PCI Compliance & Access Review Specialist (Security Engineer)

TESO Group

• $100K — $150K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in cybersecurity or computer science is preferred
  • Over 4 years of experience in security engineering or operations
  • Familiarity with PCI compliance or Governance, Risk, and Compliance (GRC) processes
  • Proficient with EDR, SIEM, and vulnerability management tools
  • Strong Python scripting skills and an ability to work with technical and compliance contexts

Responsibilities

  • Build and operate the security toolchain, including EDR and email security
  • Conduct vulnerability scans and manage remediation efforts
  • Run PCI compliance assessments and maintain evidence for audits
  • Periodically review access for business systems and cloud environments
  • Investigate and respond to security incidents effectively

Benefits

  • 401(k) plan with company matching
  • Paid sick leave to support employees during illness
  • Employee discounts on company products and services
  • Comprehensive health insurance coverage
  • Generous paid time off to encourage work-life balance
Full Job Description
Position Overview

This specialist guards both the company's defenses and its compliance cadence, building and operating the security toolchain while managing the PCI calendar, access reviews, and evidence.

This role does not set company-level security strategy (owned by the Digital Information Manager); it lands controls onto systems and endpoints and keeps compliance continuously attained.

Job Responsibilities

  1. Security toolchain
    1. Build/operate EDR, email security, identity security, logging; land MFA and 802.1X.
    2. Run vulnerability scans and remediation; manage store and cloud baselines.
  2. PCI compliance
    1. Run quarterly scans, annual assessment, SAQ/ROC prep; drive remediation to closure.
    2. Maintain the evidence repository; support QSA and external audits.
  3. Access reviews
    1. Review business-system, cloud, and MSP access periodically.
    2. Manage third-party access (incl. warehouse-vendor remote access) onboarding, approval, revocation.
  4. Incidents & reviews
    1. Investigate, contain, and review security incidents.
    2. Provide security review for infrastructure and system changes.


Qualifications

  • Education: Bachelor's degree or above; cybersecurity or computer science preferred.
  • Experience: 4+ years in security engineering/operations; PCI or GRC experience preferred.
  • Knowledge & Skills: EDR/SIEM/vulnerability tooling; PCI-DSS controls and IAM concepts; Python scripting.
  • Competencies: Fast responder with strong evidence discipline; principled; switches fluently between technical and compliance work.


Compensation

  • $100,000 - $150,000 per year
  • Quarterly Performance Bonus: This position is eligible for a quarterly performance-based bonus, subject to the eligibility requirements, performance criteria, and terms of the Company's bonus program.


Benefits

  • 401(k) & 401(k) matching - subject to the eligibility requirements
  • Paid Sick Leave
  • Employee discount
  • Health insurance
  • Paid Time Off


Job Type: Full-Time (On-Site)

Similar Jobs

More Jobs at TESO Group

More Information Technology Jobs

Find similar PCI Compliance & Access Review Specialist (Security Engineer) jobs: