PCI Compliance & Access Review Specialist (Security Engineer)

TESO Group

• $100K — $150K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in cybersecurity or computer science preferred
  • 4+ years in security engineering/operations; PCI or GRC experience preferred
  • Proficient in EDR, SIEM, and vulnerability tooling
  • Familiar with PCI-DSS controls and IAM concepts
  • Skilled in Python scripting
  • Strong evidence discipline and principled approach
  • Ability to transition between technical and compliance tasks

Responsibilities

  • Build and operate security toolchain including EDR, email security, and MFA
  • Run vulnerability scans and manage baseline configurations for store and cloud
  • Conduct quarterly PCI scans and support remedial actions
  • Maintain evidence repository for compliance and assist with audits
  • Perform periodic access reviews for business systems and cloud services
  • Manage onboarding and offboarding of third-party access
  • Investigate and contain security incidents, providing reviews for system changes

Benefits

  • 401(k) and matching contributions
  • Paid Sick Leave
  • Employee discounts
  • Health insurance coverage
  • Paid Time Off (PTO)
Full Job Description
Position Overview

This specialist guards both the company's defenses and its compliance cadence, building and operating the security toolchain while managing the PCI calendar, access reviews, and evidence.

This role does not set company-level security strategy (owned by the Digital Information Manager); it lands controls onto systems and endpoints and keeps compliance continuously attained.

Job Responsibilities

  1. Security toolchain
    1. Build/operate EDR, email security, identity security, logging; land MFA and 802.1X.
    2. Run vulnerability scans and remediation; manage store and cloud baselines.
  2. PCI compliance
    1. Run quarterly scans, annual assessment, SAQ/ROC prep; drive remediation to closure.
    2. Maintain the evidence repository; support QSA and external audits.
  3. Access reviews
    1. Review business-system, cloud, and MSP access periodically.
    2. Manage third-party access (incl. warehouse-vendor remote access) onboarding, approval, revocation.
  4. Incidents & reviews
    1. Investigate, contain, and review security incidents.
    2. Provide security review for infrastructure and system changes.


Qualifications

  • Education: Bachelor's degree or above; cybersecurity or computer science preferred.
  • Experience: 4+ years in security engineering/operations; PCI or GRC experience preferred.
  • Knowledge & Skills: EDR/SIEM/vulnerability tooling; PCI-DSS controls and IAM concepts; Python scripting.
  • Competencies: Fast responder with strong evidence discipline; principled; switches fluently between technical and compliance work.


Compensation

  • $100,000 - $150,000 per year
  • Quarterly Performance Bonus: This position is eligible for a quarterly performance-based bonus, subject to the eligibility requirements, performance criteria, and terms of the Company's bonus program.


Benefits

  • 401(k) & 401(k) matching - subject to the eligibility requirements
  • Paid Sick Leave
  • Employee discount
  • Health insurance
  • Paid Time Off


Job Type: Full-Time (On-Site)

Similar Jobs

More Jobs at TESO Group

  • Store Manager - Beaverton
    $90K *
    Beaverton, OR 97007 (Washington County)
    Retail & Consumer Goods
    In-Person
  • Store Manager - Lynnwood
    $90K *
    Lynnwood, WA 98036 (Snohomish County)
    Retail & Consumer Goods
    In-Person
  • Full Stack Developer
    $110K — $140K *
    New York, NY 10025 (New York County)
    Information Technology
    In-Person
  • Full Stack Developer
    $110K — $140K *
    Flushing, NY 11355 (Queens County)
    Information Technology
    In-Person
  • Store Manager - Portland
    $90K *
    Portland, OR 97229 (Washington County)
    Retail & Consumer Goods
    In-Person

More Information Technology Jobs

Find similar PCI Compliance & Access Review Specialist (Security Engineer) jobs: