Senior Security Assessor I

Valid8 Financial, Inc.

Plano (TX)

On-site

USD 110,000 - 160,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Specialized Security Services, Inc. is seeking a Senior Security Assessor to support PCI-DSS, ISO, NIST, HIPAA, GDPR, and other regulatory compliance initiatives. You will perform risk assessments, advise on security measures, and articulate client security requirements to align with industry best practices.

The role emphasizes client consulting, managing assessments, and ensuring projects meet security standards and regulatory requirements.

Qualifications

  • University degree in Computer Science, Engineering, or related field.
  • Security certification (CISSP, CISA, CISM, GIAC GSNA, ISO27001 Lead Auditor, IRCA ISMS Auditor or higher).
  • 3–5 years of information security governance, risk and compliance experience.
  • Proven track record delivering business requirements on time and within budget.
  • Understanding cyber security compliance best practices for service delivery.
  • Knowledge of vendor/supplier contract reviews.
  • Knowledge of Security Governance, Risk Management and Compliance.
  • PCI-DSS knowledge and related architecture expertise.

Responsibilities

  • Utilize strong knowledge of the PCI-DSS security standards.
  • Assess controls to determine compliance with PCI DSS, ISO, HIPAA, GDPR, NIST, FedRAMP, etc., including maturity and risk.
  • Support PCI-DSS, Risk, NIST, ISO, FedRAMP, and cyber security compliance analyses.
  • Support privacy engagements with GDPR, CCPA, HIPAA, or similar frameworks.
  • Perform threat/risk assessments and business impact analyses.
  • Participate in development and implementation of enterprise security architecture and standards.
  • Perform technical security reviews to ensure compliance with policies and standards.

Skills

PCI-DSS knowledge
Risk assessment
Security governance
Regulatory compliance
Client consulting
Threat modeling

Education

CISSP
CISA
CISM
ISO27001 Lead Auditor
GIAC GSNA

Tools

QSA experience
ITIL

Job description

About Specialized Security Services, Inc.

For over two decades, our expert team has successfully assisted organizations with the implementation and oversight of their information security, privacy, and regulatory compliance programs. Our reputation is our own, built upon our steadfast commitment over the years to do the right thing and go above and beyond for our clients. We pride ourselves on our ability to think outside-the-box, stay nimble and succeed as a team.

About the Senior Assessor role:

The Senior Security Assessor supports PCI Compliance, ISO, NIST, Risk Assessment, HIPAA, CCPA, GDPR project initiatives by undertaking risk assessments, advising on implementation of security measures, recommending appropriate risk mitigations, interpreting security policy and standards in the context of projects and business scenarios to help the business operate securely.This role has a significant client consulting and management component inadvising,defining client security requirements to industry best practice standards, andensuring that all projects meet these requirements, or that exceptions and issues are noted and remediated as appropriate.

As a Senior Assessor, you will:

  • Utilize strong knowledge of the PCI-DSS security standards
  • Assess existing controls to determine level of compliance to the PCI DSS standard, ISO, HIPAA, GDPR, NIST, FedRAMP etc. inclusive of their maturity, state of compliance, and the risk associated with any findings.
  • Support PCI-DSS, Risk, NIST, ISO, FedRAMP, Cyber Security Compliance gap analyses and assessments.
  • Support compliance privacy client engagements and familiarity with GDPR, CCPA, HIPAA, or similar privacy frameworks.
  • Perform comprehensive threat/risk assessments and business impact analysis of current system, data, application and technology environments to determine possible internal and external threats to information assets, and identify security measures required to counter such threats
  • Participate in the development and implementation of the enterprise security architecture and supporting security standards to ensure compliance with corporate policies, and relevant legislative and regulatory requirements
  • Perform technical security reviews or assessments to ensure targeted systems, networks, applications and/or data are in compliance with corporate policies and standards

Required Education and Experience:

  • A university degree in Computer Science, Engineering, or closely related field
  • Minimum of one Security certification such as CISSP, CISA, CISM, SANS GIAC - GSNA, ISO27001 Certified Lead Implementer/Lead Auditor/Internal Auditor, IRCA ISMS Auditor or higher, IIA Certified Internal Auditor (CIA)
  • 3-5 years of Information Security experience in Security Governance, Risk and Compliance practices and methodologies.
  • Proven track record of successfully delivering business requirements on time and within budget constraints
  • A thorough understanding of the best practices of Cyber Security Compliance for services execution
  • Knowledge of vendor/supplier contracts reviews
  • Knowledge of Security Governance, Risk Management and Compliance
  • Demonstrates advanced knowledge of the principles, best practices architecture and design approaches to applicable capabilities, services and standard controls that fall under the scope of the PCI-DSS
  • Exposure as a QSA (Qualified Security Assessor), HITRUST, NIST, ISO, ITIL, CISSP or an ISA (Internal Security Assessor) would be a definite asset

Preferred Experience that drives success in this role:

  • Additional Security certification such as QSA, ISO, SOC, IRCA ISMS Auditor or higher, IIA Certified Internal Auditor (CIA)
  • Demonstrates advanced knowledge of principles, best practices architecture and design approaches to applicable capabilities, services and standard controls that fall under the scope of the PCI-DSS, NIST, and ISO.
  • Experience with performing cyber security assessments.
  • Experience of Cyber security policy development, Incident response procedures, and Risk assessments.
  • Previous experience in PCI-DSS, NIST, ISO compliance program including pre-assessment or assessment and gap remediation programs.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Assessor II
Senior Security Assessor II

Valid8 Financial, Inc. • Plano (TX)

On-site
USD 90,000 - 130,000
Senior Security Assessor & Compliance Architect
Senior Security Assessor & Compliance Architect

Valid8 Financial, Inc. • Plano (TX)

On-site
USD 90,000 - 130,000
Senior Security Assessor: PCI/ISO Risk & Compliance
Senior Security Assessor: PCI/ISO Risk & Compliance

Valid8 Financial, Inc. • Plano (TX)

On-site
USD 110,000 - 160,000
Principal, Cybersecurity Compliance Services
Principal, Cybersecurity Compliance Services

Socket.dev • Plano (TX)

On-site
USD 180,000 - 240,000
Principal, Cybersecurity Compliance Services
Principal, Cybersecurity Compliance Services

Valid8 Financial, Inc. • Plano (TX)

On-site
USD 180,000 - 260,000
Senior Cybersecurity Compliance Leader & Trusted Advisor
Senior Cybersecurity Compliance Leader & Trusted Advisor

Valid8 Financial, Inc. • Plano (TX)

On-site
USD 180,000 - 260,000
PCI Qualified Security Assessor (QSA)
PCI Qualified Security Assessor (QSA)

MegaplanIT, LLC • Scottsdale (AZ)

On-site
USD 80,000 - 120,000
Senior PCI Analyst
Senior PCI Analyst

Computer Services, Inc. • United States

On-site
USD 70,000 - 100,000
Consultant- PCI
Consultant- PCI

Cdw • Atlanta (GA)

On-site
USD 100,000 - 140,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000