PCI DSS Compliance:
1. Lead the organizations efforts to achieve and maintain PCI DSS certification. PIC-PIN, PCI S3 and PCI P2PE
2. Develop, implement, and enforce policies and procedures to comply with PCI DSS requirements, including the 12 core domains (e.g., firewall configurations, encryption, secure system development).
3. Act as the primary liaison with Qualified Security Assessors (QSAs) and other auditors during compliance audits.
4. Conduct periodic PCI DSS gap analyses, audits, and readiness assessments to identify non-compliance areas and recommend corrective actions.
5. Ensure secure payment transaction processes across all environments (e.g., cardholder data environments, payment gateways, and point-of-sale systems).
Risk Management:
1. Identify, assess, and mitigate risks associated with payment security, focusing on cardholder data protection.
2. Implement risk treatment plans in alignment with PCI DSS risk management guidelines.
3. Monitor and report on key risk indicators (KRIs) for payment environments.
4. Ensure robust incident response planning, testing, and execution as per PCI DSS requirements.
Data Security:
1.
Collaborate with IT and DevOps teams to ensure compliance with PCI DSS requirements for encryption, tokenization, and secure transmission of cardholder data.
2. Oversee the implementation and management of access control measures to restrict access to cardholder data based on business need-to-know.
3. Monitor logging and monitoring systems to detect and respond to potential security breaches as required by PCI DSS Requirement 10.
Training and Awareness:
1. Develop and deliver PCI DSS compliance training for employees, focusing on secure handling of payment card data.
2. Promote a culture of payment security awareness across the organization.
Required Qualifications:
1. Education: Bachelors degree in IT, Cybersecurity, Risk Management, or related fields.
2. Certifications:
- Mandatory: PCI Qualified (PCIP) or PCI DSS Implementer.
- Preferred: CISA, CISSP, or CISM.
1. Experience:
- 3 -5 years in governance, risk, and compliance roles, with significant experience in PCI DSS compliance programs.
- Proven track record in managing audits and certification processes related to payment security.
📌 Security Lead (Noida)
🏢 Paytm
📍 Noida