yandex
T
tevora
Страна
США
Зарплата
60 000 $ – 90 000 $
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
ГибридПолная занятость

PCI Technical Payments Associate-Analyst (QSA Track)

Оценка ИИ

Отличная возможность для старта карьеры в узкоспециализированной и высокооплачиваемой нише QSA-аудита с четким планом развития. Компания предлагает полный пакет льгот и поддержку в обучении.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Роль требует базового опыта в PCI DSS (от 1 года) и технического образования. Основная сложность заключается в необходимости быстро освоить методологию аудита для подготовки к сертификации QSA.

Анализ зарплаты

Медиана85 000 $
Рынок70 000 $ – 105 000 $
Оценка ИИ

Предложенная зарплата ($60k - $90k) находится в пределах рыночной нормы для начальных позиций в сфере комплаенса в Калифорнии, хотя верхняя граница чуть ниже медианы для опытных аналитиков. Основная ценность здесь заключается в оплачиваемом обучении и выходе на уровень QSA, где зарплаты значительно выше.

Сопроводительное письмо

I am writing to express my strong interest in the PCI Technical Payments Associate-Analyst position at Tevora. With a solid foundation in cybersecurity and direct experience participating in PCI DSS assessments, I am eager to contribute to your team's mission of creating secure digital environments while working towards my QSA qualification.

In my previous experience, I have been involved in control validation and evidence review, which has given me a practical understanding of the complexities involved in PCI DSS compliance. I am particularly drawn to Tevora's collaborative culture and the structured 'QSA Track' mentorship, as I am committed to advancing my technical expertise in payment security and helping clients navigate evolving threat landscapes.

I am confident that my analytical skills and dedication to professional growth make me an excellent fit for this role. Thank you for considering my application. I look forward to the possibility of discussing how my background aligns with the needs of your payments team.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в tevora уже сейчас

Сделайте первый шаг к карьере сертифицированного QSA-аудитора в команде экспертов Tevora — подайте заявку сегодня!

Описание вакансии

PCI Technical Payments Analyst (QSA Track)

at Tevora

Irvine, CA

If you haven't heard of Tevora, it's because we've done our job!

Tevora is a tight-knit community of professionals with a shared passion for our craft. Every day, we combine in-depth knowledge of cybersecurity, technology, and compliance to help create more secure digital environments. To Tevorans, every problem is a puzzle in need of solving. We strongly believe that if we put smart, driven people in a room together, they will accomplish great things. We maintain a supportive culture that celebrates continuous learning, diverse perspectives, and sharing the wins. That's why we have our eyes on you.

What's the role?

As a Technical Payments Analyst (QSA Track), you will support consultants and PCI Qualified Security Assessors (QSAs) in delivering payment security and compliance assessments for clients in the payments industry. This role is intended for professionals already working with PCI DSS who want to deepen their assessment experience and progress towards PCI QSA qualification.

In this role, you will contribute to evaluating payment environments, reviewing documentation and evidence, and identifying gaps in security controls across payment systems, applications, and processes. Working closely with experienced QSAs, you will help assess and document controls designed to protect sensitive payment data and support PCI DSS compliance while continuing to build the experience required for QSA certification.

A day in the life could include:

Payment Security Assessments:

  • Participate in PCI DSS assessments of client payment systems, applications, and processes to identify potential security vulnerabilities and compliance gaps.
  • Assist in reviewing payment architectures, technologies, and processing environments to evaluate alignment with industry security standards and compliance requirements.
  • Support the collection, analysis, and documentation of evidence related to payment security controls.

Compliance and Certification:

  • Work alongside experienced QSAs and consultants to help clients navigate payment security standards such as PCI DSS, SSF (or PA-DSS), and other payment domain requirements.
  • Contribute to assessment documentation, compliance reports, and supporting materials used in certification and validation processes.
  • Gain practical experience with PCI assessment methodologies as part of the path toward QSA qualification.

Security Recommendations and Remediation:

  • Assist in developing recommendations to strengthen the security posture of client payment systems and applications.
  • Collaborate with consultants and client teams to help track and document remediation efforts addressing identified vulnerabilities and compliance gaps.

Technical Consultation:

  • Support consultants in advising clients on secure payment technologies, encryption approaches, secure data storage, and secure development practices.
  • Participate in technical discussions related to protecting payment card data and sensitive financial information.

Client Relationship Management:

  • Build productive working relationships with client stakeholders while supporting engagement teams during assessments and advisory activities.
  • Participate in client meetings, workshops, and technical discussions as part of the assessment process.

Industry Awareness:

  • Stay current with emerging cybersecurity threats, evolving payment security standards, and trends impacting the payments ecosystem and cybersecurity threat landscape.
  • Continuously develop technical and compliance expertise in preparation for pursuing QSA certification.

