обновлено 1 час назад
Principal Specialist, PCI DSS Compliance
225 400 - 354 200PLN
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Principal Specialist, PCI DSS Compliance (Cybersecurity and IT Governance): Managing HARMAN’s PCI DSS compliance program, audit readiness, risk assessments, remediation, and IT governance across in-scope environments with an accent on secure payment processes, cloud security, and risk-based controls. Focus on leading PCI DSS assessments, designing ITGC frameworks, validating remediation, and coordinating internal, external, and (K)SOX audits.
Location: Lodz, Poland; hybrid work with onsite attendance three days per week. Domestic and international travel of up to 5% may be required.
Salary: PLN 225,400–354,200 gross annually.
Company
develops connected technology solutions across automotive, lifestyle, and digital transformation markets under brands including JBL, Kardon, AKG, and Mark Levinson.
What you will do
- Facilitate the global PCI DSS compliance program across environments.
- Conduct PCI DSS gap assessments and risk evaluations, then define remediation priorities.
- Enhance PCI DSS governance through control frameworks, policies, procedures, and documentation.
- Lead internal and external PCI DSS assessments and act as the primary liaison for Qualified Security Assessors.
- Coordinate remediation of PCI findings, validate closure, and advise business, IT, and product teams on secure payment controls.
- Maintain IT governance and ITGC control frameworks and support internal, external, and (K)SOX audits from a second-line perspective.
Requirements
- Bachelor’s or Master’s degree in information security, IT, or a related field.
- At least 5 years of experience in cybersecurity, risk, or compliance roles.
- Strong hands-on experience with PCI DSS and proven experience managing audits and remediation programs.
- Strong understanding of cloud environments, network security and segmentation, identity and access management, encryption, and key management.
- Effective English communication skills in reading, writing, and speaking.
- Baseline familiarity with using AI for efficiency, problem-solving, and quality improvement.
Nice to have
- CISSP, CISM, CISA, ISO 27001 LI/LA, PCIP, or ISA certification.
- Experience with payment gateways, tokenization solutions, or e-commerce platforms.
- Experience in a global enterprise with distributed environments.
- Ability to translate regulatory requirements into actionable technical controls and drive compliance programs end to end.
Culture & Benefits
- Hybrid work environment balancing flexibility with in-person collaboration.
- Employee discounts on and Samsung products.
- Learning and development through University programs.
- Inclusive and diverse environment supporting professional and personal development.
- Paid time off, holidays, leave, health and wellbeing support, and retirement or savings plans may be available depending on local arrangements.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
3 дня назад
Senior Information Security Infrastructure Engineer - Security Architecture - InfoSec
307 800 - 485 000PLN
10 часов назад
Cybersecurity Risk Analyst (iGaming)
12 часов назад
Security Architect (Cybersecurity)
5 дней назад
Cybersecurity Data Analytics Engineer
3 дня назад
Junior Cybersecurity Analyst
Okta
4 дня назад
Senior Solutions Engineer (Identity Security)
330 000 - 484 000PLN