BigCommerce

Senior Security GRC Analyst (PCI ISA Specialist)

BigCommerce$88K — $150K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years in Information Security or IT Audit experience
  • 3+ years focused on PCI DSS in cloud-native environments
  • Active PCI ISA or PCI QSA certification required
  • Thorough understanding of PCI DSS 4.0 requirements
  • Experience leading Level 1 Service Provider assessments
  • Ability to communicate compliance effectively to technical and business teams

Responsibilities

  • Serve as the PCI ISA managing the annual assessment lifecycle
  • Direct maintenance and evolution of the PCI 4.0 program
  • Validate PCI scope and ensure effective network segmentation with Cloud Engineering
  • Act as primary liaison with external QSA for audits
  • Operationalize PCI requirements into automated compliance workflows
  • Support SOC2 Type 2 and ISO 27001 audits as part of the GRC team
  • Track audit findings remediation and collaborate on secure solutions

Benefits

  • Hybrid work model starting March 2026 with in-office expectations
  • Access to compliance and security training and development opportunities
  • Collaborative work environment fostering technical and regulatory skill enhancement
  • Potential for variable compensation including bonuses and equity options
Full Job Description

As a Senior Security GRC Analyst and Internal Security Assessor (ISA), you will serve as the primary Subject Matter Expert (SME) for our global PCI DSS program at Commerce. We operate a highly mature PCI DSS 4.0 environment; your mission is to lead the continuous evolution of this program, ensuring that compliance is integrated into our "business as usual" (BAU) operations.

While your primary focus is PCI, you will be a key player in our broader GRC function, supporting our SOC2 and ISO 27001 certifications. You will act as the technical bridge between our Engineering, Infrastructure, and IT teams and external auditors, ensuring that our high-security standards are documented, validated, and maintained.

What You'll Do:

PCI SME & Internal Security Assessor (ISA)
  • ISA Leadership: Serve as the officially designated PCI ISA for the organization. Manage the annual assessment lifecycle, including scoping, evidence collection, and validation of controls.

  • PCI 4.0 Evolution: Direct the ongoing maintenance of our PCI 4.0 program, with a specific focus on managing Targeted Risk Analyses (TRAs) and the customized approach where applicable.

  • Scoping & Segmentation: Partner with Cloud Engineering to validate PCI scope across our global footprint, ensuring effective network segmentation and data flow isolation.

  • QSA Liaison: Act as the primary point of contact for our external QSA, defending our control environment and streamlining the audit process to minimize disruption to technical teams.

  • Continuous Compliance: Operationalize PCI requirements (e.g., quarterly scans, penetration test remediation) into automated workflows.

Multi-Framework Audit Management
  • Unified Control Framework: Support the broader GRC team in managing our SOC2 Type 2, ISO 27001, and other regulatory audits (as seen on https://www.google.com/search?q=security.commerce.com).

  • Technical Advisory: Provide GRC perspective on architectural designs, product launches, and infrastructure changes to ensure "compliance by design."

  • Remediation Management: Track and drive the remediation of audit findings and security gaps, working closely with asset owners to find pragmatic, secure solutions.

Who You Are:
  • Experience: 6+ years in an Information Security or IT Audit role, with at least 3 years of deep focus on PCI DSS within a major cloud-native environment.

  • Certification:Active PCI ISA (Internal Security Assessor) or PCI QSA certification is mandatory.

  • Regulatory Expertise: Thorough understanding of PCI DSS 4.0 requirements and the practical application of the standard in modern environments.

  • Audit Fluency: Proven experience leading Level 1 Service Provider assessments.

  • Communication: Ability to explain complex compliance requirements to developers and business leaders in a way that emphasizes enablement rather than "blockage."

Preferred Qualifications
  • Broad Framework Knowledge: Experience with SOC2 and ISO 27001:2022.

  • Cloud Security: Experience with GRC automation and familiarity with modern cloud-native security and observability tools.

  • Automation Mindset: Experience using GRC platforms and a desire to automate manual evidence collection to reduce audit fatigue.

About You
  • You understand the "Why": You don't just "do compliance"; you understand the security intent behind every control and can help teams meet the requirement in a way that actually improves our security posture.

  • Technical Curiosity: You are comfortable diving into technical configurations (IAM policies, VPC flow logs, etc.) to verify control effectiveness yourself.

  • Adaptable: You enjoy the challenge of a high-paced environment where scale and security must coexist and evolve together.

This is a Hybrid role - Beginning March 1, 2026, employees who live within commuting distance of a Dedicated Office will be expected to be in the office three days per week.

#LI-KE1

#LIHYBRID

(Pay Transparency Range: $88,951.00 - $150,432.00)

Compensation Transparency

The national base salary range for this role is posted above in this job post.

Final compensation will be determined based on factors such as relevant experience, skills, qualifications and geographic location. We also consider internal equity to help ensure fair and consistent pay practices across our teams.

Where applicable, this role may also be eligible for variable compensation (such as bonus or commission), equity, and benefits in accordance with local policies. Details will be shared during the hiring process. We are committed to equitable and transparent pay practices that align to market data, internal equity, and individual contribution.

About BigCommerce

BigCommerce is a software company that provides a platform for online businesses to create and manage their e-commerce websites. The company was founded in 2009 and is headquartered in Austin, Texas, U.S. Its platform allows businesses to create online stores, manage their products, process payments, and handle shipping and fulfillment. The company offers a range of plans for businesses of different sizes, from small startups to large enterprises. As of 2020, the company has more than 60,000 customers in over 120 countries. BigCommerce is a privately held company and has raised over $200 million in funding.
Learn more about BigCommerce
Size
813 employees
Market Cap
$597.2 million
Industry
Net Income
-$37.5 million
Founded
2009
Revenue
$152.3 million
NASDAQ

Similar Jobs

More Jobs at BigCommerce

More Information Technology Jobs

Find similar Senior Security GRC Analyst (PCI ISA Specialist) jobs: