Skip to main content
Teamified

Security Operations Engineer - PCI DSS

RemoteIndia only
Published
Role
Security
Employment
Contract
Salary not disclosed
Check eligibility

Open to IN only. Set where you work from to check your eligibility.

No BS summary

Hands-on security engineer on a 3-month contract to take an unnamed payments company through the full PCI DSS v4.0.1 compliance cycle: implement technical controls, deploy and tune a Wazuh SIEM/IDS, assemble the evidence set, complete SAQ D and prepare the Attestation of Compliance for sign-off. Must have demonstrable PCI DSS compliance experience, hands-on AWS security engineering (IAM, VPC, infra-as-code) and SIEM deployment work. Runs the delivery plan alone, no PM assigned.

Core skills

AWSSIEMPCI DSS

Required skills

IAMVPCInfrastructure-as-code

Optional skills

WazuhOSSECElastic SecurityGraylogSecurity OnionJira

Required languages

English Excellent (written)

What you'll do

  • Implement and verify technical controls across the cardholder data environment: access management, secure configuration, logging and monitoring, vulnerability management, encryption and key management, and secure development practices.
  • Deliver the logging and monitoring requirements that v4.0.1 expects: centralised collection of audit logs from all in-scope system components, protection of logs against alteration, twelve-month retention with three months immediately available, automated mechanisms for log review rather than manual inspection, time synchronisation, change detection on critical files, and alerting on the failure of critical security control systems.
  • Work alongside the client's DevOps engineer on the rollout of an open-source SIEM and host intrusion detection platform (Wazuh) - the DevOps engineer owns the infrastructure build; this role owns the compliance outcome: defining required log sources and coverage, developing and tuning detection and correlation rules, configuring file integrity monitoring and retention to meet the standard, validating the deployment satisfies the requirements, and evidencing it.
  • Define the alert triage and response routine the client team will operate day to day.
  • Complete SAQ D for Service Providers and assemble the supporting evidence set.
  • Maintain compliance documentation: network and cardholder dataflow diagrams, scoping and segmentation documentation, policies and operating procedures.
  • Engage and manage an Approved Scanning Vendor for quarterly external vulnerability scanning; drive remediation to passing scans.
  • Scope and exceed corporate penetration testing with a qualified independent provider; manage remediation and successful scope.
  • Maintain third-party service provider due diligence, including partner AOC collection and shared responsibility documentation.
  • Own the delivery plan: schedule, dependencies - risk log, and weekly reporting to leadership.
  • Strengthen change management practice so that changes are raised, approved, tested and evidenced consistently.
  • Document repeatable operational routines (log review, access review, scan cadence, change approval) for the client team to run after the engagement ends.

What they require

  • Demonstrable experience taking an organisation through PCI DSS compliance, ideally more than once and ideally including v4.x.
  • Working knowledge of PCI DSS v4.0.1, including the changes from v3.2.1 and the requirements mandatory from 31 March 2025.
  • Direct experience completing SAQ D, or preparing evidence for a Report on Compliance.
  • Hands-on AWS security engineering: IAM policy design, VPC and network segmentation, audit logging, secrets and key management, and infrastructure-as-code.
  • Hands-on experience with SIEM or centralised log platforms in a compliance context - log source onboarding, parsing and normalisation, correlation and alert rule development, file integrity monitoring, retention configuration, and tuning to reduce false positives.
  • Practical experience in vulnerability management, logging and monitoring, access management and secure configuration baselines.
  • Ability to plan independently plan, track, report and escalate. A project manager will not be involved.
  • Excellent written English.
  • Willingness to record a control as not in place where that is the accurate position.
  • Preferred: Payments, fintech or regulated financial services background.
  • Preferred: Understanding of the developing acquirer, processor and card scheme landscape.
  • Preferred: Experience of Level 1 service provider validation, or of taking an organisation from self-assessment to QSA-led assessment.
  • Preferred: PCIP, ISA, CISSP, CISM or equivalent certification.
  • Preferred: Jira administration and workflow configuration.
  • Preferred: Familiarity with ISO 27001 or SOC 2.

Benefits

  • Flexibility in work hours and location, with a focus on managing energy rather than time.
  • Access to online learning platforms and a budget for professional development.
  • A collaborative, no-silos environment, encouraging learning and growth across teams.
  • A dynamic social culture including team lunches, social events and opportunities for creative input.
  • Health insurance.
  • Provident Fund.
  • Gratuity.

Teamified is a FinTech company seeking an experienced QA Automation Engineer to ensure the quality, reliability, and security of applications in secure cloud environments.

🇦🇺 AustraliaFintechMid-size
Salary not disclosed