PCI Assessment Specialist

🏢 JP Morgan
📍 Jersey City, United StatesFull-timeOn-site
📅 Posted: 3d ago🔄 Updated: 3d ago
CV%
✨ AI Summary
As a PCI Specialist in the Cybersecurity Technology and Controls Global Regulatory Assessments team, you will be the firm's subject matter expert on PCI DSS frameworks, driving compliance validation across a global financial environment. Your responsibilities include overseeing PCI assessments, partnering with external QSAs and internal stakeholders, analyzing documentation, validating scope, and managing risk. You will also provide guidance on remediation activities, develop business and technology relationships, communicate findings, and leverage emerging technologies to enhance assessment efficiency. The ideal candidate must have a minimum of 5 years of professional experience in technology risk and controls, risk-based consulting, risk assessments, or audit and regulatory activities, with specific emphasis on PCI DSS. Comprehensive knowledge of technology infrastructure and PCI DSS requirements, along with proven experience in tracking and driving remediation of PCI findings, is crucial. Strong analytical, communication, and project management skills are required, with a preference for a Bachelor's degree or equivalent practical experience in a technology, business, or related discipline, especially within financial services.
Required Skills
Information Technology
PCI-DSSIT Infrastructure
Other
technology riskregulatory activitiescompensating controls
Finance, Legal & Governance
Financial ControlsAuditingMediation
Engineering, Construction & Trades
Risk AssessmentValidation
Business, Sales & Management
Project ManagementInfluencer Marketing
Soft Skills & Professional Competencies
Stakeholder ManagementAnalytical SkillsDecision MakingTime ManagementPrioritizationCommunicationCollaboration
Nice to have:
Finance, Legal & Governance
COSOCOBIT
Information Technology
NISTITILIncident ManagementSDLCGenerative AI
Business, Sales & Management
Change Management
Productivity & Workplace Tools
RPA
Other
emerging technologies
Healthcare & Life Sciences
Clinical Judgment
🎁 Benefits & Perks
competitive total rewards package including base salary, commission-based pay and/or discretionary incentive compensation, comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching.
Requirements
Requires a minimum of 5 years of experience in technology risk and controls, risk assessments, or audit activities, with a strong emphasis on PCI DSS. Must have comprehensive knowledge of technology infrastructure and PCI DSS requirements, including tracking and validating PCI findings remediation. Excellent analytical, communication, and project management skills are essential.
Description

Data security underpins the trust that millions of clients place in the firm every day, and in this role, you will be at the forefront of protecting it. In this role, you will drive compliance validation across one of the world's most complex financial environments, working at the intersection of regulatory expertise, technical depth, and cross-functional leadership. This is your opportunity to shape how the firm interprets, implements, and demonstrates adherence to PCI DSS requirements at a global scale.

 

As a PCI Specialist at JPMorganChase in the Cybersecurity Technology and Controls Global Regulatory Assessments team, you will oversee end-to-end PCI assessment processes, serving as the firm's subject matter expert on PCI DSS frameworks. You will partner with external Qualified Security Assessors (QSAs) , internal control owners, and business stakeholders to validate compliance, manage risk, and protect cardholder data across diverse environments. Your work directly supports the firm's commitment to regulatory excellence and the security of its most sensitive systems.

 

Job responsibilities

  • Oversee and manage multiple concurrent PCI assessments within firm standards and procedures, adhering to time-sensitive deadlines through effective project management and stakeholder coordination.
  • Capture, review, and analyze PCI-required documentation, ensuring quality and suitability that meet PCI SSC requirements while exercising professional judgment on complex technical and compliance matters.
  • Partner with Business Leads and control owners to determine and validate assessment scope across people, processes, systems, and third-party dependencies in accordance with PCI DSS scoping requirements.
  • Collaborate closely with external QSAs to facilitate assessment processes, ensuring alignment with business objectives and regulatory requirements.
  • Proactively monitor key risk indicators to identify non-compliance and support remediation, including the development of compensating controls to address security, risk, and control gaps.
  • Provide guidance on remediation activities, ensuring appropriate resolution of issues and completion of action plans, and support the closure verification process.
  • Develop and maintain strong business and technology relationships, becoming a trusted compliance partner across the firm.
  • Communicate risk and control findings to key stakeholders, develop recommendations, and deliver accurate metrics and management reports on a timely basis.
  • Leverage emerging technologies, including AI and automation, to enhance assessment efficiency, documentation quality, and risk identification processes.

 

Required qualifications, capabilities, and skills

  • Minimum 5 years of professional experience in technology risk and controls, risk-based consulting, risk assessments, or audit and regulatory activities, with specific emphasis on PCI DSS.
  • Comprehensive knowledge and practical experience across all domains of technology infrastructure and PCI DSS requirements, including implementation and oversight of technology risk and controls, and coordination of audit activities.
  • Proven experience tracking and driving remediation of PCI findings, including validating control closure and documenting compensating controls through the formal PCI SSC process.
  • Detail-oriented with strong conceptual, analytical, decision-making, time management, and prioritization capabilities.
  • Exceptional oral and written communication skills with the ability to articulate complex technical concepts to diverse audiences at all organizational levels and influence without direct authority.
  • Proven experience in planning, coordination, and implementation with the ability to work across teams and functions to deliver quality outcomes.

 

Preferred qualifications, capabilities, and skills

  • Bachelor's degree or equivalent practical experience in a technology, business, or related discipline; experience within financial services is preferred.
  • Experience reviewing vendor, third-party, or software technical documentation to identify control gaps and assess suitability against defined security and compliance requirements.
  • Experience in a regulated financial services environment subject to external examinations or regulatory oversight.
  • Familiarity with IT risk and process frameworks including COSO, COBIT, NIST CF, and ITIL, as well as process-focused methodologies such as Change Management, Incident Management, and SDLC.
  • Demonstrated application of AI, automation, or emerging technologies to improve compliance workflows, documentation quality, or assessment efficiency.
  • Sound judgment in ambiguous situations, balancing regulatory requirements with business realities to develop pragmatic, risk-informed solutions.

 

#CTC

✨ Premium Match Details
Deep-dive CV analysis, customized Cover Letters, and Interview prep!
📊 Match Analysis
Insights against your active CV
📊
Personalized Match Analysis
Upload your CV to see exact matching percentages, detailed skills mapping, and gap analysis for this role.
🎯 Overalli74%
⚡ Skillsi85%
View Breakdown
Ontology Match: 85.0
Matched:✓ Requirements Matching✓ Ontology Skills Mapping
📜 Eligibilityi49%
View Breakdown
Local: 19600%
🏗️ Career Fiti91%
View Breakdown
Seniority: 91.0
📋 Requirementsi67%
View Breakdown
Domain: 67.0
🔥 Motivationi78%
View Breakdown
Title Fit: 78.00