Basic Information
Ref Number
Primary Location
Country
Job Type
Work Style
Description and Requirements
Job type: Contractor to Hire
Here’s the impact you’ll make and what we’ll accomplish together
The InfoSec PCI Compliance Lead is a key part of the Information Security and Governance, Risk, and Compliance (GRC) team. You’ll report to the Information Security Compliance Manager and function as a central Payment Card Information subject matter expert, supporting enterprise teams looking to involve PCI data in business solutions and processes.
Responsibilities
Draft policies/procedures that govern the security of PCI data across the enterprise with a specific focus on compliance requirements.
Design, lead and execute a Compliance program focused on PCI data handling across the enterprise.
Partner with security teams to identify and analyze security requirements to align with PCI compliance standards.
Track, document and address PCI compliance gaps to ensure timely closure.
Manage the annual PCI audit including evidence gathering, quality assurance of evidence, coordination of audit resource meetings, and other tasks required to successfully complete the audit.
Ensure ASV Scans and Pentesting are conducted quarterly and annually, respectively with all remediation activities being completed within expected timelines.
Lead security enhancement projects focused on new or changing PCI compliance requirements.
Educate and build awareness of PCI compliance requirements.
Coordinate with Third Party Risk management to ensure PCI compliance needs are being addressed and tracked appropriately with third-party vendors.
Coordinate with Privacy / Legal to ensure the overall compliance landscape is well understood and the program captures a complete view of our PCI compliance needs.
Continuously improve the PCI compliance program with new information, procedures, or documentation.
Other responsibilities as assigned.
What’s in it for you?
TELUS International is pleased to offer you some great benefits as a contractor which include but are not limited to:
Internal Referral Program, for every referral hired you’ll get a referral bonus and amazing prizes
Transparent work culture to lift your ideas & initiatives at the enterprise level & investment to execute successfully.
Our development programs are designed to promote technical growth and enhance leadership and relationship skills across individuals. We spark your career growth, with a vast array of in-house and external training programs which are listed below, but not limited to:
Trending technical skills
Business domain & customer interaction
Behavioral & effective communication
Qualifications and Skills
4-6 years of experience in the role.
Must have a solid understanding of SOX, PCI, CPNI, CCPA, FACTA, and similar IT Compliance and Privacy regulations.
Experience with compliance audits such as PCI and/or CPNI. Former QSA preferred.
Experience with NIST, ISO, and other industry standards.
Expert user of Microsoft/Google Suite and an eGRC tool.
Education/Certifications
Professional certification (CISSP, CISA, CSIM, CIA or similar) is highly desired.
Join our TELUS International Family
Everyone belongs to TELUS International. It doesn’t matter who you are, what you do, or how you do it, at TELUS International, your unique contribution and talents will be valued and respected. Because the more diverse perspectives we have, the more likely we are to crack the code on what our customers want and what our communities need. From start-ups to large global brands, we deliver on all stages of customer growth and engagement. Our industry track record speaks for itself. #Happytocodehere
TELUS International is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability or protected veteran status, or any other legally protected basis, per applicable law.
Connect with us: Twitter | YouTube | LinkedIn | Facebook | Instagram
Additional Job Description
The InfoSec PCI Compliance Lead is a key part of the Information Security and Governance, Risk, and Compliance (GRC) team.
EEO Statement