Security Operations Engineer - PCI DSS
New
T
TeamifiedFintech Payments
IndiaContractSenior
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Languages
- English
- Required Skills
- AWS
Requirements
- Demonstrable experience leading an organization through PCI DSS compliance, ideally with v4.x.
- Deep working knowledge of PCI DSS v4.0.1 and the specific mandatory requirements.
- Direct experience completing the Self-Assessment Questionnaire (SAQ) D or preparing evidence for a Report on Compliance.
- Hands-on AWS security engineering expertise, specifically in IAM policy design, VPC segmentation, and infrastructure-as-code.
- Hands-on experience with SIEM or centralized log platforms (e.g., Wazuh, OSSEC, Elastic Security, Graylog) in a compliance context.
- Proven proficiency in vulnerability management and establishing secure configuration baselines.
- Excellent written English proficiency for high-stakes documentation and evidence preparation.
- Ability to independently plan, track, report, and escalate project status without dedicated project management support.
- Nice to have: Experience with Level 1 service provider validation or migrating from self-assessment to QSA-led assessments.
- Nice to have: Relevant professional certifications such as PCIP, ISA, CISSP, or CISM.
Responsibilities
- Implement and verify technical controls across the cardholder data environment, including access management, secure configuration, logging, monitoring, and encryption.
- Deliver logging and monitoring requirements compliant with PCI DSS v4.0.1, including centralized log collection, retention, and automated review mechanisms.
- Develop and tune detection and correlation rules in Wazuh, configuring file integrity monitoring and ensuring the deployment meets compliance standards.
- Complete the SAQ D for Service Providers and assemble all necessary supporting evidence sets for external assessment.
- Maintain compliance documentation such as dataflow diagrams, scoping/segmentation documentation, and operational policies.
- Engage and manage third-party providers for quarterly external vulnerability scanning and annual penetration testing.
- Own the delivery plan, including scheduling, dependency management, risk logs, and weekly status reporting to leadership.
- Document repeatable operational routines such as access reviews and change approvals for the ongoing use by the client team.
View Full Description & ApplyYou'll be redirected to the employer's site