Simplify Logo

Full-Time

PCI Compliance and Security Program Manager

Posted on 11/30/2023

SoFi

SoFi

1,001-5,000 employees

Offers comprehensive digital financial services

Data & Analytics
Venture Capital
Fintech
Financial Services
Real Estate
Education

Senior

Salt Lake City, UT, USA + 2 more

Category
Legal & Compliance
Product
Required Skills
Communications
Management
AWS
Requirements
  • Minimum of 7 years of experience in PCI DSS compliance, preferably in a similar role.
  • Strong understanding of information security principles, best practices, and the PCI DSS.
  • Relevant certifications such as Qualified Security Assessor (QSA) Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), PCI Professional (PCIP), AWS Certified Solutions Architect - Associate or AWS Certified Security Specialty
  • Excellent organizational and technical program management skills.
  • Strong interpersonal and communication skills.
  • Experience assessing security in a cloud-hosted environment
  • Experience managing SOC2, PCI DSS, SOX ITGC, GLBA or other compliance standards and framework programs
  • Demonstrated ability to assimilate new knowledge quickly
  • Comfortable working in a fast-paced, dynamic environment, and managing multiple projects concurrently
Responsibilities
  • Develop and maintain the organization's PCI DSS compliance roadmap
  • Partner with stakeholders and cross-functional partners to identify, document, and communicate project/program scope, schedule, risks, and issues
  • Serve as the primary point of contact for PCI Qualified Security Assessors (QSAs), Approved Scanning Vendors (ASVs), and relevant external partners.
  • Be the subject matter expert for PCI DSS compliance across SoFi
  • Coordinate PCI DSS annual assessments, vulnerability scans, and penetration testing with various internal and external stakeholders
  • Perform ongoing compliance checks to ensure continuous compliance.
  • Facilitate code reviews, architecture reviews, API security reviews and third party reviews with engineering and security teams for PCI scoped environment
  • Lead PCI governance for cardholder data environment
  • Collect, prioritize, track, and drive issues to resolution/closure
  • Collaborate with relevant departments to maintain and update PCI DSS-compliant policies, controls and procedures
  • Regularly review and update the organization's policies and procedures to ensure ongoing compliance
  • Conduct PCI DSS awareness and training sessions for staff
  • Ensure all relevant personnel are aware of PCI DSS requirements as they pertain to their roles
  • Identify potential areas of compliance vulnerability and risk
  • Develop and implement corrective action plans for resolution of problematic issues
  • Provide guidance on risk mitigation techniques related to PCI DSS
  • Assist with any potential cardholder data breaches or incidents, ensuring they are appropriately addressed, documented, and reported in accordance with PCI DSS requirements
  • Provide regular updates to leadership on the status of PCI DSS compliance, including any potential risks or issues
  • Stay updated on changes to the PCI DSS and related industry best practices
  • Recommend improvements to enhance the security posture and efficiency of the organization's PCI program
Desired Qualifications
  • MS in a technical field or equivalent experience
  • Experience with network and firewall reviews, review of technical flows and architecture diagrams, data classification, SIEM logging tools, cloud security posture management, compliance scanning solutions, vulnerability scanners, data security posture management

SoFi offers a range of modern financial products and services, utilizing innovative technologies to support borrowing, saving, spending, investing, and financial protection, enabling financial independence and goal attainment. The company leverages technology to provide comprehensive financial solutions, focusing on innovative methods to support its offerings.

Company Stage

IPO

Total Funding

$6.2B

Headquarters

San Francisco, California

Founded

2011

Growth & Insights
Headcount

6 month growth

5%

1 year growth

9%

2 year growth

17%

Benefits

You’re taken care of. SoFi employees receive comprehensive health, vision, dental, life insurance, and disability benefits—as well as flexible time off, fitness, fertility, and family planning options.

Realize your ambitions. We want to help our employees achieve financial freedom, just like our members. That’s why we contribute $200 per month toward your student loans to help pay down your debt—plus free financial classes.

Never stop learning. We offer frequent training, mentorship opportunities, and leadership programs to develop our people. We also cover tuition costs for approved programs, up to $5,250 per year.

INACTIVE