





Remote but niche PCI DSS and SIEM specialization significantly reduces qualified applicant density.
PCI DSS compliance and payments security strongly restrict transferable candidates outside fintech or security domains.
Mandatory PCI DSS, SIEM, AWS security, and compliance evidence requirements create strict technical and domain filters.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Own the annual PCI DSS v4.0.1 compliance cycle delivery, including implementing technical controls and completing SAQ D for Service Providers with evidence assembled to a standard suitable for QSA validation.
Configure and tune SIEM and host intrusion detection systems (Wazuh preferred) meeting PCI DSS logging and monitoring requirements and define alert triage/response processes.
Manage external vulnerability scanning, penetration testing engagements, and compliance documentation; maintain change management and operational routines for sustained compliance.
Proven experience delivering PCI DSS compliance cycles including v4.x, with direct involvement in SAQ D completion or RoC evidence preparation.
Hands-on AWS security engineering skills including IAM, VPC/network segmentation, audit logging, key management, and infrastructure-as-code; equivalent major public cloud experience considered.
Practical expertise with SIEM/log management platforms (preferably Wazuh or similar) for compliance, including rule development, file integrity monitoring and log retention.
Work Experience Required: Not explicitly mentioned in the JD.
Experienced security engineer with a strong focus on PCI DSS compliance lifecycle management and governance in cloud-hosted payment environments.
Technically proficient in cloud security and centralized logging solutions with demonstrated ability to independently manage delivery schedules, reporting, and risk.
Familiar with regulated payments/fintech or financial services environments and able to produce clear, high-quality compliance documentation for executive and external stakeholders.