
Senior Security Compliance Analyst - PCI DSS & U.S. Fed
119 078 - 174 648$
Описание вакансии
Текст:
TL;DR
Senior Security Compliance Analyst - PCI DSS & U.S. Fed (PCI DSS, NIST 800-53, FedRAMP): Leading continuous compliance monitoring, audit readiness, control testing, and remediation across cloud-based, on-premises, and hybrid environments with an accent on PCI DSS, U.S. Federal compliance, and evidence-driven GRC operations. Focus on designing actionable controls, coordinating third-party audits, developing FedRAMP artifacts, and closing control deficiencies across engineering and infrastructure teams.
Location: Fully remote for U.S.-based candidates; the primary posting location is Shakopee, Minnesota. No relocation.
Salary: $119,078–$174,648 per year, plus eligibility for an annual discretionary incentive plan.
Company
provides identity-centric security solutions and technologies for government agencies, enterprises, and financial institutions in more than 150 countries.
What you will do
- Lead PCI DSS compliance activities, certification efforts, readiness assessments, audits, and continuous monitoring.
- Support U.S. Federal compliance readiness through NIST SP 800-53 gap assessments, POA&M tracking, and FedRAMP documentation.
- Maintain evidence artifacts, ensure traceability, and measure control effectiveness across cloud, on-premises, and hybrid environments.
- Translate compliance requirements into actionable controls for engineering, infrastructure, and operations teams.
- Coordinate external audits, third-party service providers, control owners, and auditor requests.
- Identify compliance risks, track findings, and drive remediation and closure of control deficiencies.
Requirements
- 5+ years of experience in security compliance, audit, or GRC.
- Hands-on experience with PCI DSS and NIST 800-53 compliance.
- Strong understanding of administrative, technical, and physical security controls.
- Knowledge of cloud environments, shared responsibility models, access control, change management, logging, alerting, and vulnerability management.
- Experience in SaaS or cloud-native environments and collaboration with engineering and infrastructure teams.
- Must be based in the United States; ability to work across multiple time zones with virtual global teams is required.
Nice to have
- Experience with PCI CP, SOC 2, FedRAMP, FISMA, ISO 27001/2, or ISO 42001.
- Experience with modern GRC platforms, control automation, and continuous compliance models.
- CISSP, CISA, CISM, CRISC, PCI ISA, QSA, or PCI CP certification.
Culture & Benefits
- Remote and flexible work options with a collaborative global workplace.
- Career growth initiatives, learning opportunities, and education reimbursement.
- Medical, vision, dental, life, and disability insurance.
- 401(k) matching, paid personal time off, 12 paid holidays, and parental leave.
- Mental health coaching, virtual fitness programs, diversity initiatives, and global affinity groups.