About the Role
You'll lead the day-to-day activities of the PCI Compliance and IT Risk Management team, serve as a subject matter expert on PCI compliance and technology risk, and support risk assessments, audits, regulatory requirements, and compliance initiatives.
This role is ideal for someone who combines PCI compliance knowledge, IT/cybersecurity risk management experience, strong execution discipline, and people leadership.
Key Responsibilities
- Lead and oversee the daily activities and performance of PCI Compliance and IT Risk Management team members.
- Provide guidance, prioritization, training, and support for team members.
- Serve as a PCI Compliance and IT Risk SME, monitoring regulatory requirements, industry trends, and emerging threats.
- Conduct and support technology and cybersecurity risk assessments, including control reviews, risk analysis, stakeholder engagement, and recommendations.
- Ensure compliance with payment network and regulatory requirements, including Visa, Mastercard, AMEX, and Discover.
- Advise technical and business stakeholders on compliant business and technology solutions.
- Partner with cross-functional teams to document compliance requirements and align technical solutions with risk, compliance, and business objectives.
- Support audits, compliance documentation, evidence collection, and reporting activities.
- Help develop and enforce compliance and risk management processes and policies.
- Support business continuity and risk mitigation initiatives where applicable.
Must-Have Qualifications
- Bachelor's degree in Information Security, Cybersecurity, IT, Risk Management, or a related field; equivalent experience may be considered.
- 4–6 years of experience in PCI Compliance and IT Risk Management.
- Background in information security, risk assessment, regulatory compliance, audit, and governance.
- At least 2 years of experience managing and developing resources.
- Strong organizational, multitasking, written, verbal, presentation, and collaboration skills.
- Strong execution discipline and ability to work within structured processes and controlled environments.
- Ability to assess risk, exercise sound judgment, and resolve issues using established policies and procedures.
- Ability to collaborate with cross-functional and global teams.
Good-to-Have
- Knowledge of PCI DSS and payment card industry standards.
- Understanding of information security concepts such as access control and encryption.
- Familiarity with ISO 27001 and NIST.
- Experience supporting audits, documentation, and evidence collection.
- Microsoft Office proficiency.
- Certifications such as PCI-P, CRISC, Security+ (SEC+), or CISSP.
Why Join Us
- Take ownership of PCI compliance and IT risk management at manager level.
- Lead and develop a dedicated compliance and risk team.
- Work closely with technical and business stakeholders on high-impact risk and compliance initiatives.
- Hybrid work setup: 3 days WFH / 2 days onsite.