FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Application Security Compliance Lead
NCR Atleos. Govern the Secure SDLC and maintain and improve practices aligned with the PCI Secure SLC Standard .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in governing Secure SDLC practices aligned with PCI Secure Software Standards, translating complex security and compliance requirements into actionable guidance, and effectively managing stakeholder relationships. Proficient in application security, risk management, and compliance frameworks, with a strong focus on embedding security throughout the software lifecycle.
Highest-signal resume keywords
Secure SDLC GovernancePCI SSF ValidationThreat ModellingVulnerability ManagementStakeholder Management
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Application SecuritySoftware Security AssuranceSecure Software DevelopmentRisk-Based Decision-MakingSecurity TestingEvidence CollectionGap AnalysisRemediationCloud ServicesCI/CD Practices
Soft Skills
Analytical SkillsProblem-Solving SkillsCommunication SkillsInfluencing SkillsIndependent Work
Tools & Technologies
Source-Code ManagementAI Assistants
Certifications & Qualifications
CISSPCSSLPCIPPCIPTCIPM
Industry Keywords
PCI Secure Software StandardGDPR RequirementsNIST CSFOWASP StandardsPayment-Card Security
Tech Stack
Tools & technologiesCloudSDLC
About the role
Key responsibilities & impact- Govern the Secure SDLC and maintain and improve practices aligned with the PCI Secure SLC Standard
- Guide teams through PCI SSF external assessments, self-assessments, annual attestations, and periodic revalidation activities
- Translate security, privacy, legal, and industry requirements into clear, proportionate guidance
- Coordinate reviews, evidence collection, gap analysis, remediation, and resolution of findings
- Partner with engineering, Legal, risk, compliance, and security teams, QSAs, and the PCI SSC
- Create training and reusable guidance; monitor developments and communicate material changes
- Use industry changes, stakeholder feedback, internal audits, assessment outcomes, recurring findings, and incidents to strengthen controls and processes
- Help ensure software products and development practices meet applicable security, privacy, and regulatory requirements
- Prepare teams for assessments and help demonstrate that security and privacy are embedded throughout the software lifecycle
- Support product teams in achieving and retaining PCI Secure Software Standard listings and maintaining validation of Secure Software Lifecycle practices
Requirements
What you’ll need- Typically, 7+ years of relevant experience in application security, software security assurance, secure software development, technology risk, privacy, compliance, or audit
- Practical experience developing, operating, governing, or assessing a Secure SDLC
- Experience interpreting security or compliance requirements and supporting assessments, evidence collection, gap analysis, and remediation
- Working knowledge of threat modelling, vulnerability management, security testing, and risk-based decision-making
- Technical understanding of cloud services, source-code management, and CI/CD practices sufficient to engage credibly with engineering teams
- Ability to convert complex requirements into pragmatic guidance and make evidence-based recommendations
- Strong stakeholder management, communication, analytical, and problem-solving skills, including the ability to influence without direct authority
- Ability to work independently and effectively within a globally distributed team
- Comfortable using AI assistants, such as Copilot, responsibly in day-to-day work
- A bachelor’s degree in a STEM discipline, or equivalent relevant professional experience and qualifications
- Direct experience of PCI SSF validation or a comparable software security assurance framework is desirable
- Knowledge of payment-card security, GDPR requirements, NIST CSF, and OWASP standards and guidance is desirable
- Experience delivering application security or compliance-related training is desirable
- Knowledge of security and governance for AI-enabled software development and products is desirable
- Relevant certification, such as CISSP, CSSLP, CIPP, CIPT, or CIPM, is desirable
- Employment is conditional upon passing applicable screening criteria
Benefits
Comp & perks- Offers of employment are conditional upon passage of screening criteria applicable to the job
- Equal-opportunity employment policy