远程工作雷达

安全运营工程师 - PCI DSS

Security Operations Engineer - PCI DSS

开发工程职能支持限定地区(需当地身份)
公司Teamified
薪资未公开
工作地点Philippines
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Contractor
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 Philippines 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

关于客户
我们的客户是一家创新的支付技术公司,正在改变企业发送、接收、支付和对账发票的方式。他们专注于简化复杂的支付流程,提供无缝的计费和支付生态系统,使企业及其客户在现金流方面拥有更大的灵活性、可见性和控制力。
通过与现有的会计平台和支付工作流程集成,我们的客户帮助减少手动管理,简化对账,提升支付体验,并创建更高效和安全的财务流程。他们致力于创新,提供使支付更简单、更快捷、更以客户为中心的技术解决方案。
随着业务的持续增长,他们正在寻找热爱技术、支付和提供卓越客户体验的优秀人才加入团队。

关于 Teamified
Teamified 是一家人才合作伙伴,帮助公司在全球范围内构建优秀的远程团队,涵盖 IT、软件、产品和数字创新领域。我们与全球领先的企业和快速扩展的科技公司合作,帮助他们获取世界级的人才并加速增长。我们在全球设有运营中心,我们的使命是让构建高性能的全球团队变得简单、快速且成本效益高。Teamified 拥有数百家客户,每天有超过 200 名工程师、测试人员、产品经理、设计师和技术专家交付具有影响力的解决方案。

职位概述:
我们的客户运营一个云托管的支付平台,并通过 SAQ D 服务提供商方式作为二级服务提供商验证符合 PCI DSS v4.0.1 标准。他们正在寻找一位经验丰富的安全工程师,签订三个月的合同,完成年度合规周期。
这是一个需要动手操作的工程角色,同时还需要负责项目管理。成功的候选人将实施技术控制变更,整理并质量检查证据集,完成自我评估问卷,并准备合规证明供高管签署。他们将与客户的现有工程和运维团队合作。
所产生的证据和文档应达到适合外部评估的标准,因为客户预计在未来周期中转向 QSA 主导的一级验证。
职责:

  • 在持卡人数据环境中实施并验证技术控制措施:访问管理、安全配置、日志记录、监控和漏洞管理
  • 协助制定和维护安全政策和程序,确保符合 PCI DSS 要求
  • 与跨职能团队协作,包括开发、运维、法务和合规团队
  • 准备和提交合规性报告和证明文件
  • 支持内部和外部审计过程
  • 提供安全建议和最佳实践,以持续改进整体安全态势
查看英文原文

About the client
Our client is an innovative payments technology company transforming the way businesses send, receive, pay, and reconcile invoices. With a strong focus on simplifying complex payment processes, they provide a seamless billing and payments ecosystem designed to give businesses and their customers greater flexibility, visibility, and control over cash flow.
By integrating with existing accounting platforms and payment workflows, our client helps reduce manual administration, streamline reconciliation, improve payment experiences, and create more efficient and secure financial processes. They are committed to innovation and delivering technology solutions that make payments simpler, faster, and more customer-focused.
As the business continues to grow, they are seeking talented professionals who are passionate about technology, payments, and delivering exceptional customer experiences to join their team.
About Teamified

Teamified is a talent partner helping companies build exceptional remote teams across IT, software, product, and digital innovation. We collaborate with leading enterprises and fast-scaling tech businesses worldwide to help them access world class talent and accelerate growth. With operations across the globe our mission is to make building high performing global teams simple, fast, and cost-effective. Teamified has hundreds of clients with more than 200 engineers, testers, product managers, designers, and technology experts delivering impactful solutions every day.
Job Summary:
Our client operates a cloud-hosted payment platform and validates against PCI DSS v4.0.1 as a Level 2 service provider via SAQ D for Service Providers. They are seeking an experienced security engineer on a three-month contract to run the annual compliance cycle to completion.
This is a hands-on engineering role combined with programme ownership. The successful candidate will implement technical control changes, assemble and quality-check the evidence set, complete the self-assessment questionnaire, and prepare the Attestation of Compliance for executive sign-off. They will work alongside the client's existing engineering and operations teams.
The evidence and documentation produced should be built to a standard suitable for external assessment, as the client anticipates moving to QSA-led Level 1 validation in a future cycle.
Responsibilities:

