×
Register Here to Apply for Jobs or Post Jobs. X

Senior IT Security Engineer

Job in El Segundo, Los Angeles County, California, 90245, USA
Listing for: Los Angeles Times
Full Time position
Listed on 2025-12-02
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security, IT Consultant, Data Security
Job Description & How to Apply Below

Overview

The Senior IT Security Engineer will assess, recommend, and maintain a robust information security infrastructure and ensure the company’s adherence to policy compliance, such as Payment Card Industry Data Security Standards (PCI DSS). This position involves conducting thorough and independent assessments of the management, operational, and technical security protocols across the company’s cloud and on-premise Information Technology (IT) infrastructure. This role oversees project management for security initiatives, manages relationships with managed information security providers, and ensures the effectiveness of current cybersecurity measures.

This role will oversee risk management, ensure vulnerability compliance and reporting, handle internal controls, and contribute to IT optimization efforts.

Responsibilities
  • Oversee the Managed Security Services Provider (MSSP), ensuring their services and performance delivery are consistent with our published SLAs.
  • Conduct internal assessments and audits to ensure compliance with the most recent PCI DSS and other relevant security standards.
  • Collaborate with various departments to identify, evaluate, and mitigate vulnerabilities and risks in payment card processing environments.
  • Develop, maintain, and update a comprehensive PCI compliance program, including policies, procedures, and documentation.
  • Oversee the management of security infrastructure and ensure its robustness against potential threats.
  • Provide guidance and support to business units and IT teams on implementing secure payment card processing practices.
  • Liaise with external Qualified Security Assessors (QSAs) during annual PCI DSS assessments and facilitate the remediation of any identified gaps.
  • Train and educate staff on PCI DSS requirements and best practices for protecting cardholder data.
  • Track updates to PCI DSS standards and ensure timely implementation of required updates and changes within the organization.
  • Prepare Reports on Compliance (ROCs) and Self-Assessment Questionnaires (SAQs) for annual reporting on the Company's status to the Payment Card Industry Data Security Standard (PCI-DSS).
  • Present and obtain Senior IT Management approval of process improvements and implement process modifications successfully.
  • Determines whether company information systems comply with existing policies, standards, architectures, procedures, laws, regulations, and other requirements.
  • Generate and audit monthly vulnerability reports, quarterly network scans, and bi-annual penetration tests to ensure compliance and remediation tasks and activities are completed within SLA periods.
  • Work collaboratively with Application Support, Network Infrastructure, Enterprise Architecture & Dev Ops, Product & Program Management, Data Science, Digital Engineering, and IT Operations teams.
  • Work with the legal department to develop and maintain IT Security Compliance and Governance contract provisions for external service providers and vendors.
  • Perform quarterly follow-up activities to report on status and/or mitigation completion.
  • Assist in the development and maintenance of a robust incident response plan for security breaches and incidents involving cardholder data.
  • Generate regular reports on compliance status, security assessments, and remediation efforts for senior executive management and relevant stakeholders.
  • Participate in security and compliance projects as required.
  • Perform other tasks as assigned.
Requirements
  • Bachelor’s degree in Information Technology, Information Security, Computer Science (or a related field), and 8+ years of experience in information security, with specific experience in PCI DSS compliance OR 10+ years of experience in information security, with specific experience in PCI DSS compliance.
  • 6+ years of experience with security tools and technologies used for information security and compliance monitoring.
  • Expert knowledge of information security principles, vulnerability scanning, remediation, reporting, data protection laws, and payment industry standards.
  • Excellent analytical, problem-solving, and decision-making skills.
  • Adaptive communicator tailoring messages for diverse audiences.
  • Detail-oriented…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary