PCI Compliance Analyst
Listed on 2026-09-04
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Back PCI Compliance Analyst
Infrastructure & Security Philadelphia , PA Contract On-Site Sep 1, 2026
Philadelphia, PA 19103 (hybrid)
Pay: $70,Position Overview
We are seeking a Compliance Analyst to support cybersecurity and compliance initiatives focused on Payment Card Industry (PCI) requirements across a large, complex enterprise environment. This role will partner closely with cybersecurity teams, engineers, data teams, application owners, infrastructure teams, and business stakeholders to help ensure systems handling payment card data remain compliant with PCI standards and are prepared for internal and external audits.
The ideal candidate will possess a strong understanding of PCI compliance, payment card processing environments, and enterprise technology infrastructure. This individual will leverage data analysis, compliance reporting, and technical investigation skills to identify vulnerabilities, assess compliance gaps, and support remediation efforts across a large asset footprint.
Key Responsibilities- Support PCI compliance programs and initiatives across enterprise environments that process, transmit, or store payment card data.
- Assist in the preparation and execution of internal and external PCI assessments and attestation audits.
- Partner with cybersecurity, compliance, engineering, infrastructure, and application teams to ensure adherence to PCI requirements.
- Identify compliance gaps, vulnerabilities, and misconfigurations impacting PCI compliance.
- Analyze large datasets to validate compliance controls and support audit activities.
- Execute SQL queries and perform data analysis to support compliance investigations and reporting.
- Work with system owners to review findings and develop remediation plans.
- Track remediation efforts and provide status updates to stakeholders and leadership.
- Assess compliance scope across network devices, servers, cloud environments, applications, workstations, databases, and supporting infrastructure.
- Review technical documentation, system inventories, architecture diagrams, and control evidence.
- Support risk assessments and compliance reporting activities.
- Assist with policy, process, and control documentation related to PCI compliance requirements.
- Maintain accurate records of findings, remediation activities, and audit evidence.
- Monitor compliance trends and identify opportunities for process improvement and risk reduction.
- 3+ years of experience in compliance, cybersecurity, risk management, information security, audit support, or a related field.
- Strong understanding of PCI DSS compliance requirements.
- Experience supporting PCI audits, assessments, compliance reviews, or attestation activities.
- Knowledge of payment card processing environments and the technologies involved in handling payment card data.
- Strong SQL skills with the ability to query, analyze, and validate large datasets.
- Experience analyzing compliance data across large technology environments.
- Understanding of enterprise infrastructure, including:
- Network devices
- Servers
- Applications
- Databases
- Cloud platforms
- End-user workstations
- Experience identifying vulnerabilities, compliance gaps, and security control deficiencies.
- Ability to work with technical and non-technical stakeholders to drive remediation efforts.
- Strong analytical, investigative, and problem-solving skills.
- Excellent written and verbal communication skills.
- Experience working within a cybersecurity, governance, risk, and compliance (GRC), or audit organization.
- Familiarity with payment processing systems, merchant environments, and cardholder data environments (CDE).
- Experience supporting large-scale compliance programs involving thousands of technology assets.
- Knowledge of vulnerability management and remediation processes.
- Experience working with security assessment tools, reporting platforms, and compliance dashboards.
- Familiarity with cloud security and compliance frameworks.
- Experience working alongside external auditors and assessors.
- Knowledge of regulatory and industry security standards beyond PCI.
- Ability to analyze complex technical environments and identify areas…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).