- Implement and verify technical controls across the cardholder data environment, including access management, secure configuration, logging, monitoring, and encryption.
- Deliver logging and monitoring requirements compliant with PCI DSS v4.0.1, including centralized log collection, retention, and automated review mechanisms.
- Develop and tune detection and correlation rules in Wazuh, configuring file integrity monitoring and ensuring the deployment meets compliance standards.
- Complete the SAQ D for Service Providers and assemble all necessary supporting evidence sets for external assessment.
- Maintain compliance documentation such as dataflow diagrams, scoping/segmentation documentation, and operational policies.
- Engage and manage third-party providers for quarterly external vulnerability scanning and annual penetration testing.
- Own the delivery plan, including scheduling, dependency management, risk logs, and weekly status reporting to leadership.
- Document repeatable operational routines such as access reviews and change approvals for the ongoing use by the client team.