cybersecurity analyst senior, PCI compliance

Starbucks

Seattle (WA)

On-site

USD 140,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, vision insurance
401(k) with employer match
Bean Stock equity program
Tuition coverage through Starbucks ACH

Job summary

Starbucks Technology is seeking a Senior Cybersecurity Analyst focused on PCI DSS v4.0 to design, validate, and automate controls across payment environments. You will translate PCI requirements into practical engineering patterns, reducing risk and minimizing scope, partnering with architecture, infrastructure, applications, and platform teams.

You will lead PCI scoping and segmentation, implement encryption and tokenization patterns, and support GRC capabilities including automation,

Qualifications

  • Bachelor's degree in computer science, information systems, cybersecurity, engineering, or a related field, or 3+ years of relevant experience in cybersecurity, infrastructure, application, cloud, compliance automation, or technology risk roles.
  • Translate business, technology, and compliance objectives into practical technical requirements, implementation guidance, and control outcomes across cross-functional engineering and risk activities.
  • Apply analytical and problem-solving skills to evaluate system designs, data flows, control evidence, root causes, and remediation options in complex technology environments.
  • Create clear technical documentation, including data-flow narratives, control evidence, implementation guidance, process documentation, and materials that help engineering teams understand and meet PCI requirements.
  • Familiarity with payment ecosystems (processors, tokenization).
  • Exhibit exceptional oral and written interpersonal and communication skills.
  • Experience with Microsoft Office products such as Word and Excel.
  • Apply a deep understanding of business processes and process improvement initiatives.
  • Provide top-tier customer service.
  • Apply systems development concepts, including requirements analysis, design review, testing, release practices, defect management, and operational readiness, to ensure PCI controls are embedded into technology delivery.
  • Proven working knowledge of systems development lifecycle and IT operations.
  • Ability to use business knowledge, sound judgment, and resourcefulness to design and deploy highly reliable and sustainable technology solutions.
  • Ability to balance multiple priorities and meet deadlines.
  • Configuration knowledge of relevant applications/modules/platforms.

Responsibilities

  • Lead technical PCI architecture reviews by evaluating segmentation models, network paths, trust boundaries, service-to-service interactions, cloud and hybrid connectivity, and system components that store, process, transmit, or could impact cardholder data.
  • Provide technical guidance on encryption for data at rest and in transit, tokenization, certificate and key management, cryptographic control design, and implementation patterns that satisfy PCI requirements without adding unnecessary scope or operational friction.
  • Lead PCI scoping by validating data-flow diagrams, payment transaction paths, CHD lifecycle stages, connected systems, compensating controls, and segmentation assumptions across applications, infrastructure, networks, cloud platforms, and third-party integrations.
  • Identify opportunities to eliminate or reduce cardholder data storage and shrink PCI scope.
  • Translate PCI DSS requirements into technical requirements and control implementations.
  • Support PCI assessments (QSA-facing), including evidence validation, control testing, and remediation planning.
  • Design and maintain risk and control matrices aligned to PCI and enterprise standards.
  • Track remediation, risk acceptance, and exceptions with stakeholders.
  • Provide guidance on use of compliance and risk management tools and processes.
  • Develop documentation and training for compliance processes and tooling.
  • Design and build automated approaches for continuous PCI control validation and evidence collection, using integrations, APIs, data models, workflow automation, and telemetry from security, infrastructure, cloud, and GRC/IRM platforms.
  • Develop metrics, dashboards, and control-health views that use system data and control telemetry to show PCI coverage, remediation status, exception trends, and risk exposure.
  • Gather, analyze, and document solution requirements. Facilitate user story creation and backlog grooming in an agile delivery environment
  • Utilize agile delivery methodologies and participates on scrum teams to deliver on projects
  • Effectively assess overall improvement opportunities (productivity/efficiency gains, cost savings, etc.)
  • Partner with engineering teams to embed PCI requirements into system design
  • Provide guidance aligned to policies, standards, and risk reduction
  • Develop reusable templates, documentation, and training
  • Support delivery of compliance capabilities and program metrics (KPIs)
  • Self-directed; is successful with minimal direction from more senior analysts providing escalation when necessary

Skills

PCI DSS
Cybersecurity
Network security
Cloud security
Risk assessment
Automation
Documentation
Stakeholder communication

Education

Bachelor's degree in computer science, information systems, cybersecurity, or engineering

Tools

GRC platforms

Job description

Now Brewing - cybersecurity analyst senior, PCI compliance! #tobeapartner

This role supports Starbucks Technology as a technical PCI DSS v4.0 SME, partnering with architecture, infrastructure, application, and platform teams to design, validate, and automate controls across payment environments. The role combines hands-on understanding of network architecture, segmentation, encryption, data flows, and cardholder data environment (CDE) scoping with the ability to translate PCI requirements into practical engineering patterns to reduce risk and minimize compliance scope. The cybersecurity analyst sr partners with engineering teams to design and validate solutions that meet PCI requirements while minimizing scope. This role leads PCI scoping and segmentation efforts, translates requirements into technical implementations, and supports GRC capabilities including automation, continuous monitoring, and evidence orchestration. Operates independently to identify risks and drive cross-functional improvements.

