
Security Operations Engineer – PCI DSS
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in India.
• Implement and validate technical controls within the cardholder data environment, encompassing access management, secure configuration, logging and monitoring, vulnerability management, encryption and key management, and secure development practices.
• Provide logging and monitoring that complies with PCI DSS v4.0.1, which includes centralized audit-log collection, log protection, retention, automated review, time synchronization, critical-file change detection, and alerts for security-control failures.
• Collaborate with the DevOps engineer to deploy Wazuh; identify log sources and coverage, create and refine detection and correlation rules, set up file integrity monitoring and retention, ensure compliance, and generate evidence.
• Establish the client team's alert triage and response procedures.
• Complete SAQ D for Service Providers and compile supporting documentation.
• Keep updated network and cardholder data flow diagrams, scoping and segmentation documentation, policies, and operational procedures.
• Engage and supervise an Approved Scanning Vendor for quarterly external vulnerability assessments and drive remediation to achieve passing scans.
• Define the scope and coordinate penetration testing with a qualified independent provider; oversee remediation and retesting processes.
• Maintain due diligence for third-party service providers, including collection of partner AOC and shared-responsibility documentation.
• Take ownership of the delivery plan, schedule, dependencies, risk log, and weekly leadership updates.
• Enhance change-management practices ensuring that changes are proposed, approved, tested, and documented consistently.
• Document sustainable operational routines for the client team following the conclusion of the engagement.
• Proven experience in guiding an organization through PCI DSS compliance, ideally on multiple occasions and including v4.x.
• Familiarity with PCI DSS v4.0.1, including updates from v3.2.1 and requirements that will be mandatory from March 31, 2025.
• Direct experience in completing SAQ D or preparing evidence for a Report on Compliance.
• Practical AWS security engineering experience: IAM policy design, VPC and network segmentation, audit logging, secrets and key management, and infrastructure-as-code. Equivalent experience in another major public cloud will be considered if the candidate demonstrates transferable design judgment.
• Hands-on experience with SIEM or centralized log platforms in a compliance environment — onboarding log sources, parsing and normalization, developing correlation and alert rules, configuring file integrity monitoring, retention settings, and tuning to minimize false positives. Direct experience with Wazuh is a significant advantage; equivalent open-source stacks (OSSEC, Elastic Security, Graylog, Security Onion) are acceptable. Candidates should be able to specify the platforms they have worked with and describe their configurations, not just what they monitored.
• Practical experience in vulnerability management, logging and monitoring, access management, and establishing secure configuration baselines.
• Capability to independently plan, track, report, and escalate issues without the assignment of a project manager.
• Exceptional written English skills.
• Willingness to accurately document a control as not implemented if that reflects the true situation.
• Background in payments, fintech, or regulated financial services.
• Understanding of the acquirer, processor, and card scheme landscape.
• Experience with Level 1 service provider validation or guiding an organization from self-assessment to QSA-led assessment.
• Relevant certifications such as PCIP, ISA, CISSP, CISM, or equivalent.
• Proficiency in Jira administration and workflow configuration.
• Knowledge of ISO 27001 or SOC 2.
• Flexibility in work hours and location, prioritizing energy management over time management.
• Access to online learning platforms along with a budget for professional development.
• A collaborative environment with no silos, fostering learning and growth across teams.
• A vibrant social culture featuring team lunches, social events, and opportunities for creative contributions.
• Health insurance.
• Leave benefits.
• Provident Fund.
• Gratuity.
AlphaSense
Charter Technology Solutions
Viatris
Zscaler
Get handpicked remote jobs straight to your inbox weekly.