
Manager - Technology Risk & Control (PCI DSS)
- Phoenix, AZ
- $110,000-190,000 per year
- Permanent
- Full-time
- Conduct validation activities for applications and infrastructure that comprise the American Express cardholder data environments by following the test procedures prescribed by the PCI DSS
- Work in conjunction with external QSAs to ensure effective and efficient execution of assigned project tasks in conformance with professional and department standards, timelines, and objectives
- Develop evidence packages and other documentation to facilitate QSA validation activities
- Provide PCI subject matter expertise to a wide range of technologies and applicable standards
- Assist with development of alternative approaches or compensating controls that meet security objectives
- Validate that actions or decisions taken to address gaps are appropriate and reported accurately
- Assist with response efforts to implement process improvements for the PCI Program Management Office (PMO) in response to findings and recommendations from internal and external teams
- Frequent collaboration and communication with key stakeholders, including vendor partners and internal teams
- Create high quality and executive-ready documentation and presentations
- 5+ years relevant experience with compliance and risk management in Information Security with a focus on PCI DSS
- Current or former PCI QSA certification
- Current PCI ISA certification, or commitment to acquire certification
- Proven ability to lead and manage multiple, simultaneous assessments
- Strong collaboration skills working within a team environment delivering results for assigned tasks
- Ability to communicate effectively and succinctly while translating complex, technical information to non-technical audiences
- Must be able to interpret vulnerability reports and advise technology owners as needed
- Sound knowledge and understanding of vulnerability management (i.e.: awareness of scanning tools like Tenable, Twistlock, Qualys, etc.)
- Knowledge of secure configurations for Linux and Windows servers, hardware and software vendor appliances
- Well versed with network segmentation tools and techniques (i.e.: firewalls, IP switches, routers, proxy gateways, API gateways, service mesh, etc.)
- Sound understanding of encryption mechanisms for data at rest and data in transit
- Ability to read, understand, create and enhance architecture and data flow diagrams
- Understanding of virtualization technologies (i.e.: VMware, Citrix, etc.)
- Understanding of various database and distributed technologies (i.e.: Cassandra, Redis, Oracle DB, Couchbase, PostgreSQL, HDFS, Spark, Cloudian, NetApp ONTAP etc.)
- Sound knowledge of container orchestration tools and technologies (i.e.: container images, Openshift, Kubernetes, Docker, etc.)
- Competitive base salaries
- Bonus incentives
- 6% Company Match on retirement savings plan
- Free financial coaching and financial well-being support
- Comprehensive medical, dental, vision, life insurance, and disability benefits
- Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need
- 20+ weeks paid parental leave for all parents, regardless of gender, offered for pregnancy, adoption or surrogacy
- Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)
- Free and confidential counseling support through our Healthy Minds program
- Career development and training opportunities