Develop, implement, and maintain information security policies, standards, and procedures.
As an Information Security Assessor (QSA), you will lead and support client engagements focused on evaluating security controls, validating compliance against regulatory frameworks, and providing structured, evidence-based reporting.
Must have experience with the network and the security
Conduct information security risk assessments and recommend mitigation plans.
Ensure compliance with security frameworks and regulatory requirements (PCI is Must)
Coordinate with internal teams and external auditors during PCI DSS audits and certification processes.
Hands-on experience with PCI DSS compliance and audit processes is Must
· Responsible for protecting the organization's systems, networks, and data from cyber threats and security breaches by implementing effective security controls and ensuring compliance with security policies.
Perform Security Assessments: Lead and execute PCI DSS assessments, including scoping client environments, performing control validation, and producing required deliverables such as Reports on Compliance (ROC), Attestations of Compliance (AOC), and Self-Assessment Questionnaires (SAQ), as applicable.
Develop and maintain information security governance frameworks, policies, and procedures.
Develop Assessment Reports: Produce clear, structured reports that document compliance status, supporting evidence, and identified gaps in alignment with applicable regulatory requirements.
Provide Advisory Support: Guide clients in preparation for assessments by assisting with scoping, identifying sensitive data flows, performing gap analyses, and outlining remediation actions.
Support Technical Documentation: Contribute to or lead the development and review of policies and procedures to align with compliance requirements and industry standards.
Assist in the development, implementation, and maintenance of GRC policies, standards, and procedures.
Conduct risk assessments to identify, analyze, and evaluate potential risks and vulnerabilities across various business functions and IT systems.
Collaborate with cross-functional teams to ensure alignment of GRC activities with business objectives.
Requirements:
Bachelor's degree in Computer Science, Information Technology, or a related field.
Must have experience with the network and the security
·English Level Excellent to fluent is must (written and spoken).
4+ years of experience in Information Security, Governance, Risk, and Compliance (GRC), or a similar role.( Must have experience with the network
Strong documentation, analytical, and reporting skills.
Excellent communication and stakeholder management skills.
Strong knowledge of security standards and compliance frameworks, including PCI DSS, and other relevant regulations.
Practical experience with PCI DSS compliance, including gap assessments, audit preparation, evidence collection, and remediation activities.