PCI Architecture & Engineering
  • Lead technical PCI architecture reviews by evaluating segmentation models, network paths, trust boundaries, service-to-service interactions, cloud and hybrid connectivity, and system components that store, process, transmit, or could impact cardholder data.
  • Provide technical guidance on encryption for data at rest and in transit, tokenization, certificate and key management, cryptographic control design, and implementation patterns that satisfy PCI requirements without adding unnecessary scope or operational friction.
  • Lead PCI scoping by validating data-flow diagrams, payment transaction paths, CHD lifecycle stages, connected systems, compensating controls, and segmentation assumptions across applications, infrastructure, networks, cloud platforms, and third-party integrations.
  • Identify opportunities to eliminate or reduce cardholder data storage and shrink PCI scope
Compliance Program Operations
  • Translate PCI DSS requirements into technical requirements and control implementations
  • Support PCI assessments (QSA-facing), including evidence validation, control testing, and remediation planning
  • Design and maintain risk and control matrices aligned to PCI and enterprise standards
  • Track remediation, risk acceptance, and exceptions with stakeholders
  • Provide guidance on use of compliance and risk management tools and processes
  • Develop documentation and training for compliance processes and tooling
Solution Design and Automation
  • Design and build automated approaches for continuous PCI control validation and evidence collection, using integrations, APIs, data models, workflow automation, and telemetry from security, infrastructure, cloud, and GRC/IRM platforms.
  • Develop metrics, dashboards, and control-health views that use system data and control telemetry to show PCI coverage, remediation status, exception trends, and risk exposure.
  • Gather, analyze, and document solution requirements. Facilitate user story creation and backlog grooming in an agile delivery environment
  • Utilize agile delivery methodologies and participates on scrum teams to deliver on projects
  • Effectively assess overall improvement opportunities (productivity/efficiency gains, cost savings, etc.)
Collaboration & Delivery
  • Partner with engineering teams to embed PCI requirements into system design
  • Provide guidance aligned to policies, standards, and risk reduction
  • Develop reusable templates, documentation, and training
  • Support delivery of compliance capabilities and program metrics (KPIs)
  • Self-directed; is successful with minimal direction from more senior analysts providing escalation when necessary
Basic Qualifications
  • Bachelor's degree in computer science, information systems, cybersecurity, engineering, or a related field, or 3+ years of relevant experience in cybersecurity, infrastructure, application, cloud, compliance automation, or technology risk roles.
  • Translate business, technology, and compliance objectives into practical technical requirements, implementation guidance, and control outcomes across cross-functional engineering and risk activities.
  • Apply analytical and problem-solving skills to evaluate system designs, data flows, control evidence, root causes, and remediation options in complex technology environments.
  • Create clear technical documentation, including data-flow narratives, control evidence, implementation guidance, process documentation, and materials that help engineering teams understand and meet PCI requirements.
  • Familiarity with payment ecosystems (processors, tokenization)
  • Exhibit exceptional oral and written interpersonal and communication skills.
  • Experience Microsoft Office products such as Word and Excel proficiently.
  • Apply a deep understanding of business processes and process improvement initiatives.
  • Provide top-tier customer service.
  • Apply systems development concepts, including requirements analysis, design review, testing, release practices, defect management, and operational readiness, to ensure PCI controls are embedded into technology delivery.
  • Proven working knowledge of systems development lifecycle and IT operations.
  • Ability to use business knowledge, sound judgment, and resourcefulness to design and deploy highly reliable and sustainable technology solutions.
  • Ability to balance multiple priorities and meet deadlines.
  • Configuration knowledge of relevant applications/modules/platforms.
Preferred Qualifications
  • 3+ years of progressive industry experience in Information Risk Management, IT Governance, IT Compliance, Compliance Engineering, Data Privacy or Internal/External Technology Audit disciplines, with at least two of those years in an IT or a software development setting.
  • Experience in cybersecurity, network security, or cloud security, with direct exposure to PCI DSS environments
  • Strong understanding of network architecture, cloud security design, encryption protocols
  • Direct experience supporting PCI DSS assessments (QSA-facing)
  • Experience designing or validating CDE segmentation in cloud and hybrid environments
  • Exposure to Common Control Framework (CCF) practices with knowledge and ability to track common control requirements across numerous security and regulatory standards
  • Ability to influence technical and business stakeholders in complex environments
  • Certifications such as PCI QSA/ISA, PCIP, CISA, CISSP, CISM, CIPM or others focused on controls assurance, information security, data privacy or information risk management is a strong plus
  • Hands on experience in developing roadmaps, story outlines, writing user stories, refining product backlogs, and coordinating/prioritizing conflicting requirements across teams in a fast-paced, changing environment
  • Experience in engineering and/or platform role for GRC solutions and/or cybersecurity risk management solutions.