Necessary skills and qualifications:

  • Minimum of 1 year of experience participating in PCI DSS assessments or supporting PCI compliance engagements, such as evidence review, control validation, gap analysis, documentation preparation, or quality assurance.
  • Ideal candidate has experience contributing to PCI DSS Reports on Compliance (ROC), Self-Assessment Questionnaires (SAQ), or PCI gap assessments.
  • Demonstrated interest in advancing a career in payment security and progressing towards PCI Qualified Security Assessor (QSA) certification.
  • Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related STEM field (or equivalent practical experience).
  • Strong analytical and problem-solving skills, with the ability to identify security risks and contribute to recommending appropriate solutions.
  • Excellent communication and interpersonal skills, with the ability to convey technical concepts to both technical and non-technical audiences.
  • Ability to work independently and collaboratively within cross-functional teams to support client engagements and project objectives.
  • Foundational understanding of cybersecurity principles, including areas such as network security, access control, encryption, and secure system design.
  • Exposure to payment technologies, payment processing environments, or compliance frameworks is a plus, including PCI DSS, SSF (or PA-DSS), ISO 27001, and NIST Cybersecurity Framework.
  • A commitment to maintaining the highest level of confidentiality and professionalism.
  • Preferred Certifications

(Not required but beneficial)

* Certified Information Systems Security Professional (CISSP)

* Certified Information Systems Auditor (CISA)

* Certified Information Security Manager (CISM)

* ISO 27001 Lead Auditor

Additional requirements:

  • Eligibility to work in the United States.

We've got you covered!

  • Comprehensive benefits including: Medical, Dental, Vision & Basic Life Insurance
  • Paid Vacations, Sick Time, & Holidays
  • 401 (k) with discretionary company match
  • Vibrant work culture

EEOC Statement

Tevora is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, disability status, or other applicable legally protected characteristics.

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • Cybersecurity
  • ISO 27001
  • PCI DSS
  • Information Security
  • Compliance
  • Risk Assessment
  • Network Security
  • Encryption
  • NIST Cybersecurity Framework

Возможные вопросы на собеседовании

Проверка практического опыта работы с основным стандартом вакансии.

Расскажите о вашем опыте участия в подготовке отчетов ROC или заполнении опросников SAQ. С какими сложностями вы сталкивались?

Оценка понимания технических аспектов защиты данных платежных карт.

Как вы проверяете соблюдение требований по сегментации сети (network segmentation) в рамках PCI DSS?

Проверка навыков анализа рисков и предложения решений.

Если клиент не может выполнить конкретное требование PCI DSS по техническим причинам, какой процесс разработки компенсирующих мер вы предложите?

Оценка коммуникативных навыков, критически важных для аудитора.

Опишите ситуацию, когда вам нужно было объяснить сложное техническое требование безопасности нетехническому специалисту со стороны клиента.

Проверка мотивации к профессиональному росту в данной узкой нише.

Какие изменения в версии PCI DSS 4.0 вы считаете наиболее значимыми для индустрии платежей и почему?

Похожие вакансии

J
JETLYN
210 000 ₽ – 260 000 ₽

Специалист по защите информации (Mobile Security Engineer)

SeniorУдалённоРоссия
iOS · Cryptography · Jailbreak · HTTPS · REST API · gRPC · TCP · UDP · HTTP · Protobuf · JSON · Avro · MessagePack · Reverse Engineering
+14 навыков
AG
Atom group
4 000 $ – 5 000 $

Senior Information Security (ИБ)

SeniorУдалённоБеларусь
Information Security · DevSecOps · SDLC · Risk Management · Security Policy · DevOps
+6 навыков
S
SDOdev
380 000 ₽ – 500 000 ₽

Senior Android Security / Reverse Engineer (HTTPS Traffic, Google Services)

SeniorУдалённоРоссия
Android · iOS · TCP/IP · HTTPS · Cryptography · MITM · Frida · Objection · Apktool · Jadx · Hopper · Smali · Hermes · Swift · Dart · Objective-C · C++ · Reverse Engineering · Cybersecurity
+19 навыков
И
ИНФОБЕЗ
100 000 ₽ – 500 000 ₽

Специалист по информационной безопасности (Пентестер)

УдалённоРоссия
Kali Linux · Metasploit · NMAP · Burp Suite · sqlmap · OWASP Top 10 · C++ · Python · JavaScript · PHP · MSSQL · MySQL · RCE
+13 навыков
OZ
Operation Zero
450 000 ₽ – 900 000 ₽

Исследователь безопасности Android

УдалённоРоссия
Android · Reverse Engineering · Exploit Development · Kernel Research · C++ · ARM Assembly · Java · Ghidra · IDA Pro · Linux Kernel · Kotlin · JavaScript
+12 навыков
NDA
Не указана

Senior AppSecOps Engineer

SeniorУдалённоБеларусь
AppSec · C++ · Go · Java · SAST · SCA · Svace · CodeScoring · Jira · GitLab · GCC · Make · Linux Kernel
+13 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

T
tevora
Страна
США
Зарплата
60 000 $ – 90 000 $