Sr. Manager - IT Compliance (Remote)

Hyatt

• $120K — $150K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in IT compliance, audit, cybersecurity, or risk management.
  • 4+ years managing PCI DSS compliance programs or people.
  • Deep knowledge of PCI DSS, COBIT, CIS, ISO27001, and NIST CSF 2.0.
  • Experience with Internal and External Audits, managing multiple projects.
  • Strong analytical, communication, project management, and documentation skills.

Responsibilities

  • Lead and manage the PCI DSS compliance program and certification activities.
  • Coordinate annual PCI assessments and compliance reports for multiple units.
  • Define and validate Cardholder Data Environment and compliance boundaries.
  • Ensure PCI controls are effectively implemented across systems.
  • Oversee compliance monitoring, evidence collection, and remediation actions.
  • Partner with Cybersecurity and Technology teams on compliance alignment.
  • Develop team capability and align projects with organizational strategy.

Benefits

  • Collaborative work environment focused on professional development.
  • Comprehensive training programs to nurture curiosity and skills.
  • Opportunities for career advancement within a global organization.
Full Job Description
Summary:
The Opportunity

Hyatt Hotels Corporation seeks an enthusiastic Senior Manager, IT Compliance to join our IT Governance, Risk Management, and Compliance department. You will be part of a team that is passionate about our purpose, committed to nurturing curiosity and new skills, and building connections across the organization with colleagues, customers, and guests.

The Role

The Senior Manager, IT Compliance, is responsible for leading the organization's PCI Compliance Program including Payment Card Industry Data Security Standard (PCI-DSS). This position ensures compliance with PCI Standards and PCI-DSS requirements to protect cardholder data and maintain secure payment environments, coordinating teams across cybersecurity, technology, and business units to protect payment account data and maintain ongoing compliance. This role requires a strategic approach to compliance management, ensuring that PCI-DSS controls are effectively implemented, maintained, and continuously improved.
• Manage the organization's PCI DSS compliance program and annual certification activities.
• Coordinate annual PCI assessments, Self-Assessment Questionnaires (SAQs), and Report on Compliance (ROC) activities for multiple business units.
• Define and validate the Cardholder Data Environment (CDE), connected systems, data flows, and compliance boundaries. This includes providing guidance on PCI requirements for new systems, applications, vendors, and business initiatives.
• Ensure the appropriate PCI controls and supporting processes are implemented and maintained across the in-scope systems and infrastructure relevant to the CDE.
• Direct PCI DSS assessment activities and annual penetration testing, partnering with QSAs and internal stakeholders to maintain compliance posture.
• Oversee the team to closely monitor and track compliance requirements, evidence collection, remediation activities, and ongoing control monitoring.
• Partner with Cybersecurity, Infrastructure, Application Development, Application Owners, Technology Operations, and Infrastructure teams to ensure alignment exists with PCI DSS compliance requirements and industry best practices.
• Manages and develops teams within areas of responsibility including all aspects of the company's talent management processes. Develops and manages group / team structures and resource levels to support business needs and to develop team members.
• Assures projects / requests are appropriately prioritized and aligned with the strategy and direction of the organization and appropriate resources are allocated for their development.
• Provides input to annual operating budget and capital plans. Accountable for performance against financial parameters.

Qualifications:
Experience Required:
• 8+ years of experience in IT compliance, IT audit, cybersecurity, risk management, or related discipline.
• 4+ years of direct experience managing larger PCI DSS compliance programs and/or leadership or people management experience.
• Strong understanding of:

o PCI DSS framework and standards

o IT risk management frameworks

o Different frameworks such as COBIT, CIS, ISO27001, and NIST CSF 2.0
• Experience working with Internal Audit and External Auditors along with ability to manage multiple initiatives and work effectively with technical and nontechnical stakeholders.
• Strong analytical, creating robust documentation, project management, process design/implementation, and communication skills.

Experience Preferred:
• Education - Bachelor's degree in information security, Information Technology, Risk Management, Cyber Security, or a related field (or equivalent work experience).
• Certificates, Licenses, Registrations - Preferred certifications: CISA, CISSP, CRISC, PCI Qualified Security Assessor (QSA), PCI Internal Security Assessor (ISA), or equivalent.
• Computer Skills Needed to Perform this Job - Microsoft Office (Word, Excel, PowerPoint, etc.). GRC tools like LogicGate, Auditboard/Optro, OneTrust, etc.

The position responsibilities outlined above are in no way to be construed as all-encompassing. Other duties, responsibilities, and qualifications may be required and/or assigned as necessary.

We welcome you:

Research shows that individuals tend to apply to jobs only if they meet all the listed job qualifications. Unsure if you check every box, but feeling inspired to enhance your career? Apply. We'd love to consider your unique experiences and how you could make Hyatt even better.

We value our relationships with recruitment partners and require that agencies contact us first before submitting any candidates. Hyatt will not be responsible for any fees and obligations associated with unsolicited submissions unless a formal agreement is in place.

The salary range for this position is $120,000 to $150,000. This position is also eligible to earn incentive awards and an annual bonus.The final pay rate/salary offered to the successful candidate will depend on experience, skill level and other qualifications for the role, as well as the location of the performance of work. Pay for the successful candidate will meet local requirements, including the local minimum wage rate.

Similar Jobs

More Jobs at Hyatt

More Information Technology Jobs

Find similar Sr. Manager - IT Compliance (Remote) jobs: