M3
Associate PCI Qualified Security Assessor (Associate QSA)
Merit 321
🇺🇸 United States
On-site
11 months ago
- PCI DSS
- NIST
- ISO 27001
- SOC2
11 months ago
Bethesda, MD
- Support PCI engagements: Assist senior QSAs with PCI DSS assessments and pre-assessments, ensuring client environments align with applicable standards and controls.
- Participate in scoping and validation: Help identify the systems, applications, networks, and business processes that fall within a client’s PCI DSS scope.
- Gather and review evidence: Collect, organize, and validate documentation and technical artifacts to support compliance testing.
- Collaborate with clients: Participate in quarterly review meetings and readiness sessions to discuss milestones, vulnerability scans, and remediation progress.
- Assist in control evaluation: Support the review of compensating controls and preparation of Compensating Control Worksheets (CCWs).
- Contribute to deliverables: Help draft sections of Reports on Compliance (ROC), Attestations of Compliance (Client), and Self-Assessment Questionnaires (SAQ).
- Engage and learn: Work alongside seasoned assessors and consultants, expanding your technical expertise and consulting acumen.
What You Bring
- Current or in-progressAssociate QSA (AQSA) certification from the PCI Security Standards Council.
- 2–4 years of experience in IT audit, information security, or risk/compliance consulting.
- Foundational understanding ofPCI DSS standards and security best practices.
- Exposure toinformation security frameworks such as NIST, ISO 27001, or SOC 2.
- Strong analytical skills with exceptional attention to detail.
- Excellent communication and interpersonal skills — comfortable engaging directly with clients and technical teams.
- Bachelor’s degree in Computer Science, Cybersecurity, or related field (or equivalent experience).
Associate PCI Qualified Security Assessor (Associate QSA) · Merit 321