cybersecurity analyst senior, PCI compliance
About the role
This role supports Starbucks Technology as a technical PCI DSS v4.0 Subject Matter Expert (SME), partnering with architecture, infrastructure, application, and platform teams to design, validate, and automate controls across payment environments. The role combines hands-on understanding of network architecture, segmentation, encryption, data flows, and cardholder data environment (CDE) scoping with the ability to translate PCI requirements into practical engineering patterns to reduce risk and minimize compliance scope.
The Cybersecurity Analyst Senior partners with engineering teams to design and validate solutions that meet PCI requirements while minimizing scope. This role leads PCI scoping and segmentation efforts, translates requirements into technical implementations, and supports GRC capabilities including automation, continuous monitoring, and evidence orchestration. Operates independently to identify risks and drive cross-functional improvements.
Responsibilities
- Lead technical PCI architecture reviews by evaluating segmentation models, network paths, trust boundaries, service-to-service interactions, cloud and hybrid connectivity, and system components that store, process, transmit, or could impact cardholder data.
- Provide technical guidance on encryption for data at rest and in transit, tokenization, certificate and key management, cryptographic control design, and implementation patterns that satisfy PCI requirements without adding unnecessary scope or operational friction.
- Lead PCI scoping by validating data-flow diagrams, payment transaction paths, CHD lifecycle stages, connected systems, compensating controls, and segmentation assumptions across applications, infrastructure, networks, cloud platforms, and third-party integrations.
- Identify opportunities to eliminate or reduce cardholder data storage and shrink PCI scope.
- Translate PCI DSS requirements into technical requirements and control implementations.
- Support PCI assessments (QSA-facing), including evidence validation, control testing, and remediation planning.
- Design and maintain risk and control matrices aligned to PCI and enterprise standards.
- Track remediation, risk acceptance, and exceptions with stakeholders.
- Provide guidance on use of compliance and risk management tools and processes.
- Develop documentation and training for compliance processes and tooling.
- Design and build automated approaches for continuous PCI control validation and evidence collection, using integrations, APIs, data models, workflow automation, and telemetry from security, infrastructure, cloud, and GRC/IRM platforms.
- Develop metrics, dashboards, and control-health views that use system data and control telemetry to show PCI coverage, remediation status, exception trends, and risk exposure.
- Gather, analyze, and document solution requirements. Facilitate user story creation and backlog grooming in an agile delivery environment.
- Utilize agile delivery methodologies and participate on scrum teams to deliver on projects.
- Effectively assess overall improvement opportunities (productivity/efficiency gains, cost savings, etc.).
- Partner with engineering teams to embed PCI requirements into system design.
- Provide guidance aligned to policies, standards, and risk reduction.
- Develop reusable templates, documentation, and training.
- Support delivery of compliance capabilities and program metrics (KPIs).
- Operate self-directed with minimal direction from more senior analysts, providing escalation when necessary.
Requirements
- Bachelor's degree in computer science, information systems, cybersecurity, engineering, or a related field, or 3+ years of relevant experience in cybersecurity, infrastructure, application, cloud, compliance automation, or technology risk roles.
- Translate business, technology, and compliance objectives into practical technical requirements, implementation guidance, and control outcomes across cross-functional engineering and risk activities.
- Apply analytical and problem-solving skills to evaluate system designs, data flows, control evidence, root causes, and remediation options in complex technology environments.
- Create clear technical documentation, including data-flow narratives, control evidence, implementation guidance, process documentation, and materials that help engineering teams understand and meet PCI requirements.
- Familiarity with payment ecosystems (processors, tokenization).
- Exhibit exceptional oral and written interpersonal and communication skills.
- Experience with Microsoft Office products such as Word and Excel proficiently.
- Apply a deep understanding of business processes and process improvement initiatives.
- Provide top-tier customer service.
- Apply systems development concepts, including requirements analysis, design review, testing, release practices, defect management, and operational readiness, to ensure PCI controls are embedded into technology delivery.
- Proven working knowledge of systems development lifecycle and IT operations.
- Ability to use business knowledge, sound judgment, and resourcefulness to design and deploy highly reliable and sustainable technology solutions.
- Ability to balance multiple priorities and meet deadlines.
- Configuration knowledge of relevant applications/modules/platforms.
Preferred Qualifications
- 3+ years of progressive industry experience in Information Risk Management, IT Governance, IT Compliance, Compliance Engineering, Data Privacy, or Internal/External Technology Audit disciplines, with at least two of those years in an IT or a software development setting.
- Experience in cybersecurity, network security, or cloud security, with direct exposure to PCI DSS environments.
- Strong understanding of network architecture, cloud security design, encryption protocols.
- Direct experience supporting PCI DSS assessments (QSA-facing).
- Experience designing or validating CDE segmentation in cloud and hybrid environments.
- Exposure to Common Control Framework (CCF) practices with knowledge and ability to track common control requirements across numerous security and regulatory standards.
- Ability to influence technical and business stakeholders in complex environments.
- Certifications such as PCI QSA/ISA, PCIP, CISA, CISSP, CISM, CIPM or others focused on controls assurance, information security, data privacy, or information risk management is a strong plus.
- Hands-on experience in developing roadmaps, story outlines, writing user stories, refining product backlogs, and coordinating/prioritizing conflicting requirements across teams in a fast-paced, changing environment.
- Experience in engineering and/or platform role for GRC solutions and/or cybersecurity risk management solutions.
Benefits
- Medical, dental, vision, basic and supplemental life insurance, and other voluntary insurance benefits.
- Short-term and long-term disability, paid parental leave, family expansion reimbursement.
- Paid vacation from date of hire (accrued up to a maximum of 120 hours for roles below director and 200 hours for roles at director or above, with variations in CA, CO, IL, LA, ME, MA, NE, ND, or RI), sick time (accrued at 1 hour for every 25 hours worked), eight paid holidays, and two personal days per year.
- 401(k) retirement plan with employer match.
- Discounted company stock program (S.I.P.), Starbucks equity program (Bean Stock).
- Incentivized emergency savings and financial well-being tools.
- 100% upfront tuition coverage for a first-time bachelor’s degree through Arizona State University’s online program via the Starbucks College Achievement Plan.
- Student loan management resources and access to other educational opportunities.
- Backup care and DACA reimbursement.
The actual base pay offered will be based on job-related knowledge/skills, experience, geographical location, and internal equity.
Schedule
Onsite four days a week.