SR. MANAGER - IT COMPLIANCE

Hyatt

Chicago (IL)

On-site

USD 120,000 - 150,000

Full time

10 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Hyatt Hotels Corporation seeks a Senior Manager, IT Compliance to lead the PCI DSS program across cybersecurity, technology, and business units. Collaborate with internal audit, risk management, and IT teams to protect cardholder data and ensure ongoing PCI compliance.

This role requires 8+ years in IT compliance and 4+ years managing PCI programs, with knowledge of COBIT, CIS, ISO27001, and NIST CSF 2.0. Lead controls, assessments, and evidence collection while guiding a growing team.

Qualifications

  • 8+ years IT compliance, IT audit, cybersecurity, or risk management.
  • 4+ years leading PCI DSS programs or teams.
  • Knowledge of PCI DSS, IT risk frameworks, COBIT, CIS, ISO27001, and NIST CSF 2.0.

Responsibilities

  • Manage the organization’s PCI DSS compliance program and annual certification activities.
  • Coordinate annual PCI assessments, SAQs, and ROC activities for multiple units.
  • Define and validate the Cardholder Data Environment (CDE) and data flows.
  • Ensure PCI controls are implemented across in-scope systems.
  • Direct PCI DSS assessments and annual penetration testing with QSAs.
  • Monitor evidence collection, remediation, and ongoing control monitoring.
  • Partner with Cybersecurity, Infrastructure, Dev, and Ops teams for PCI alignment.
  • Develop and manage teams, resource levels, and career growth.
  • Provide input to annual operating budget and capital plans.

Skills

PCI DSS
IT risk management
COBIT
ISO27001
NIST CSF 2.0
Internal/External Audit collaboration
Documentation & PM
Stakeholder communication

Education

Bachelor’s degree in information security or related field

Tools

LogicGate
Auditboard/Optro
OneTrust

Job description

Hyatt Corporate

Hyatt Corporate Office

US - IL - Chicago

Technology

Professional Staff/Corporate

Full-time

Yearly US Dollar (USD) pay basis

Req ID: CHI015668

Summary

The Opportunity

Hyatt Hotels Corporation seeks an enthusiastic Senior Manager, IT Compliance to join our IT Governance, Risk Management, and Compliance department. You will be part of a team that is passionate about our purpose, committed to nurturing curiosity and new skills, and building connections across the organization with colleagues, customers, and guests.

Who We Are

At Hyatt, we believe in the power of belonging and creating a culture of care, where our colleagues become family. Since 1957, our colleagues and our guests have been at the heart of our business and helped Hyatt become one of the best and fastest-growing hospitality brands in the world. Our transformative growth and the addition of new hotels, brands, and business lines can open the door for exciting career and growth opportunities for our colleagues.

As we continue to grow, we never lose sight of what’s most important: People. We turn trips into journeys, encounters into experiences, and jobs into careers.

Why Now?

This is an exciting time to be at Hyatt. We are growing rapidly and are looking for passionate changemakers to be a part of our journey. The hospitality industry is resilient and continues to offer dynamic opportunities for upward mobility, and Hyatt is no exception.

How We Care for Our People

What sets us apart is our purpose—to care for people so they can be their best. Every business decision is made through the lens of our purpose, and it informs how we have and will continue to support each other as members of the Hyatt family. Our care for our colleagues is the key to our success. We’re proud to have earned a place on Fortune’s prestigious 100 Best Companies to Work For® list since 2013. This recognition is a testament to the tremendous way our Hyatt family continues to come together to care for one another, our commitment to a culture of inclusivity, empathy, and respect, and making sure everyone feels like they belong.

We’re proud to offer exceptional corporate benefits which include:

  • Annual allotment of free hotel stays at Hyatt hotels globally
  • Flexible work schedule
  • Work-life benefits including wellbeing initiatives such as a complimentary Headspace subscription, and a discount at the on-site fitness center
  • A global family assistance policy with paid time off following the birth or adoption of a child as well as financial assistance for adoption
  • Paid Time Off, Medical, Dental, Vision, 401K with company match
Who You Are

As our ideal candidate, you understand the power and purpose of our culture of care, and embody our core values of Empathy, Inclusion, Integrity, Experimentation, Respect, and Wellbeing. You enjoy working with others, are results-driven, and are looking for a variety of opportunities to develop personally and professionally.

The Role

The Senior Manager, IT Compliance, is responsible for leading the organization’s PCI Compliance Program including Payment Card Industry Data Security Standard (PCI-DSS). This position ensures compliance with PCI Standards and PCI-DSS requirements to protect cardholder data and maintain secure payment environments, coordinating teams across cybersecurity, technology, and business units to protect payment account data and maintain ongoing compliance. This role requires a strategic approach to compliance management, ensuring that PCI-DSS controls are effectively implemented, maintained, and continuously improved.