  • Implement and verify technical controls across the cardholder data environment: access management, secure configuration, logging and monitoring, vulnerability management, encryption and key management, and secure development practices.
  • Deliver the logging and monitoring requirements to the standard v4.0.1 expects: centralised collection of audit logs from all in-scope system components, protection of logs against alteration, twelve-month retention with three months immediately available, automated mechanisms for log review rather than manual inspection, time synchronisation, change detection on critical files, and alerting on the failure of critical security control systems.
  • Work alongside the client's DevOps engineer on the rollout of an open-source SIEM and host intrusion detection platform (Wazuh). The DevOps engineer owns the infrastructure build; this role owns the compliance outcome — defining required log sources and coverage, developing and tuning detection and correlation rules, configuring file integrity monitoring and retention to meet the standard, validating that the deployment actually satisfies the requirements, and evidencing it.
  • Define the alert triage and response routine the client team will operate day to day.
  • Complete SAQ D for Service Providers and assemble the supporting evidence set.
  • Maintain compliance documentation: network and cardholder dataflow diagrams, scoping and segmentation documentation, policies and operating procedures.
  • Engage and manage an Approved Scanning Vendor for quarterly external vulnerability scanning; drive remediation to passing scans.
  • Scope and co-ordinate penetration testing with a qualified independent provider; manage remediation and retest.
  • Maintain third-party service provider due diligence, including partner AOC collection and shared responsibility documentation.
  • Own the delivery plan: schedule, dependencies, risk log, and weekly reporting to leadership.
  • Strengthen change management practice so that changes are raised, approved, tested and evidenced consistently.
  • Document repeatable operational routines (log review, access review, scan cadence, change approval) for the client team to run after the engagement ends.

Requirements:
Essential experience

  • Demonstrable experience taking an organisation through PCI DSS compliance, ideally more than once and ideally including v4.x.
  • Working knowledge of PCI DSS v4.0.1, including the changes from v3.2.1 and the requirements mandatory from 31 March 2025.
  • Direct experience completing SAQ D, or preparing evidence for a Report on Compliance.
  • Hands-on AWS security engineering: IAM policy design, VPC and network segmentation, audit logging, secrets and key management, and infrastructure-as-code. Equivalent depth in another major public cloud will be considered where the candidate can demonstrate transferable design judgement.
  • Hands-on experience with SIEM or centralised log platforms in a compliance context — log source onboarding, parsing and normalisation, correlation and alert rule development, file integrity monitoring, retention configuration, and tuning to reduce false positives. Direct Wazuh experience is a strong advantage; equivalent open-source stacks (OSSEC, Elastic Security, Graylog, Security Onion) are acceptable. Candidates should be able to name the platforms they have worked with and describe what they configured, not only what they monitored.
  • Practical experience in vulnerability management, logging and monitoring, access management and secure configuration baselines.
  • Ability to independently plan, track, report and escalate. No project manager will be assigned.
  • Excellent written English. A significant portion of this role is documentation and evidence that must be read and accepted by others.
  • Willingness to record a control as not in place where that is the accurate position.

Desirable

  • Payments, fintech or regulated financial services background.
  • Understanding of the acquirer, processor and card scheme landscape.
  • Experience of Level 1 service provider validation, or of taking an organisation from self-assessment to QSA-led assessment.
  • PCIP, ISA, CISSP, CISM or equivalent certification.
  • Jira administration and workflow configuration.
  • Familiarity with ISO 27001 or SOC 2.

Benefits:

  • Flexibility in work hours and location, with a focus on managing energy rather than time.
  • Access to online learning platforms and a budget for professional development
  • A collaborative, no-silos environment, encouraging learning and growth across teams
  • A dynamic social culture with team lunches, social events, and opportunities for creative input
  • Leave Benefits

If you possess the required skills and are eager to contribute to our team's success, we encourage you to apply for this exciting opportunity. Apply now!
#GrowWithTeamified #TeamifyYourCareer
Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

产品经理

TeamifiedIndiaFull Time今天
开发工程职能支持限定地区(需当地身份)

产品设计师

TeamifiedPhilippinesFull Time昨天
设计限定地区(需当地身份)

← 返回全部职位