
Tech Risk & Controls Lead -PCI Compliance
- Atlanta, GA
- Permanent
- Full-time
- Ensure effective identification, quantification, communication, and management of technology risk, focusing on root cause analysis and resolution recommendations.
- Oversee PCI assessments within firm standards and procedures according to methodology and frameworks, adhering to time sensitive deadlines.
- Capture, review and analysis of PCI required documentation, ensuring quality and suitability that meets PCI SSC requirements.
- Work with Business Leads & control owners and other members of the PCI team to determine and validate scope.
- Proactively monitor Key Risk Parameters to identify non-compliance and assist in remediation including potential compensating controls to address security, risk and control gaps.
- Develop and maintain robust relationships, becoming a trusted partner with LOB technologists, assessments teams, and data officers to facilitate cross-functional collaboration and progress toward shared goals.
- Execute reporting and governance of controls, policies, issue management, and measurements, offering senior management insights into control effectiveness and inform governance work.
- Proactively monitor and evaluate control effectiveness, identify gaps, and recommend enhancements to strengthen risk posture and regulatory compliance.
- Formal training or certification on security concepts and 5+years of applied experience.
- Good experience with technology risk and controls, risk based consulting, risk assessments, audit and regulatory activities in the PCI Data Security Standards.
- Hands on experience with implementation and oversight of technology risk and controls, coordination of activities for audits and assessing in an assigned environment.
- Good experience with risk management frameworks, industry standards, and financial industry regulatory requirements.
- Proficient knowledge and expertise in data security, risk assessment & reporting, control evaluation, design, and governance, with a proven record of implementing effective risk mitigation strategies.
- Demonstrated ability to influence executive-level strategic decision-making and translating technology insights into business strategies for senior executives.
- Current or Prior PCI QSA/ISA certification.
- Knowledge of process-focused methodologies for ITrelated activities (Change Management, Incident Management, and SDLC).
- IT Risk and Process frameworks such as COSO, COBIT, NIST, Cybersecurity Horizontal reviews, ITIL.
eQuest