PCI Penetration Testing Coordinator , NY
Listed on 2026-01-03
-
IT/Tech
Cybersecurity, Data Security
Location: New York
PCI Penetration Testing Coordinator job York, NY.
NBCUniversal is one of the world's leading media and entertainment companies. We create world-class content, which we distribute across our portfolio of film, television, and streaming, and bring to life through our theme parks and consumer experiences. We own and operate leading entertainment and news brands, including NBC, NBC News, MSNBC, CNBC, NBC Sports, Telemundo, NBC Local Stations, Bravo, USA Network, and Peacock, our premium ad‑supported streaming service.
We produce and distribute premier filmed entertainment and programming through Universal Filmed Entertainment Group and Universal Studio Group, and have world‑renowned theme parks and attractions through Universal Destinations & Experiences. NBCUniversal is a subsidiary of Comcast Corporation.
Our impact is rooted in improving the communities where our employees, customers, and audiences live and work. We have a rich tradition of giving back and ensuring our employees have the opportunity to serve their communities. We champion an inclusive culture and strive to attract and develop a talented workforce to create and deliver a wide range of content reflecting our world.
Job DescriptionNBCUniversal’s Cyber Governance Risk and Compliance team is seeking a PCI Scanning & Penetration Testing Coordinator to lead and manage the organization’s PCI ASV scanning and penetration testing programs. This role serves as the central liaison between internal business units, technical teams, and external vendors, while also possessing the technical capability to conduct penetration tests independently when required. The successful candidate will ensure timely execution, remediation, and compliance with PCI DSS requirements across all business entities.
Responsibilities:
- Managing and maintaining PCI ASV scan schedules across all business units.
- Initiating and tracking ad hoc scans, ensuring timely execution and reporting.
- Validating remediation of vulnerabilities and special notes, coordinating with technical teams and GRC.
- Acting as the single point of contact for the ASV vendor, resolving anomalies and portal issues.
- Negotiating false positives and scan disputes with the vendor on behalf of business units.
- Coordinating annual and ad‑hoc PCI penetration tests across applicable environments.
- Scoping, scheduling, and executing penetration tests internally when vendor support is unavailable or impractical.
- Performing manual and automated testing techniques including network, web application, and system‑level assessments.
- Analyzing test results, documenting findings, and providing remediation guidance aligned with PCI DSS.
- Tracking remediation efforts and maintaining centralized documentation of test reports and compliance evidence.
- Generating and maintaining reports for internal stakeholders, auditors, and compliance attestations.
- Interfacing with business unit technical teams to ensure understanding and prioritization of findings.
- Providing guidance and support to teams with limited PCI knowledge or bandwidth.
Requirements:
- Bachelor’s Degree in an IT‑related field and/or equivalent work experience.
- Minimum 3–5 years of experience in PCI compliance, vulnerability management, or penetration testing.
- Strong understanding of PCI DSS requirements, especially ASV scanning and penetration testing controls.
- Proficiency in penetration testing methodologies (OWASP, NIST SP 800‑115, PTES).
- Experience with tools such as Burp Suite, Nmap, Nessus, Metasploit, Kali Linux, and scripting (Python, Bash).
- Working knowledge of network protocols, web application architecture, and common vulnerabilities.
- Experience working with external vendors and internal technical teams.
- Excellent organizational, communication, and documentation skills.
- Ability to manage multiple concurrent projects and deadlines.
- Certifications (at least one Required):
- Offensive Security Certified Professional (OSCP)
- GIAC Penetration Tester (GPEN)
- Certified Ethical Hacker (CEH)
- Certifications (Preferred):
- PCI Internal Security Assessor (ISA)
- GIAC Web Application Penetration Tester (GWAPT)
- CISSP or CISM for broader security leadership alignment
Additional Requirements:
- Fu…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).