SRC PCI Senior Associate

Not Interested
Bookmark
Report This Job

profile Job Location:

Pune - India

profile Monthly Salary: Not Disclosed
Posted on: 17 hours ago
Vacancies: 1 Vacancy

Job Summary

Industry/Sector

Not Applicable

Specialism

Cybersecurity & Privacy

Management Level

Senior Associate

Job Description & Summary

At PwC our people in risk and compliance focus on maintaining regulatory compliance and managing risks for clients providing advice and solutions. They help organisations navigate complex regulatory landscapes and enhance their internal controls to mitigate risks effectively.

In regulatory risk compliance at PwC you will focus on confirming adherence to regulatory requirements and mitigating risks for clients. You will provide guidance on compliance strategies and help clients navigate complex regulatory landscapes.

  • 210 years of Information Security experience with relevant PCI experience performing assessments advisory work or compliance implementation.

  • Strong understanding of PCI DSS ecosystems scoping compliance processes andmaintainingongoing compliance programs.

  • Experience working with PCI DSS v4.0.1 requirements controls and testing procedures.

  • UnderstandingPCI DSS segmentation testing scoping principles and evidence validation techniques.

  • Preferably certified as PCI QSA or ISA (optional) with experience leading or supporting PCI DSS assessments and generating ROCs/Self-Assessments.

  • Experience with PCI Industry benchmarking RFPs/RFQs scoping SAQs auditing remediation and providing recommendations to large enterprises.

  • SME-level knowledge in controls implementation assessmentsperformgap analysis compliance reporting and creation of PCI-aligned policies procedures and governance checks.

  • Must have strong experience in implementing/assessing the P2PE solution requirements and testing procedures encryption/decryptionmethodologiesandkey management within secure cryptographic devices.

  • Responsible for building and influencing payment security as a core competency across clients internal teams partners and vendors. This includes providing education developing processes and procedures standard templates accelerators and training to support internal competency build.

  • Strong understanding and hands-on experienceinconducting security reviews of various cybersecurity solutions including but not limited to the following:

  • Application or network firewalls

  • Intrusion detection/prevention systems

  • Database or other storage solutions

  • Encryption solutions

  • Security audit/log monitoring solutions

  • File integrity monitoring solutions.

  • Anti-virus solutions

  • Vulnerability scanning services or solutions.

  • Conduct targeted validation and detailed assessments of client processes applications products policydocumentationandthird-party adherence to PCI DSS requirements.

  • Delivers findings recommendations and remediation steps for all activities in a clearconciseand audience-specificformat.

  • Strong understanding of cloud platforms cloud security principles and PCI-specific requirementsincluding segmentation access control encryption and loggingwith the ability to assess PCI applicability within cloud shared responsibility models.

  • Familiarity with containerization and orchestration technologies (e.g. Kubernetes) and their secure configuration in PCI-scoped environments.

  • Ability toestablishcredibility andmaintainstrong working relationships with teams involved with payment security (InfoSec Legal Business Development Physical Security Developer Community Networking Systems etc.).

  • Strong understanding of application security practices (such as OWASP Top 10) and familiarity with other compliance standards/frameworks like ISO 27001/27002 NIST HITRUST COBIT SOX GLBA SSAE16/SOC 2 HIPAA etc.

  • Working knowledge of AI/GenAI technologies with awareness of related data security and governance risks relevant to PCI DSS environments.

Minimum years experience required

5-8 Years

Minimum years experience required

5-8 Years

  • Related payment security control and compliance experience in conductingexecutingand managing fieldwork for assessments: PCI DSS SOX GLBA HIPAA desirable.

  • Strong leadership teamwork and collaboration abilities.

  • Ability to quicklyacquireandutilizeknowledge onnew technologiesand solutions emergingthreatsand vulnerabilities.

  • Must have experience with Business development and should be able to contribute to team development and growth.

  • Good presentation project management facilitation and delivery skills as well as strong analytical and problem-solving capabilities.

  • Develop/implement automation solutions and capabilities that are clearly aligned to client businesstechnologyand threat posture.

  • Excellent written oral communication and presentation skills.

  • Ability to listen and contribute effectively to team environments.

  • Results oriented high energy self-motivated.

  • Worked in a client facing role.

Professional & Educational Background

  • MCA / BE / B Tech

  • Preferredcertifications:PCI QSA/ISAPCIPCISSPCISA CISM CRISC or other comparable audit/security certifications.

Travel Requirements

Not Specified

Job Posting End Date


Required Experience:

Senior IC

Industry/SectorNot ApplicableSpecialismCybersecurity & PrivacyManagement LevelSenior AssociateJob Description & SummaryAt PwC our people in risk and compliance focus on maintaining regulatory compliance and managing risks for clients providing advice and solutions. They help organisations navigate c...
View more view more

Key Skills

  • CCTV
  • Airport Security
  • Analysis
  • Higher Education
  • Jewellery
  • Jboss

About Company

Company Logo

At PwC, our purpose is to build trust in society and solve important problems. We’re a network of firms in 155 countries with over 284,000 people who are committed to delivering quality in assurance, advisory and tax services. Find out more and tell us what matters to you by vis ... View more

View Profile View Profile