Information Security Consultant, PCI Compliance; IT SCRTY ANL TX
Listed on 2026-06-03
-
IT/Tech
Cybersecurity, Information Security
Overview
Reporting to the Deputy Chief Information Security Officer, the ISO Payment Card Industry Data Security Standard (PCI DSS) Compliance Consultant serves as a technical lead and subject matter expert, working with the UC Davis Merchant Support team in the UC Davis Controls and Accountability Unit, UC Davis Health technical and security personnel, qualified UC Davis Internal Security Assessors (ISAs), qualified external assessors (QSAs), IT and Security specialists, senior management, and Campus and UC Davis Health merchants to ensure all merchants are fully compliant with the PCI DSS year-round, and to complete the annual PCI DSS attestation through an external QSA audit company.
Job Summary:
Reporting to the Deputy Chief Information Security Officer, the PCI DSS Compliance Consultant serves as a technical lead and subject matter expert with the UC Davis Merchant Support team to ensure PCI DSS compliance and annual attestations.
The Consultant leads and administers key aspects of the compliance program, including development of compliance standards and training of UC Davis employees who contribute to the program, analyzes complex compliance risks, monitors progress and alerts about potential challenges to compliance, and champions the program as PCI DSS evolves. The Consultant acts as the senior compliance assessor and mentor, providing strategic reporting and recommendations, and monitors compliance status to senior management.
This position provides oversight and program leadership to ensure ongoing compliance. Responsible for managing program requirements, guiding remediation efforts, and strengthening coordination across units that process payment card data, ensuring proactive and systematic compliance.
Please note:
To be considered for this position, candidates must already have authorization to work in the United States. Unfortunately, we are unable to provide visa sponsorship at this time.
(In-State Only)
To see IET job postings, please visit (Use the "Apply for this Job" box below)./jobs
QualificationsMinimum Qualifications
- PCI DSS Internal Security Assessor (ISA) certification
- Bachelor's degree in a related area and/or equivalent experience/training
- Minimum 3-4 years of experience working in information security, information technology, or risk management with a focus on PCI DSS compliance
- Experience working with industry security standards, frameworks, regulations, and best practices. Experience writing and providing detailed status reports
- Experience building and maintaining positive relationships and meeting client expectations with an emphasis on quality and timeliness of work
- Experience managing and leading multiple projects under strict timelines in a demanding/dynamic environment, working with highly confidential information
- Knowledge of information security fundamentals, risk management fundamentals and the PCI DSS
- Written/verbal communication skills, interpersonal/collaborative skills, & ability to consult clients and communicate security/risk-related concepts to technical and non-technical audiences
- Certified Information System Security Professional (CISSP), Certified Information System Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), or similar certification
- Minimum 4 years of experience supporting information security activities and/or information risk management in a large organization
- Experience in higher education, government, research, or the public sector
- Experience conducting risk assessments and developing mitigation plans
- Experience reviewing attestation reports (e.g., SOC 1/2), certifications, security testing reports, etc
- Implementation level knowledge of information security standards and frameworks (e.g., ISO/IEC 27001/27002, PCI-DSS, NIST Cybersecurity Framework, FedRAMP, etc.)
- 40% - PCI DSS Compliance and Information Security Consulting & Coordination
- 40% - Compliance Assessments
- 20% - Security Operations, Incident Response & Program Support
The Information Security Office (ISO), a division of Information & Educational Technology (IET), helps protect the confidentiality, availability, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).