Job Title: PCI DSS Auditor
We are looking for an experienced and detail-oriented PCI DSS Auditor to join our Information Security team. The ideal candidate will be responsible for planning, coordinating, and executing internal and external PCI DSS assessments to ensure compliance with PCI DSS v4.0 standards. The role involves conducting comprehensive risk assessments, performing gap analyses, evaluating security controls, and identifying areas of non-compliance across the organization's cardholder data environment.
The PCI DSS Auditor will work closely with cross-functional teams, including IT, Security, Infrastructure, and Business stakeholders, to collect audit evidence, validate technical and administrative controls, and recommend practical remediation plans. The candidate will prepare detailed audit reports, present findings and risk assessments to senior management, and support remediation activities by tracking corrective actions through to successful closure. The role also requires close coordination with Qualified Security Assessors (QSAs) during formal PCI DSS certification and validation exercises.
Additionally,
the successful candidate will maintain and update security policies, procedures, standards, and control documentation related to PCI DSS compliance. They will stay informed about changes to PCI DSS requirements, emerging security threats, and industry best practices, ensuring the organization remains compliant and audit-ready. The role also includes conducting awareness sessions and providing guidance to internal teams on PCI DSS controls and compliance obligations.
Required Qualifications:
- Bachelor's degree in Information Security, Computer Science, Information Systems, or a related field.
- 3–5 years of experience in IT auditing, cybersecurity, risk management, or compliance.
- Solid hands-on experience with PCI DSS v4.0 assessments and audit methodologies.
- Familiarity with security frameworks such as NIST, ISO 27001, and CIS Controls.
- Solid understanding of network security, encryption, identity and access management, vulnerability management, and security governance.
- Excellent analytical, communication, documentation, and stakeholder management skills.
📌 PCI DSS Auditor (India)
🏢 SISA
📍 India