
Security Operations Engineer – PCI DSS
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Sri Lanka.
• Implement and validate technical controls within the cardholder data environment, encompassing access management, secure configuration, logging and monitoring, vulnerability management, encryption and key management, as well as secure development practices.
• Deliver logging and monitoring requirements for PCI DSS v4.0.1, which include centralized audit-log collection, log protection, retention, automated review, time synchronization, critical-file change detection, and failure alerting.
• Collaborate with the DevOps engineer on the Wazuh rollout, taking ownership of compliance outcomes such as log-source coverage, detection and correlation rules, file-integrity monitoring, retention, validation, and evidence gathering.
• Establish the alert triage and response procedure for daily operations with the client team.
• Complete SAQ D for Service Providers and compile supporting documentation.
• Maintain network and cardholder data flow diagrams, scoping and segmentation documentation, policies, and operating procedures.
• Engage and oversee an Approved Scanning Vendor for quarterly external vulnerability scanning and drive remediation efforts.
• Scope and coordinate penetration testing with a qualified independent provider; manage remediation and retesting processes.
• Maintain due diligence for third-party service providers, including partner AOC collection and shared-responsibility documentation.
• Own the delivery plan, scheduling, dependencies, risk log, and weekly leadership reporting.
• Enhance change management practices to ensure changes are raised, approved, tested, and documented consistently.
• Document repeatable operational routines for the client team following engagement completion.
• Proven experience guiding an organization through PCI DSS compliance, preferably multiple times and ideally including v4.x.
• Proficient understanding of PCI DSS v4.0.1, including the changes from v3.2.1 and the requirements that will be mandatory from 31 March 2025.
• Direct experience in completing SAQ D, or preparing evidence for a Report on Compliance.
• Practical AWS security engineering experience: IAM policy design, VPC and network segmentation, audit logging, secrets and key management, and infrastructure-as-code.
• Equivalent experience in another major public cloud will be considered if the candidate can demonstrate transferable design judgment.
• Hands-on experience with SIEM or centralized log platforms in a compliance context, including log source onboarding, parsing and normalization, correlation and alert rule development, file integrity monitoring, retention configuration, and tuning to minimize false positives.
• Direct experience with Wazuh is a significant advantage; equivalent open-source stacks (OSSEC, Elastic Security, Graylog, Security Onion) are acceptable.
• Candidates should be able to identify the platforms they have worked with and explain their configurations, not just what they monitored.
• Practical experience in vulnerability management, logging and monitoring, access management, and secure configuration baselines.
• Ability to independently plan, track, report, and escalate issues without a project manager assigned.
• Excellent proficiency in written English.
• Willingness to document a control as not in place when that accurately reflects the situation.
• Background in payments, fintech, or regulated financial services.
• Understanding of the acquirer, processor, and card scheme landscape.
• Experience with Level 1 service provider validation, or guiding an organization from self-assessment to QSA-led assessment.
• Relevant certifications such as PCIP, ISA, CISSP, CISM, or equivalent.
• Experience with Jira administration and workflow configuration.
• Familiarity with ISO 27001 or SOC 2 standards.
• Flexibility in work hours and location, focusing on managing energy rather than time.
• Access to online learning platforms and a budget for professional development.
• A collaborative environment free of silos, promoting learning and growth across teams.
• A vibrant social culture featuring team lunches, social events, and opportunities for creative contributions.
• Comprehensive leave benefits.
Capgemini
Teamified
Get handpicked remote jobs straight to your inbox weekly.