
Security Operations Engineer – PCI DSS
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Philippines.
• Implement and validate technical controls within the cardholder data environment, encompassing access management, secure configuration, logging and monitoring, vulnerability management, encryption and key management, and secure development practices.
• Enforce PCI DSS v4.0.1 logging and monitoring requirements, which include centralized audit-log collection, log protection, retention, automated log review, time synchronization, critical-file change detection, and failure alerting.
• Collaborate with the client's DevOps engineer on the deployment of Wazuh, ensuring compliance outcomes, necessary log-source coverage, detection and correlation rules, file-integrity monitoring, retention, validation, and evidence management.
• Establish the alert triage and response process for the client team.
• Complete SAQ D for Service Providers and compile the supporting evidence.
• Keep up-to-date network and cardholder data flow diagrams, scoping and segmentation documentation, policies, and operational procedures.
• Engage and oversee an Approved Scanning Vendor for quarterly external vulnerability scanning and lead remediation efforts to achieve passing scans.
• Plan and coordinate penetration testing with a qualified independent provider; manage remediation and subsequent retesting.
• Maintain due diligence for third-party service providers, including the collection of partner AOC and shared-responsibility documentation.
• Take ownership of the delivery plan, schedule, dependencies, risk log, and weekly reporting to leadership.
• Enhance change-management practices to ensure that changes are consistently raised, approved, tested, and documented.
• Document repeatable operational routines for the client team following the conclusion of the engagement.
• Successfully manage the annual PCI DSS compliance cycle throughout a three-month contract and prepare the Attestation of Compliance for executive approval.
• Proven experience guiding an organization through PCI DSS compliance, preferably more than once and ideally involving v4.x.
• Familiarity with PCI DSS v4.0.1, including the updates from v3.2.1 and the requirements that will be mandatory from March 31, 2025.
• Direct experience in completing SAQ D or preparing evidence for a Report on Compliance.
• Practical AWS security engineering experience, including IAM policy design, VPC and network segmentation, audit logging, secrets and key management, and infrastructure-as-code.
• Equivalent experience in another major public cloud will be considered, provided the candidate can demonstrate transferable design judgment.
• Hands-on experience with SIEM or centralized log platforms within a compliance framework, covering log source onboarding, parsing and normalization, correlation and alert rule development, file integrity monitoring, retention configuration, and tuning to minimize false positives.
• Direct experience with Wazuh is a strong plus; other equivalent open-source stacks (OSSEC, Elastic Security, Graylog, Security Onion) are acceptable.
• Ability to identify platforms used and explain the configurations made, rather than solely what was monitored.
• Practical expertise in vulnerability management, logging and monitoring, access management, and establishing secure configuration baselines.
• Capability to independently plan, track, report, and escalate; no project manager will be provided.
• Excellent proficiency in written English.
• Willingness to accurately document a control as not in place when that is the correct status.
• Experience in payments, fintech, or regulated financial services is desirable.
• Knowledge of the acquirer, processor, and card scheme landscape is preferred.
• Experience with Level 1 service provider validation or transitioning an organization from self-assessment to QSA-led assessment is advantageous.
• PCIP, ISA, CISSP, CISM, or equivalent certification is desirable.
• Experience in Jira administration and workflow configuration is a plus.
• Familiarity with ISO 27001 or SOC 2 is beneficial.
• Flexibility in work hours and location, emphasizing energy management over strict time constraints.
• Access to online learning platforms and a budget allocated for professional development.
• A collaborative environment free of silos, promoting learning and growth across teams.
• A vibrant social culture featuring team lunches, social events, and opportunities for creative contributions.
• Generous leave benefits.
Capgemini
Teamified
Get handpicked remote jobs straight to your inbox weekly.