  • Manage the organization’s PCI DSS compliance program and annual certification activities.
  • Coordinate annual PCI assessments, Self-Assessment Questionnaires (SAQs), and Report on Compliance (ROC) activities for multiple business units.
  • Define and validate the Cardholder Data Environment (CDE), connected systems, data flows, and compliance boundaries. This includes providing guidance on PCI requirements for new systems, applications, vendors, and business initiatives.
  • Ensure the appropriate PCI controls and supporting processes are implemented and maintained across the in-scope systems and infrastructure relevant to the CDE.
  • Direct PCI DSS assessment activities and annual penetration testing, partnering with QSAs and internal stakeholders to maintain compliance posture.
  • Oversee the team to closely monitor and track compliance requirements, evidence collection, remediation activities, and ongoing control monitoring.
  • Partner with Cybersecurity, Infrastructure, Application Development, Application Owners, Technology Operations, and Infrastructure teams to ensure alignment exists with PCI DSS compliance requirements and industry best practices.
  • Manages and develops teams within areas of responsibility including all aspects of the company’s talent management processes. Develops and manages group / team structures and resource levels to support business needs and to develop team members.
  • Assures projects / requests are appropriately prioritized and aligned with the strategy and direction of the organization and appropriate resources are allocated for their development.
  • Provides input to annual operating budget and capital plans. Accountable for performance against financial parameters.
Qualifications

Experience Required:

  • 8+ years of experience in IT compliance, IT audit, cybersecurity, risk management, or related discipline.
  • 4+ years of direct experience managing larger PCI DSS compliance programs and/or leadership or people management experience.
  • Strong understanding of:
    • PCI DSS framework and standards
    • IT risk management frameworks
    • Different frameworks such as COBIT, CIS, ISO27001, and NIST CSF 2.0
  • Experience working with Internal Audit and External Auditors along with ability to manage multiple initiatives and work effectively with technical and nontechnical stakeholders.
  • Strong analytical, creating robust documentation, project management, process design/implementation, and communication skills.

Experience Preferred:

  • Education - Bachelor’s degree in information security, Information Technology, Risk Management, Cyber Security, or a related field (or equivalent work experience).
  • Certificates, Licenses, Registrations - Preferred certifications: CISA, CISSP, CRISC, PCI Qualified Security Assessor (QSA), PCI Internal Security Assessor (ISA), or equivalent.
  • Computer Skills Needed to Perform this Job - Microsoft Office (Word, Excel, PowerPoint, etc.). GRC tools like LogicGate, Auditboard/Optro, OneTrust, etc.

The position responsibilities outlined above are in no way to be construed as all-encompassing. Other duties, responsibilities, and qualifications may be required and/or assigned as necessary.

The salary range for this position is $120,000 to $150,000. This position is also eligible to earn incentive awards and an annual bonus. The final pay rate/salary offered to the successful candidate will depend on experience, skill level and other qualifications for the role, as well as the location of the performance of work. Pay for the successful candidate will meet local requirements, including the local minimum wage rate.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Manager - IT Compliance (Remote)
Sr. Manager - IT Compliance (Remote)

Hyatt Hotels Corporation • Chicago (IL)

Remote
USD 120,000 - 150,000
Annual bonus
Incentive awards
Competitive compensation
Principal Technology Compliance Program Manager - Payment Card Indu...
Principal Technology Compliance Program Manager - Payment Card Indu...

United States Digital Space LLC • Seattle (WA)

On-site
USD 120,000 - 180,000
PCI QSA Manager, Cybersecurity
PCI QSA Manager, Cybersecurity

BDO USA, LLP • Chicago (IL)

On-site
USD 115,000 - 140,000
Security & Compliance Analyst
Security & Compliance Analyst

OTG • New York (NY)

On-site
USD 90,000 - 110,000
Senior Security GRC Manager - Remote
Senior Security GRC Manager - Remote

PayNearMe • Santa Clara (CA)

On-site
USD 140,000 - 180,000
Stock options
$50 monthly communication stipend
$250 WFH setup stipend
+7
Project Manager - PCI DSS compliance program
Project Manager - PCI DSS compliance program

STAND 8 Technology Consulting • Long Beach (CA)

On-site
USD 111,585 - 125,361
Medical coverage through Anthem
Dental/Vision/Various Ancillary coverages through Unum
401(k) retirement savings plan
+3
SENIOR TECHNICAL BUSINESS ANALYST/DATA ARCHITECT
SENIOR TECHNICAL BUSINESS ANALYST/DATA ARCHITECT

Hyatt • Chicago (IL)

On-site
USD 130,000 - 140,000
Sr. Security Compliance Analyst - PCI DSS & U.S. FedRAMP
Sr. Security Compliance Analyst - PCI DSS & U.S. FedRAMP

Entrust Corporation • Field (NM)

Remote
USD 119,000 - 175,000
Medical insurance
Vision insurance
Dental insurance
+7
PCI QSA Manager, Cybersecurity
PCI QSA Manager, Cybersecurity

BDO USA • Nashville (TN)

On-site
USD 115,000 - 140,000
ESOP
Total Rewards
PCI QSA Manager, Cybersecurity
PCI QSA Manager, Cybersecurity

BDO USA • Houston (TX)

On-site
USD 115,000 - 140,000