Full-Time

Senior Information Security Compliance Specialist

Payment Security, PCI DSS

Posted on 8/18/2025

NMI

NMI

501-1,000 employees

White-label payment gateway for partners

No salary listed

Bristol, UK

Remote

Occasional in-person responsibilities for cryptographic ceremonies held at our Bristol, UK office.

Category
IT & Security (1)
Requirements
  • 5+ years of experience in information security, IT risk, or compliance roles
  • In-depth experience with PCI DSS and at least two of: PCI PIN, PCI P2PE, SOC 2
  • Proven ability to manage end-to-end compliance projects including successful third-party audits
  • Familiarity with common security documentation, audit evidence gathering, and security documentation management practices
  • Strong organizational, project management, and stakeholder communication skills
Responsibilities
  • Develop and evolve compliance programs for PCI (DSS, PIN, P2PE), and SOC 2 across their full lifecycle
  • Establish and maintain audit-ready compliance processes that support year-round readiness
  • Define internal roadmaps to achieve and sustain certification status
  • Own the full policy lifecycle, including control mapping, documentation governance, and change management
  • Conduct risk assessments and controls testing to identify and remediate gaps
  • Collaborate with engineering, infrastructure, and operations teams to ensure effective design and implementation of controls
  • Lead NMI’s Business Continuity and Disaster Recovery planning, management, and testing programs
  • Provide compliance-focused input on new systems and service implementations
  • Serve as a primary point of contact for external auditors and assessors
  • Lead audit prep activities including walkthroughs, documentation reviews, and technical evidence collection
  • Ensure timely resolution of audit findings and communicate progress to stakeholders
  • Engage with stakeholders across Engineering, Product, Legal, and HR to support compliance-by-design
  • Educate internal teams on compliance responsibilities, procedures, and controls
  • Support vendor risk and third-party security assessment activities
Desired Qualifications
  • Experience with compliance oversight for secure key management ceremonies and cryptographic key exchanges
  • Industry certifications such as CISA, CISM, CRISC, or ISO 27001 Lead Implementer
  • Background in SaaS or fintech environments
  • Exposure to secure development practices, risk assessments, and vendor risk management programs
  • Familiarity with common GRC tools such as Tugboat, Drata, or Vanta
  • Understanding of privacy regulations (e.g., GDPR, CCPA) as they relate to operational compliance

NMI provides white-labeled payment gateway technology for ISOs, VARs, ISVs, and payment facilitators. Its platform enables partners to offer their own branded payment gateway services to merchants, while handling secure, real-time omnichannel payments (in-store, online, mobile, unattended). Partners access a merchant portal for transaction management, reporting, and analytics. NMI earns revenue through partner fees such as transaction fees, monthly fees, and value-added services. The company differentiates itself by offering a white-label, omnichannel payment gateway with a robust set of tools that partners can rebrand as their own, allowing them to maintain their brand identity while leveraging NMI’s infrastructure. The goal is to empower partner networks to deliver seamless payment services under their own brands at scale.

Company Size

501-1,000

Company Stage

Private

Total Funding

$620M

Headquarters

Schaumburg, Illinois

Founded

2000

Simplify Jobs

Simplify's Take

What believers are saying

  • Steven Pinado appointed CEO to drive next growth phase.
  • LANDI M20SE partnership launches compact Tap to Pay Android device.
  • Bill Connect embeds payments into QuickBooks and Xero for SMBs.

What critics are saying

  • Stripe erodes market share with superior developer tools and pricing.
  • Shopify Payments captures eCommerce volumes via proprietary POS sync.
  • Plaid open banking APIs bypass NMI through direct ACH integrations.

What makes NMI unique

  • NMI delivers white-label payment gateway for ISOs, VARs, ISVs, and payment facilitators.
  • iSpyFraud and tokenization provide advanced security beyond standard gateways.
  • Omnichannel platform supports in-store, online, mobile, and unattended payments.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Unlimited Paid Time Off

Paid Holidays

Remote Work Options

Company Equity

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

-1%

2 year growth

0%
Anexan Solutions Inc.
Sep 16th, 2025
Understanding Credit Card Payments Response Codes within Black Belt Membership Software

That's why Blackbeltcrm has partnered with NMI, one of the most trusted payment gateways in the industry.

The Financial Technology Report
Sep 2nd, 2025
NMI Appoints Steven Pinado as CEO to Lead Next Phase of Growth

NMI appoints Steven Pinado as CEO to lead next phase of growth.

Retail Solutions Providers Association (RSPA)
Jun 4th, 2025
LANDI and NMI Expand Partnership with Launch of LANDI M20SE: A Compact, Cost-Effective Android Device Configured for Tap to Pay

LANDI and NMI expand partnership with launch of LANDI M20SE: A compact, cost-effective Android device configured for Tap to Pay.

Financial Technology Insights
Mar 27th, 2025
NMI Launches Tap to Pay on Google Play Store

NMI, a global leader in embedded payments infrastructure, announces the availability of its new Tap to Pay solution on the Google Play Store.

PYMNTS
Jan 23rd, 2025
Nmi Embeds Payment Functionality Into Popular Accounting Software

Embedded payments infrastructure provider NMI has launched a new extension for use with its NMI Payment Gateway that embeds payment functionality directly into popular accounting software like QuickBooks and Xero. This new extension, Bill Connect, is powered by Biller Genie, NMI said in a Thursday (Jan. 23) press release. Bill Connect helps the small and medium-sized businesses (SMBs) that use the popular accounting software automate and streamline invoicing, accept secure payments and automate reconciliation — all within a single platform and without a need for enterprise resource planning (ERP) systems — according to the release

INACTIVE