PCI Internal Security Assessor (ISA) - Caribbean

Visa Hunt

Netherlands

On-site

EUR 70,000 - 100,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Visa Hunt in the Netherlands is seeking a PCI Internal Security Assessor (ISA) to help our banking client maintain PCI DSS compliance across systems and processes. The role collaborates with internal teams and external QSAs to enhance security and reduce risk.

The ISA will conduct regular assessments, develop policies, manage SAQs/AOCs, and provide training on PCI requirements. A strong background in information security and PCI programs is required.

Qualifications

  • Bachelor’s degree in Information Security, Computer Science, or related field, or equivalent work experience.
  • 3–5 years of experience in information security, PCI compliance, or related field.
  • Certified PCI ISA or PCIP preferred; CISSP/CISM/CISA/CEH are a plus.

Responsibilities

  • Conduct regular internal PCI DSS assessments and audits.
  • Develop and implement PCI compliance policies, procedures, and controls.
  • Serve as internal PCI DSS point of contact and coordinate with the external QSA.
  • Prepare and maintain documentation and reports for PCI DSS compliance.
  • Manage SAQs and Attestation of Compliance documents.

Skills

PCI DSS
Security frameworks
Risk assessment
Communication

Education

Bachelor’s degree in Information Security or related field

Tools

Vulnerability scanners
SIEM

Job description

Job Description: PCI Internal Security Assessor (ISA)

Department: Enterprise Security & Technology Risk Management Location: Regionwide

Reports To: Chief Information Security Officer (CISO)

Employment Type: Full-time
Job Overview

The PCI Internal Security Assessor (ISA) is responsible for ensuring that our client from banking industry complies with the Payment Card Industry Data Security Standard (PCI DSS). The ISA will assess, monitor, and enforce the security measures necessary to protect cardholder data and maintain PCI compliance across all systems and processes. This role works closely with internal stakeholders and external parties to maintain a secure environment, mitigate risks, and improve overall security posture.

Key Responsibilities:
  • PCI DSS Compliance Management:
    • Conduct regular internal assessments and audits to ensure the organization's compliance with PCI DSS.

Develop and implement PCI compliance policies, procedures, and controls.

  • Serve as the internal point of contact for PCI DSS-related matters and ensure all applicable security controls are in place.
  • Collaborate with the external Qualified Security Assessor (QSA) to facilitate annual PCI DSS certification audits.
Documentation and Reporting:
  • Prepare and maintain comprehensive documentation, including policies, procedures, and reports required for PCI DSS compliance.
  • Maintain comprehensive documentation of assessment findings, corrective actions, and compliance status.
  • Manage the submission of the Self-Assessment Questionnaires (SAQs) and Attestation of Compliance documents (AOCs) as needed.
Qualifications:
Education:
  • Bachelor’s degree in Information Security, Computer Science, or a related field (or
equivalent work experience).
  • Experience:
    • Minimum of 3-5 years of experience in information security, PCI compliance, or a related field.
    • Previous experience as an ISA, QSA, or a similar role is highly desirable.
  • Certifications:
    • Certified PCI Internal Security Assessor (ISA) or Certified PCI Professional (PCIP) certifications preferred.

Additional certifications such as CISSP, CISM, CISA, or CEH are a plus.

  • Skills and Competencies:
    • Deep understanding of PCI DSS requirements and data security best practices.
    • Familiarity with security frameworks (NIST, ISO 27001, CIS Controls) and security technologies (firewalls, IDS/IPS, encryption, etc.).
    • Strong analytical, problem-solving, and project management skills.
    • Excellent communication and interpersonal skills with the ability to work cross- functionally.
    • Proficiency in using security assessment tools and techniques (e.g., vulnerability scanners, SIEM).
Other Requirements:

Ability to work independently and handle sensitive information confidentially.

  • Detail-oriented with strong organizational skills.
  • Occasional travel may be required for audits or compliance reviews.
  • Risk Assessment and Mitigation:
    • Identify and assess potential risks to cardholder data environments and provide recommendations for risk mitigation.
    • Implement and enforce necessary security controls to address gaps identified during assessments.
    • Ensure vulnerability scanning, penetration testing, and security reviews are conducted to identify weaknesses and ensure continuous compliance.
  • Training and Awareness:
    • Conduct internal PCI DSS training for staff to ensure a deep understanding of the importance of compliance and security measures.
    • Provide ongoing guidance and support to departments regarding security best practices related to PCI DSS.
  • Collaboration and Communication:
    • Work closely with projects, Enterprise Security, Technology, and other relevant departments to align PCI DSS compliance with overall security policies and practices.
    • Proactively identify and/or promptly escalation risks and issues affecting PCI compliance status.
    • Stay updated on changes in PCI DSS requirements and industry best practices to ensure our client from banking industry remains compliant.
    • Present PCI DSS compliance status reports to senior management and external stakeholders.
    • Act as a liaison where necessary between our client from banking industry and external vendors or service providers involved in processing or storing cardholder data.

Originally posted on Himalayas

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Caribbean PCI ISA: Lead Cardholder Data Security
Caribbean PCI ISA: Lead Cardholder Data Security

Visa Hunt • Netherlands

On-site
EUR 70,000 - 100,000
Senior Security Expert
Senior Security Expert

Adyen • Amsterdam

On-site
EUR 70,000 - 100,000
Senior Security Certification Expert
Senior Security Certification Expert

Adyen • Amsterdam

On-site
EUR 70,000 - 90,000
Senior Security Certifications Expert
Senior Security Certifications Expert

Adyen • Amsterdam

On-site
EUR 70,000 - 90,000
PCI PTS Security Evaluator
PCI PTS Security Evaluator

SGS • Delft

On-site
EUR 60,000 - 80,000
Security Engineer
Security Engineer

Keysight Technologies, Inc. • Netherlands

On-site
EUR 55,000 - 75,000
Senior Cyber Security Internal Auditor
Senior Cyber Security Internal Auditor

SITA • Rotterdam

Hybrid
EUR 65,000 - 90,000
Flex Week
Flex Day
Flex-Location
+3
(Senior) Information Security Risk Manager
(Senior) Information Security Risk Manager

Care Professionals • Amsterdam, Utrecht

On-site
EUR 90,000 - 130,000
iOS (Senior) Mobile Security Analyst
iOS (Senior) Mobile Security Analyst

Keysight Technologies • Delft

On-site
EUR 70,000 - 110,000
Senior PCI Certifications & Security Lead
Senior PCI Certifications & Security Lead

Adyen • Amsterdam

On-site
EUR 70,000 - 100,000