Job Summary:Frazier & Deeter is seeking an
Advisory Senior Associate to lead PCI DSS assessments and evaluate security controls to validate compliance with payment card industry requirements. Review technical and process controls, identify compliance gaps, and provide remediation recommendations. Engage with client stakeholders to assess risks, review evidence, and support compliance reporting. Deliver advisory services to help organizations strengthen cardholder data security and maintain PCI DSS compliance.
Duties & Responsibilities:- Lead PCI DSS assessments, gap analyses, and readiness reviews for clients across various industries.
- Evaluate the design and effectiveness of security controls related to cardholder data environments (CDE).
- Review policies, procedures, configurations, and technical evidence to validate PCI DSS compliance.
- Conduct stakeholder interviews and walkthroughs to understand processes and identify compliance gaps.
- Develop risk-based recommendations and remediation plans to address PCI DSS findings.
- Prepare assessment deliverables, including compliance reports, observations, and executive summaries.
- Mentor junior team members, review their workpapers, and support engagement quality and timely delivery.
- Act as a trusted advisor to clients on PCI DSS requirements, security best practices, and evolving compliance expectations.
Education & Experience: - Bachelor's degree in information technology, Computer Science, Cybersecurity, Information Systems, or a related field.
- 3-5 years of experience in IT Audit, Cybersecurity, Risk Advisory, Compliance, or PCI DSS assessments.
- PCI QSA certification required; additional certifications such as CISA, CISSP, CISM, CRISC, or ISO 27001 Lead Auditor are preferred.
- Strong understanding of PCI DSS requirements, payment card processing environments, and cardholder data security controls.
- Experience conducting compliance assessments, control testing, gap assessments, and remediation validation activities.
- Familiarity with IT General Controls (ITGCs), access management, vulnerability management, network security, encryption, and logging/monitoring controls.
- Experience preparing assessment reports, executive summaries, and presenting findings to client stakeholders and management.
- Strong analytical, communication, stakeholder management, and project delivery skills with the ability to manage multiple engagements simultaneously.
- Experience mentoring junior team members and contributing to practice development initiatives is preferred.
#LI - hybrid