PCI DSS SAQ D Service Provider Lead

FYI - For Your Information, Inc.

Silver Spring (MD)

Hybrid

USD 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work schedule
Competitive salary with benefits package
Tuition/education assistance
Pet insurance

Job summary

FYI - For Your Information, Inc. is seeking a PCI DSS SAQ D Service Provider Lead to manage PCI compliance effectively. This senior role requires extensive experience in cybersecurity and PCI assessments, where the right candidate will handle evidence review, control interpretation, and compliance management in a hybrid work setup.

The position offers a competitive salary and a robust benefits package, including tuition assistance and a pet insurance plan.

Qualifications

  • 8+ years of experience in cybersecurity, GRC, IT audit, or related fields.
  • Hands-on experience with PCI DSS assessments.
  • Familiarity with SaaS and cloud-hosted environments.

Responsibilities

  • Support PCI DSS SAQ D Service Provider readiness and scoping.
  • Review and coordinate evidence for PCI assessments.
  • Communicate compliance progress and blockages to stakeholders.

Skills

Cybersecurity
GRC
IT audit
Compliance
Security consulting

Tools

ASV scanning
Vulnerability scanning
Penetration testing tools
Drata
AWS

Job description

FYI - For Your Information, Inc. is an SBA certified, Woman-Owned Small Business and GSA schedule holder that is a premier provider of Human Capital, Training, and Information Technology services. We have won awards for being a Great Place to Work and continue to make ground-breaking advancements. For four years in a row, we have been on Inc. Magazine's 5000 list and were recently named one of Inc.'s 2024 Mid-Atlantic Fastest Growing companies.

About the role

FYI is seeking a PCI DSS SAQ D Service Provider Lead to support an active PCI compliance program for a SaaS/cloud/payment-adjacent environment. This role will own the PCI domain in a fractional capacity, including PCI scoping support, evidence sufficiency review, quarterly scan cadence, penetration testing evidence, remediation tracking, and responses to auditors, QSAs, processors, banks, or other requesting entities. The right candidate has done this work before and can drive their lane without constant prompting.

Essential responsibilities and duties
  • Support PCI DSS SAQ D Service Provider readiness, scoping, evidence review, and control interpretation.
  • Review PCI scope assumptions, in-scope systems, applications, integrations, service providers, and payment/data-flow considerations.
  • Coordinate and review evidence for quarterly external ASV scans and internal vulnerability scans.
  • Coordinate PCI-relevant penetration testing evidence, including scope, rules of engagement, final report review, remediation, and retest evidence.
  • Review evidence for file integrity monitoring, encryption, MFA, IAM, logging, monitoring, change control, secure development, vulnerability management, and remediation tracking where relevant to PCI DSS.
  • Identify weak, incomplete, stale, unclear, or nonresponsive evidence before submission.
  • Draft or review PCI-related auditor, QSA, processor, or requesting-entity responses.
  • Support tracking of PCI remediation items, exceptions, compensating-control discussions, and risk acceptance needs.
  • Help define and maintain recurring PCI compliance cadence, including quarterly scans and annual validation activities.
  • Provide concise written status updates, blockers, risks, and next actions to the project manager and CISO/vCISO.
Required qualifications
  • 8+ years of cybersecurity, GRC, IT audit, compliance, security consulting, or related experience.
  • Direct hands-on experience supporting PCI DSS assessments.
  • Direct experience with PCI DSS SAQ D; Service Provider experience is strongly preferred.
  • Experience with SaaS, cloud-hosted, fintech, payment, or payment-adjacent environments.
  • Working knowledge of ASV scanning, internal vulnerability scanning, penetration testing evidence, vulnerability remediation, IAM/MFA, encryption, logging, monitoring, FIM, change control, and secure development requirements.
  • Ability to translate PCI requirements into practical tasks for engineering, IT, security, and business stakeholders.
  • Strong written communication skills and ability to produce audit-ready summaries and responses.
  • Ability to work through ambiguity and distinguish sufficient evidence from weak or incomplete evidence.
Nice to have
  • Prior QSA, ISA, or QSA-firm experience.
  • PCI DSS v4.x experience.
  • CISA, CISSP, CISM, Security+, or equivalent certification.
  • Experience with Drata, Vanta, Secureframe, Hyperproof, Jira, Confluence, AWS, Azure, GCP, or similar platforms.
  • SOC 2 familiarity, especially where controls overlap with PCI DSS.
Expected deliverables
  • PCI DSS SAQ D evidence and gap tracker inputs.
  • PCI scope notes, assumptions, and issue summaries.
  • ASV and internal vulnerability scan evidence checklists.
  • Penetration testing evidence checklist and report sufficiency review notes.
  • PCI remediation tracker updates and risk summaries.
  • PCI auditor/requesting-entity response drafts.
  • PCI quarterly and annual compliance calendar inputs.
Operating style required

This role requires a senior operator who can own the PCI lane in a fractional capacity. The contractor must communicate clearly, document next actions, identify blockers early, and coordinate through the project manager. This is not a casual side task. Responsiveness, ownership, and clean written work product are required.

FYI's Benefits/Incentives: What is in it for you?
  • Opportunity to work a hybrid work schedule
  • A knowledgeable, high-achieving, diverse, experienced, and fun team.
  • The chance to be part of a rapidly growing company and the next success story.
  • A competitive base salary with a loaded benefits package plus 401K.
  • Tuition/education assistance, personal computer allowance, pet insurance.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior PCI DSS SAQ D Lead for SaaS & Cloud
Senior PCI DSS SAQ D Lead for SaaS & Cloud

FYI - For Your Information, Inc. • Silver Spring (MD)

Hybrid
USD 90,000 - 120,000
Hybrid work schedule
Competitive salary with benefits package
Tuition/education assistance
+1
REMOTE PCI Qualified Security Assessor (QSA)
REMOTE PCI Qualified Security Assessor (QSA)

Insight Global • Hoover (AL)

Remote
USD 120,000 - 180,000
Senior PCI Analyst
Senior PCI Analyst

CSI • United States

On-site
USD 80,000 - 120,000
Consultant- PCI
Consultant- PCI

Cdw • Atlanta (GA)

On-site
USD 100,000 - 140,000
Security & Compliance Analyst
Security & Compliance Analyst

OTG • New York (NY)

Remote
USD 90,000 - 110,000
Contract to Hire_ PCI Compliance Consultant
Contract to Hire_ PCI Compliance Consultant

360 IT Professionals • Woonsocket (RI)

On-site
USD 80,000 - 110,000
Information Security Analyst
Information Security Analyst

Arbure Inc. • United States

On-site
USD 75,000 - 110,000
SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead
SOC 2 Type 2 Five-TSC SaaS / Cloud Compliance Lead

FYI - For Your Information, Inc. • Silver Spring (MD)

Hybrid
USD 80,000 - 100,000
Opportunity to work a hybrid work schedule
Tuition/education assistance
Pet insurance
PCI Qualified Security Assessor (QSA)
PCI Qualified Security Assessor (QSA)

MegaplanIT, LLC • Scottsdale (AZ)

On-site
USD 80,000 - 120,000
Senior Associate, PCI Assurance
Senior Associate, PCI Assurance

Thoropass • United States

Remote
USD 110,000 - 130,000
Access to health, dental, and vision care
Early equity options
Flexible PTO