RAS - Security and Privacy Risk Consulting Manager - PCI Compliance

RSM US   •  

Charlotte, NC

Industry: Accounting, Finance & Insurance


Less than 5 years

Posted 171 days ago

This job is no longer available.

In order to address the most critical data security and compliance needs of our clients, RSM US LLP has established the Security and Privacy Risk Consulting Services group, comprised of more than 150 professionals dedicated exclusively to serving the cybersecurity needs of our clients. This group includes experienced consultants located throughout the country dedicated to helping clients with preventing, detecting, and responding to securitythreats that may affect their critical systems and data.

We serve a diverse client base within a variety of industries, and we are relied upon to provide expertise within areas of security testing, architecture, governance, compliance, and digitalforensics. All organizations that store, process, or transmit credit card data must comply with the PCI Data Security Standard (DSS). In addition, these organizations must annually attest to their compliance either through a Self-Assessment Questionnaire or a Report of Compliance. Regardless of the reporting method, it must be completed by a qualified assessor.

As a PCI Certified Qualified Assessor (QSA) Firm, RSM is seeking individuals with exposure to implementing or assessing information technology controls designed to protect cardholder data. Responsibilities will include working with clients to determine if the design and effectiveness of their IT controls are in place to meet PCI DSS control objectives:

  • Implementation and management of firewalls
  • Hardening of servers and network devices
  • Protecting stored cardholder data
  • Data encryption, both at rest and in transit
  • Protecting systems from Malware
  • Developing and maintaining secure applications
  • Implementing "least privileged" access controls around cardholder data User Account Provisioning
  • Physical Access Controls
  • Logging and Monitoring Vulnerability and Penetration Testing Policies, Procedures, and Standards for securing cardholder data

Required Qualifications:

  • Bachelor's degree in computer science or related field from an accredited college/university or a minimum of 4 years of experience in lieu of degree
  • Minimum 3 years of experience within the cybersecurity space, with a preference for prior consulting or professional services backgrounds
  • Ability to travel as needed
  • Proven experience in completing the PCI DSS Report on Compliance (RoC) and Attestation of Compliance (AOC) for at least three Level 1 merchants
  • Exposure to Operating System, Web Server, and Database security

Preferred qualifications that may vary by candidate:

PCI Qualified Security Assessor (QSA) or PCI Internal Security Assessor (ISA)
One or more of the following certifications: 

    • Certified Information Systems Security Professionals® (CISSP®);
    • Certified ISO 27001 Lead Implementer
    • Certified ISO 27001 Lead Auditor, Internal Auditor
    • Certified Information Systems Auditor® (CISA®);
    • Certified Information Security Manager® (CISM®);
    • Certified Internal Auditor® (CIA®)
    • GIAC Systems and Network Auditor (GSNA)
    • IRCA ISMSAuditor or higher
    • Must possess a high degree of integrity and confidentiality, as well as the ability to  adhere to company policies, best practices and quality assurance methodology
    • Strong verbal and written abilities, strong multitasking and project management skills