Jobs · Finance · Georgia

Cybersecurity PCI Compliance Advisor

Elevance Health · Atlanta, GA · Yesterday
FinanceFull-time

About the role

The Information Security Advisor is responsible for leading and supporting Payment Card Industry Data Security Standard (PCI DSS) compliance activities across the enterprise. This role provides subject matter expertise for PCI DSS control interpretation, assessment readiness, evidence review, remediation tracking, scope validation, control testing, and stakeholder engagement.

Responsibilities

  • Provides first level engineering design functions and trouble resolution.
  • Serves as point of technical escalation on complex problems.
  • Supports PCI governance activities, including maintenance of PCI policies, standards, procedures, control matrices, evidence repositories, assessment schedules, risk registers, and compliance dashboards.
  • Evaluates third-party service provider PCI responsibilities, including review of AOCs, responsibility matrices, shared responsibility documentation, contracts, service descriptions, and supporting security evidence.
  • Develops testing plans to ensure quality of implementation.
  • Supports internal and external audit activities related to PCI DSS, HIPAA, HITRUST, SOC 2, NIST, and other cybersecurity or regulatory compliance requirements.
  • Supports system and network architecture support for information and network security technologies.
  • Supports business and technology associates in risk assessments and implementation of appropriate information security procedures, standards and technologies.
  • Maintains security incident response plans.
  • Represents major upgrades and business system replacements in change control.
  • Designs & engineers repetitive technical solutions based on business requirements and defined technology standards.
  • Develops support procedures and performance metrics reports.
  • Leads level 1 & 2 incident recoveries.
  • May organize the efforts of other analysts as part of incident recovery.
  • Mentor analysts and control owners by providing guidance on PCI evidence quality, control interpretation, assessment documentation, remediation planning, and stakeholder communication.
  • Contributes to continuous improvement of PCI compliance processes, templates, workflows, reporting, evidence management, automation opportunities, and program maturity initiatives.
  • Uses AI-enabled tools and emerging technologies responsibly to improve productivity, research, documentation quality, control analysis, workflow efficiency, reporting, and decision support while maintaining data protection, confidentiality, and compliance requirements.

Requirements

  • Requires BS/BA degree in Information Technology or related field of study and a minimum of 5 years experience in systems support, system administration, system engineering, system security, access management, network security, network communications, computer networking, telecommunications, systems development and management, hardware, software, and/or data; or any combination of education and experience, which would provide an equivalent background.
  • Requires experience in planning and designing highly complex systems.
  • Experience with multiple technical and business disciplines strongly preferred.
  • Security Certifications: CISSP or other technical security certifications (e.g. Systems Security Certified Practitioner, Certification and Accreditation Professional) strongly preferred.
  • Bachelor’s degree in cybersecurity, information systems, computer science, risk management, business, audit, or a related field; or equivalent combination of education, training, and work experience.
  • 5+ years of experience in cybersecurity, PCI compliance, IT audit, GRC, technology risk management, information security, regulatory compliance, or a related field.
  • Experience using GRC, workflow, ticketing, audit management, or evidence management tools.
  • Active or prior PCI Internal Security Assessor (ISA) certification or PCI Qualified Security Assessor (QSA) certification.
  • Familiarity with PCI-related standards and guidance, including PCI DSS, PCI 3DS, PCI P2PE, PCI PIN Security, PCI Secure Software Standard, PCI SSF, and PCI SSC guidance documents.

Qualifications

  • Requires strong knowledge of PCI DSS requirements, payment environments, cardholder data flows, segmentation, compensating controls, evidence validation, and risk-based compliance decision-making.
  • Requires strong knowledge of systems support, system administration, system engineering, system security, access management, network security, network communications, computer networking, telecommunications, systems development and management, hardware, software, and/or data.
  • Requires strong knowledge of third-party service provider PCI responsibilities, including review of AOCs, responsibility matrices, shared responsibility documentation, contracts, service descriptions, and supporting security evidence.
  • Requires strong knowledge of testing plans to ensure quality of implementation.
  • Requires strong knowledge of audit activities related to PCI DSS, HIPAA, HITRUST, SOC 2, NIST, and other cybersecurity or regulatory compliance requirements.
  • Requires strong knowledge of system and network architecture support for information and network security technologies.
  • Requires strong knowledge of risk assessments and implementation of appropriate information security procedures, standards and technologies.
  • Requires strong knowledge of security incident response plans.
  • Requires strong knowledge of change control for major upgrades and business system replacements.
  • Requires strong knowledge of repetitive technical solutions based on business requirements and defined technology standards.
  • Requires strong knowledge of support procedures and performance metrics reports.
  • Requires strong knowledge of incident recoveries.
  • Requires strong knowledge of mentoring analysts and control owners by providing guidance on PCI evidence quality, control interpretation, assessment documentation, remediation planning, and stakeholder communication.
  • Requires strong knowledge of continuous improvement of PCI compliance processes, templates, workflows, reporting, evidence management, automation opportunities, and program maturity initiatives.
  • Requires strong knowledge of using AI-enabled tools and emerging technologies responsibly to improve productivity, research, documentation quality, control analysis, workflow efficiency, reporting, and decision support while maintaining data protection, confidentiality, and compliance requirements.

Skills

  • Strong knowledge of PCI DSS requirements, payment environments, cardholder data flows, segmentation, compensating controls, evidence validation, and risk-based compliance decision-making.
  • Strong knowledge of systems support, system administration, system engineering, system security, access management, network security, network communications, computer networking, telecommunications, systems development and management, hardware, software, and/or data.
  • Strong knowledge of third-party service provider PCI responsibilities, including review of AOCs, responsibility matrices, shared responsibility documentation, contracts, service descriptions, and supporting security evidence.
  • Strong knowledge of testing plans to ensure quality of implementation.
  • Strong knowledge of audit activities related to PCI DSS, HIPAA, HITRUST, SOC 2, NIST, and other cybersecurity or regulatory compliance requirements.
  • Strong knowledge of system and network architecture support for information and network security technologies.
  • Strong knowledge of risk assessments and implementation of appropriate information security procedures, standards and technologies.
  • Strong knowledge of security incident response plans.
  • Strong knowledge of change control for major upgrades and business system replacements.
  • Strong knowledge of repetitive technical solutions based on business requirements and defined technology standards.
  • Strong knowledge of support procedures and performance metrics reports.
  • Strong knowledge of incident recoveries.
  • Strong knowledge of mentoring analysts and control owners by providing guidance on PCI evidence quality, control interpretation, assessment documentation, remediation planning, and stakeholder communication.
  • Strong knowledge of continuous improvement of PCI compliance processes, templates, workflows, reporting, evidence management, automation opportunities, and program maturity initiatives.
  • Strong knowledge of using AI-enabled tools and emerging technologies responsibly to improve productivity, research, documentation quality, control analysis, workflow efficiency, reporting, and decision support while maintaining data protection, confidentiality, and compliance requirements.

Benefits

Hybrid Workforce Strategy: Associates are required to work at an Elevance Health location at least once per week, and potentially several times per week. Specific requirements and expectations for time onsite will be discussed as part of the hiring process.

Healthcare Company: Elevance Health is a health company dedicated to improving lives and communities – and making healthcare simpler.

Pay

Market-competitive total rewards that include merit increases, paid holidays, Paid Time Off, and incentive bonus programs (unless covered by a collective bargaining agreement), medical, dental, vision, short and long term disability benefits, 401(k) +match, stock purchase plan, life insurance, wellness programs and financial education resources, to name a few.

Schedule

Hybrid Workforce Strategy: Associates are required to work at an Elevance Health location at least once per week, and potentially several times per week. Specific requirements and expectations for time onsite will be discussed as part of the hiring process.

Similar jobs