Job Description: PCI Internal Security Assessor (ISA) Department: Enterprise Security & Technology Risk Management Employment Type: Contractor Job Overview The PCI Internal Security Assessor (ISA) is responsible for ensuring that complies with the Payment Card Industry Data Security Standard (PCI DSS). The ISA will assess, monitor, and enforce the security measures necessary to protect cardholder data and maintain PCI compliance across all systems and processes. This role works closely with internal stakeholders and external parties to maintain a secure environment, mitigate risks, and improve overall security posture. Key Responsibilities: PCI DSS Compliance Management: Conduct regular internal assessments and audits to ensure the organization's compliance with PCI DSS. Develop and implement PCI compliance policies, procedures, and controls. Serve as the internal point of contact for PCI DSS-related matters and ensure all applicable security controls are in place. Collaborate with the external Qualified Security Assessor (QSA) to facilitate annual PCI DSS certification audits. Risk Assessment and Mitigation: Identify and assess potential risks to cardholder data environments and provide recommendations for risk mitigation. Implement and enforce necessary security controls to address gaps identified during assessments. Ensure vulnerability scanning, penetration testing, and security reviews are conducted to identify weaknesses and ensure continuous compliance. Documentation and Reporting: Prepare and maintain comprehensive documentation, including policies, procedures, and reports required for PCI DSS compliance. Maintain comprehensive documentation of assessment findings, corrective actions, and compliance status. Manage the submission of the Self-Assessment Questionnaires (SAQs) and Attestation of Compliance documents (AOCs) as needed. Training and Awareness: Conduct internal PCI DSS training for staff to ensure a deep understanding of the importance of compliance and security measures. Provide ongoing guidance and support to departments regarding security best practices related to PCI DSS. Collaboration and Communication: Work closely with projects, Enterprise Security, Technology, and other relevant departments to align PCI DSS compliance with overall security policies and practices. Proactively identify and/or promptly escalate risks and issues affecting PCI compliance status. Stay updated on changes in PCI DSS requirements and industry best practices to ensure CIBC Caribbean remains compliant. Present PCI DSS compliance status reports to senior management and external stakeholders. Act as a liaison where necessary between CIBC Caribbean and external vendors or service providers involved in processing or storing cardholder data. Qualifications: Education: Bachelor’s degree in Information Security, Computer Science, or a related field (or equivalent work experience). Experience: Minimum of 3-5 years of experience in information security, PCI compliance, or a related field. Previous experience as an ISA, QSA, or a similar role is highly desirable. Certifications: Certified PCI Internal Security Assessor (ISA) or Certified PCI Professional (PCIP) certifications preferred. Additional certifications such as CISSP, CISM, CISA, or CEH are a plus. Skills and Competencies: Deep understanding of PCI DSS requirements and data security best practices. Familiarity with security frameworks (NIST, ISO 27001, CIS Controls) and security technologies (firewalls, IDS/IPS, encryption, etc.). Strong analytical, problem-solving, and project management skills. Excellent communication and interpersonal skills with the ability to work cross-functionally. Proficiency in using security assessment tools and techniques (e.g., vulnerability scanners, SIEM). Other Requirements: Ability to work independently and handle sensitive information confidentially. Detail-oriented with strong organizational skills. Occasional travel may be required for audits or compliance reviews. Show more Show less
The PCI Internal Security Assessor (ISA) plays a crucial role within the Enterprise Security & Technology Risk Management department as a Contractor. In this position, you will be responsible for ensuring the organization's compliance with PCI DSS standards by conducting internal assessments, audits, and implementing necessary security controls. Your primary objective will be to manage PCI DSS compliance, risk assessment, documentation, training, and communication to maintain a secure environment for cardholder data. Your key responsibilities will include conducting regular internal assessments and audits to ensure compliance with PCI DSS, developing and implementing PCI compliance policies and controls, and collaborating with external Qualified Security Assessor (QSA) for certification audits. You will need to identify potential risks to cardholder data, implement necessary security controls, and ensure continuous compliance through vulnerability scanning, penetration testing, and security reviews. Additionally, you will be responsible for preparing comprehensive documentation, maintaining assessment findings, and managing submission of required documentation for PCI DSS compliance. As a PCI Internal Security Assessor, you will also conduct internal PCI DSS training, provide ongoing guidance to staff, collaborate with relevant departments, and stay updated on industry best practices to ensure compliance. You will need to possess a Bachelor's degree in Information Security or a related field, along with 3-5 years of experience in information security or PCI compliance. Certifications such as Certified PCI Internal Security Assessor (ISA) or Certified PCI Professional (PCIP) are preferred, along with additional certifications like CISSP, CISM, CISA, or CEH. Moreover, you should have a deep understanding of PCI DSS requirements, security frameworks, and technologies, strong analytical and problem-solving skills, excellent communication abilities, and proficiency in security assessment tools. The role requires you to work independently, handle sensitive information confidentially, and occasionally travel for audits or compliance reviews. Overall, as a PCI Internal Security Assessor, you will play a critical role in maintaining PCI DSS compliance and safeguarding cardholder data within the organization.,