FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Security Operations Engineer – PCI DSS
Teamified. Implement and verify technical controls across the cardholder data environment, including access management, secure configuration, logging and monitoring, vulnerability management, encryption and key management, and secure development practices.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in PCI DSS compliance, including hands-on experience with AWS security engineering and vulnerability management. Proficient in implementing technical controls, managing logging and monitoring systems, and coordinating with third-party vendors for compliance outcomes.
Highest-signal resume keywords
PCI DSS ComplianceAWS Security EngineeringVulnerability ManagementWazuh ExperienceSIEM Implementation
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
PCI DSS v4.0.1SAQ D CompletionIAM Policy DesignVPC and Network SegmentationAudit LoggingInfrastructure-as-CodeLog Source OnboardingFile Integrity MonitoringChange ManagementPenetration Testing
Soft Skills
Excellent Written EnglishIndependent PlanningReporting and Escalation
Tools & Technologies
WazuhOSSECElastic SecurityGraylogSecurity OnionJira Administration
Certifications & Qualifications
PCIPISACISSPCISM
Industry Keywords
PaymentsFintechRegulated Financial ServicesAcquirerProcessorCard SchemeISO 27001SOC 2
Tech Stack
Tools & technologiesAWSCloud
About the role
Key responsibilities & impact- Implement and verify technical controls across the cardholder data environment, including access management, secure configuration, logging and monitoring, vulnerability management, encryption and key management, and secure development practices.
- Deliver PCI DSS v4.0.1 logging and monitoring requirements, including centralised audit-log collection, log protection, retention, automated review, time synchronisation, critical-file change detection, and failure alerting.
- Work with the DevOps engineer on Wazuh rollout, owning compliance outcomes such as log-source coverage, detection and correlation rules, file-integrity monitoring, retention, validation, and evidence.
- Define the alert triage and response routine for daily client-team operations.
- Complete SAQ D for Service Providers and assemble supporting evidence.
- Maintain network and cardholder dataflow diagrams, scoping and segmentation documentation, policies, and operating procedures.
- Engage and manage an Approved Scanning Vendor for quarterly external vulnerability scanning and drive remediation.
- Scope and coordinate penetration testing with a qualified independent provider; manage remediation and retesting.
- Maintain third-party service-provider due diligence, including partner AOC collection and shared-responsibility documentation.
- Own the delivery plan, schedule, dependencies, risk log, and weekly leadership reporting.
- Strengthen change management so changes are raised, approved, tested, and evidenced consistently.
- Document repeatable operational routines for the client team after the engagement ends.
Requirements
What you’ll need- Demonstrable experience taking an organisation through PCI DSS compliance, ideally more than once and ideally including v4.x.
- Working knowledge of PCI DSS v4.0.1, including the changes from v3.2.1 and the requirements mandatory from 31 March 2025.
- Direct experience completing SAQ D, or preparing evidence for a Report on Compliance.
- Hands-on AWS security engineering: IAM policy design, VPC and network segmentation, audit logging, secrets and key management, and infrastructure-as-code.
- Equivalent depth in another major public cloud will be considered where the candidate can demonstrate transferable design judgement.
- Hands-on experience with SIEM or centralised log platforms in a compliance context, including log source onboarding, parsing and normalisation, correlation and alert rule development, file integrity monitoring, retention configuration, and tuning to reduce false positives.
- Direct Wazuh experience is a strong advantage; equivalent open-source stacks (OSSEC, Elastic Security, Graylog, Security Onion) are acceptable.
- Candidates should be able to name the platforms they have worked with and describe what they configured, not only what they monitored.
- Practical experience in vulnerability management, logging and monitoring, access management and secure configuration baselines.
- Ability to independently plan, track, report and escalate. No project manager will be assigned.
- Excellent written English.
- Willingness to record a control as not in place where that is the accurate position.
- Payments, fintech or regulated financial services background.
- Understanding of the acquirer, processor and card scheme landscape.
- Experience of Level 1 service provider validation, or of taking an organisation from self-assessment to QSA-led assessment.
- PCIP, ISA, CISSP, CISM or equivalent certification.
- Jira administration and workflow configuration.
- Familiarity with ISO 27001 or SOC 2.
Benefits
Comp & perks- Flexibility in work hours and location, with a focus on managing energy rather than time.
- Access to online learning platforms and a budget for professional development
- A collaborative, no-silos environment, encouraging learning and growth across teams
- A dynamic social culture with team lunches, social events, and opportunities for creative input
- Leave Benefits