As a Starbucks partner, you (and your family) will have access to medical, dental, vision, basic and supplemental life insurance, and other voluntary insurance benefits. Partners have access to short-term and long-term disability, paid parental leave, family expansion reimbursement, paid vacation from date of hire*, sick time (accrued at 1 hour for every 25 hours worked), eight paid holidays, and two personal days per year. Starbucks also offers eligible partners participation in a 401(k) retirement plan with employer match, a discounted company stock program (S.I.P.), Starbucks equity program (Bean Stock), incentivized emergency savings, and financial well-being tools. Additionally, Starbucks offers 100% upfront tuition coverage for a first-time bachelor’s degree through Arizona State University’s online program via the Starbucks College Achievement Plan, student loan management resources, and access to other educational opportunities. You will also have access to backup care and DACA reimbursement. Starbucks will comply with any applicable state and local laws regarding employee leave benefits, including, but not limited to providing time off pursuant to the Colorado Healthy Families and Workplaces Act, and in accordance with its plans and policies. This list is subject to change depending on collective bargaining in locations where partners have a certified bargaining representative. For additional information regarding partner perks and more detailed information about benefits, go to starbucksbenefits.com.

  • If you are working in CA, CO, IL, LA, ME, MA, NE, ND or RI, you will accrue vacation up to a maximum of 120 hours (190 in CA) for roles below director and 200 hours (316 in CA) for roles at director or above. For roles in other states, you will be granted vacation time starting at 120 hours annually for roles below director and 200 hours annually for roles director and above.

The actual base pay offered to the successful candidate will be based on multiple factors, including but not limited to job-related knowledge/skills, experience, geographical location, and internal equity. At Starbucks, it is not typical for an individual to be hired at the high end of the range for their role, and compensation decisions are dependent upon the facts and circumstances of each position and candidate.

We believe we do our best work when we're together, which is why we're onsite four days a week.

Join us and inspire with every cup.

Starbucks Coffee Company is an equal opportunity employer. All qualified applicantswill receive considerationfor employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, orprotectedveteran status,or any other characteristic protected by law.

Qualified applicants with criminal histories will be considered for employment in a manner consistent with all federal, state and local ordinances.

Starbucks Coffee Company is committed to offering reasonableaccommodations to job applicants with disabilities. If you need assistance or an accommodation due to a disability, please contact us at applicantaccommodation or 1(888) 611-2258.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Systems analyst ll - onsite and executive technology support (Nashville, TN)
Systems analyst ll - onsite and executive technology support (Nashville, TN)

Starbucks Coffee Company • Nashville (TN)

On-site
USD 70,000 - 95,000
Medical insurance
Dental insurance
Vision insurance
+3
data engineer sr- ST; Seattle, WA
data engineer sr- ST; Seattle, WA

Starbucks • Seattle (WA)

On-site
USD 140,000 - 180,000
Medical, dental, vision insurance
Life insurance
Disability insurance
+4
software engineer- ST, Cloud Foundation Services, Seattle, WA
software engineer- ST, Cloud Foundation Services, Seattle, WA

Starbucks • Seattle (WA)

On-site
USD 140,000 - 190,000
Medical benefits
401(k) retirement plan
Starbucks equity program
+1
store manager - Waterbury CT
store manager - Waterbury CT

Starbucks • Waterbury (CT)

On-site
USD 21,000 - 26,000
Health insurance
Dental insurance
Vision insurance
+9
store manager, Huntsville/Madison AL
store manager, Huntsville/Madison AL

Starbucks • Madison (AL)

On-site
USD 32,000 - 52,000
Medical insurance
Dental insurance
Vision insurance
+8
Systems analyst ll - onsite and executive technology support (Nashville, TN)
Systems analyst ll - onsite and executive technology support (Nashville, TN)

Starbucks • Nashville (TN)

On-site
USD 65,000 - 95,000
Medical, dental, vision insurance
Tuition assistance
Paid time off and holidays
+1
business analysis manager, Corporate Financial Planning and Analysis
business analysis manager, Corporate Financial Planning and Analysis

Starbucks • Seattle (WA)

On-site
USD 140,000 - 190,000
Medical insurance
Dental insurance
Vision insurance
+2
senior accountant, International & Channel Development Accounting
senior accountant, International & Channel Development Accounting

Starbucks • Seattle (WA)

On-site
USD 90,000 - 130,000
Medical benefits
401(k) match
Tuition coverage
ioT engineer senior, Seattle WA
ioT engineer senior, Seattle WA

Starbucks • Seattle (WA)

On-site
USD 140,000 - 180,000
Medical, Dental, Vision
401(k) matching
Tuition coverage
+2
store manager, Pikeville, KY
store manager, Pikeville, KY

Starbucks • Pikeville (KY)

On-site
USD 42,000 - 56,000
Medical insurance
Dental insurance
Vision insurance
+7