Эта вакансия в архиве

Посмотреть похожие вакансии ↓
Company hidden
обновлено 14 дней назад

Senior Security Compliance Analyst - PCI DSS & U.S. Fed

119 078 - 174 648$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US

Описание вакансии

Текст:
/
TL;DR
Senior Security Compliance Analyst - PCI DSS & U.S. Fed (PCI DSS, NIST 800-53, FedRAMP): Leading continuous compliance monitoring, audit readiness, control testing, and remediation across cloud-based, on-premises, and hybrid environments with an accent on PCI DSS, U.S. Federal compliance, and evidence-driven GRC operations. Focus on designing actionable controls, coordinating third-party audits, developing FedRAMP artifacts, and closing control deficiencies across engineering and infrastructure teams.

Location: Fully remote for U.S.-based candidates; the primary posting location is Shakopee, Minnesota. No relocation.

Salary: $119,078–$174,648 per year, plus eligibility for an annual discretionary incentive plan.

Company

hirify.global provides identity-centric security solutions and technologies for government agencies, enterprises, and financial institutions in more than 150 countries.

What you will do

  • Lead PCI DSS compliance activities, certification efforts, readiness assessments, audits, and continuous monitoring.
  • Support U.S. Federal compliance readiness through NIST SP 800-53 gap assessments, POA&M tracking, and FedRAMP documentation.
  • Maintain evidence artifacts, ensure traceability, and measure control effectiveness across cloud, on-premises, and hybrid environments.
  • Translate compliance requirements into actionable controls for engineering, infrastructure, and operations teams.
  • Coordinate external audits, third-party service providers, control owners, and auditor requests.
  • Identify compliance risks, track findings, and drive remediation and closure of control deficiencies.

Requirements

  • 5+ years of experience in security compliance, audit, or GRC.
  • Hands-on experience with PCI DSS and NIST 800-53 compliance.
  • Strong understanding of administrative, technical, and physical security controls.
  • Knowledge of cloud environments, shared responsibility models, access control, change management, logging, alerting, and vulnerability management.
  • Experience in SaaS or cloud-native environments and collaboration with engineering and infrastructure teams.
  • Must be based in the United States; ability to work across multiple time zones with virtual global teams is required.

Nice to have

  • Experience with PCI CP, SOC 2, FedRAMP, FISMA, ISO 27001/2, or ISO 42001.
  • Experience with modern GRC platforms, control automation, and continuous compliance models.
  • CISSP, CISA, CISM, CRISC, PCI ISA, QSA, or PCI CP certification.

Culture & Benefits

  • Remote and flexible work options with a collaborative global workplace.
  • Career growth initiatives, learning opportunities, and education reimbursement.
  • Medical, vision, dental, life, and disability insurance.
  • 401(k) matching, paid personal time off, 12 paid holidays, and parental leave.
  • Mental health coaching, virtual fitness programs, diversity initiatives, and global affinity groups.