FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Security Operations Engineer – PCI DSS
Teamified. Implement and verify technical controls across the cardholder data environment, including access management, secure configuration, logging and monitoring, vulnerability management, encryption and key management, and secure development practices.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in PCI DSS compliance, including hands-on experience with PCI DSS v4.0.1, vulnerability management, and secure configuration practices. Proficient in AWS security engineering and SIEM platforms, with a strong ability to manage compliance outcomes and document operational routines.
Highest-signal resume keywords
PCI DSS ComplianceAWS Security EngineeringVulnerability ManagementSIEM ExperienceWazuh Implementation
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
PCI DSS v4.0.1Vulnerability ManagementAccess ManagementSecure ConfigurationLog Source OnboardingAudit LoggingInfrastructure-as-CodeFile Integrity MonitoringAlert Rule DevelopmentSAQ D Completion
Soft Skills
Excellent Written EnglishIndependent PlanningTracking and Reporting
Tools & Technologies
WazuhAWSSIEM PlatformsJiraISO 27001SOC 2
Certifications & Qualifications
PCIPISACISSPCISM
Industry Keywords
PaymentsFintechRegulated Financial ServicesAcquirerProcessorCard Scheme
Tech Stack
Tools & technologiesAWSCloud
About the role
Key responsibilities & impact- Implement and verify technical controls across the cardholder data environment, including access management, secure configuration, logging and monitoring, vulnerability management, encryption and key management, and secure development practices.
- Implement PCI DSS v4.0.1 logging and monitoring requirements, including centralised audit-log collection, log protection, retention, automated log review, time synchronisation, critical-file change detection, and failure alerting.
- Work alongside the client's DevOps engineer on rollout of Wazuh, owning compliance outcomes, required log-source coverage, detection and correlation rules, file-integrity monitoring, retention, validation, and evidence.
- Define the alert triage and response routine for the client team.
- Complete SAQ D for Service Providers and assemble supporting evidence.
- Maintain network and cardholder dataflow diagrams, scoping and segmentation documentation, policies, and operating procedures.
- Engage and manage an Approved Scanning Vendor for quarterly external vulnerability scanning and drive remediation to passing scans.
- Scope and coordinate penetration testing with a qualified independent provider; manage remediation and retesting.
- Maintain third-party service-provider due diligence, including partner AOC collection and shared-responsibility documentation.
- Own the delivery plan, schedule, dependencies, risk log, and weekly leadership reporting.
- Strengthen change-management practices so changes are raised, approved, tested, and evidenced consistently.
- Document repeatable operational routines for the client team after the engagement ends.
- Run the annual PCI DSS compliance cycle to completion during a three-month contract and prepare the Attestation of Compliance for executive sign-off.
Requirements
What you’ll need- Demonstrable experience taking an organisation through PCI DSS compliance, ideally more than once and ideally including v4.x.
- Working knowledge of PCI DSS v4.0.1, including the changes from v3.2.1 and the requirements mandatory from 31 March 2025.
- Direct experience completing SAQ D, or preparing evidence for a Report on Compliance.
- Hands-on AWS security engineering: IAM policy design, VPC and network segmentation, audit logging, secrets and key management, and infrastructure-as-code.
- Equivalent depth in another major public cloud will be considered where the candidate can demonstrate transferable design judgement.
- Hands-on experience with SIEM or centralised log platforms in a compliance context, including log source onboarding, parsing and normalisation, correlation and alert rule development, file integrity monitoring, retention configuration, and tuning to reduce false positives.
- Direct Wazuh experience is a strong advantage; equivalent open-source stacks (OSSEC, Elastic Security, Graylog, Security Onion) are acceptable.
- Ability to name platforms worked with and describe what was configured, not only what was monitored.
- Practical experience in vulnerability management, logging and monitoring, access management and secure configuration baselines.
- Ability to independently plan, track, report and escalate; no project manager will be assigned.
- Excellent written English.
- Willingness to record a control as not in place where that is the accurate position.
- Payments, fintech or regulated financial services background is desirable.
- Understanding of the acquirer, processor and card scheme landscape is desirable.
- Experience of Level 1 service provider validation, or taking an organisation from self-assessment to QSA-led assessment, is desirable.
- PCIP, ISA, CISSP, CISM or equivalent certification is desirable.
- Jira administration and workflow configuration is desirable.
- Familiarity with ISO 27001 or SOC 2 is desirable.
Benefits
Comp & perks- Flexibility in work hours and location, with a focus on managing energy rather than time.
- Access to online learning platforms and a budget for professional development
- A collaborative, no-silos environment, encouraging learning and growth across teams
- A dynamic social culture with team lunches, social events, and opportunities for creative input
- Leave Benefits