Bachelor's degree in IT, Computer Science, Cybersecurity, or related field; advanced degree preferred.
6-9 years in IT Audit, Cybersecurity, Risk Advisory, Compliance, or PCI DSS assessments, with leadership experience.
PCI QSA certification required; additional certifications like CISA, CISSP, CISM, or ISO 27001 Lead Auditor preferred.
Strong understanding of PCI DSS requirements and cardholder data security controls.
Experience with PCI Point-to-Point Encryption (P2PE) environments is highly desirable.
Proven ability to manage multiple engagements and client relationships effectively.
Responsibilities
Manage PCI DSS assessments and readiness reviews as the engagement lead.
Evaluate security controls related to cardholder data environments (CDE).
Review and approve compliance-related policies and technical evidence.
Lead discussions with senior client stakeholders on complex compliance matters.
Develop risk-based recommendations and remediation plans for clients.
Finalize assessment deliverables, ensuring quality and accuracy before client delivery.
Supervise and mentor team members, providing performance feedback and career development support.
Act as a trusted advisor on PCI DSS requirements and security best practices.
Support business development through proposal writing and client presentations.
Contribute to practice development initiatives and internal knowledge sharing.
Benefits
Hybrid work model offering flexibility.
Opportunities for professional development and certifications.
Supportive team environment focused on mentorship.
Engagement in diverse projects across various industries.
Access to resources for enhancing technical skills and knowledge.
Full Job Description
Job Summary:
Frazier & Deeter is seeking an Advisory Manager to lead and manage PCI DSS assessment engagements, overseeing teams that evaluate security controls to validate compliance with payment card industry requirements. Direct the review of technical and process controls, oversee the identification of compliance gaps, and guide remediation strategy. Serve as the primary client relationship owner, engaging with senior client stakeholders and leadership to manage risk, review evidence, and drive compliance reporting. Oversee the delivery of advisory services that help organizations strengthen cardholder data security, sustain PCI DSS compliance, and contribute to the continued growth of the practice.
Duties & Responsibilities:
Manage and oversee PCI DSS assessments, gap analyses, and readiness reviews for clients across various industries, serving as engagement lead.
Direct the evaluation of the design and effectiveness of security controls related to cardholder data environments (CDE).
Review and approve policies, procedures, configurations, and technical evidence to validate PCI DSS compliance.
Oversee stakeholder interviews and walkthroughs performed by engagement teams, and personally lead discussions with senior client stakeholders on complex or high-risk matters.
Develop and present risk-based recommendations and remediation plans, advising client leadership on PCI DSS strategy.
Review and finalize assessment deliverables, including compliance reports, observations, and executive summaries, ensuring quality and accuracy prior to client delivery.
Manage engagement economics, including budgets, staffing, timelines, and scope, and communicate engagement status to clients and firm leadership.
Supervise, coach, and develop Seniors and Associates, including performance feedback, workpaper review, and career development support.
Act as a trusted advisor to client executives on PCI DSS requirements, security best practices, and evolving compliance expectations.
Support business development activities, including proposal development, client presentations, and identifying opportunities to expand services with existing and prospective clients.
Contribute to practice development initiatives, including methodology enhancement, training content, and internal knowledge sharing.
Education & Experience:
Bachelor's degree in information technology, Computer Science, Cybersecurity, Information Systems, or a related field; advanced degree a plus.
6-9 years of experience in IT Audit, Cybersecurity, Risk Advisory, Compliance, or PCI DSS assessments, including experience leading engagement teams.
PCI QSA certification required; additional certifications such as CISA, CISSP, CISM, CRISC, or ISO 27001 Lead Auditor required or strongly preferred.
Strong understanding of PCI DSS requirements, payment card processing environments, and cardholder data security controls.
Experience with PCI Point-to-Point Encryption (P2PE) environments, including validated P2PE solutions, assessment readiness, implementation reviews, or related compliance activities, is highly desirable.
Extensive experience conducting and overseeing compliance assessments, control testing, gap assessments, and remediation validation activities.
Familiarity with IT General Controls (ITGCs), access management, vulnerability management, network security, encryption, and logging/monitoring controls.
Proven experience preparing and presenting assessment reports and executive summaries, and communicating findings to senior client stakeholders, executives, and boards.
Demonstrated experience managing multiple concurrent engagements, including budgets, staffing, and client relationships.
Experience supervising, mentoring, and developing staff, including formal performance management responsibilities.
Experience contributing to business development, proposal writing, and client relationship expansion.
Strong analytical, communication, stakeholder management, and project delivery skills with the ability to manage multiple engagements and teams simultaneously.
#LI - hybrid
About Frazier & Deeter
Frazier & Deeter is a public accounting firm that provides accounting, tax, audit, and advisory services to clients in various industries. The firm was founded in 1981 and is headquartered in Atlanta, Georgia. Frazier & Deeter has additional offices in Nashville, Tennessee; Tampa, Florida; and London, United Kingdom. The firm has been recognized as one of the top accounting firms in the United States by Accounting Today and Inside Public Accounting.