About this role
As part of the Cybersecurity Technology Controls Global Regulatory Assessments team, the PCI Specialist is responsible for overseeing the end-to-end processes of a PCI Assessment driven by contractual and/or determined by business need in support of the JPMC Multi-Level PCI Compliance Validation efforts. The PCI Assessor/Advisor acts as the PCI Subject Matter Expert partnering with external Assessor partners and internal control and application owners to ensure compliance with PCI DSS SSC Frameworks. This role requires expert project management capabilities, technical proficiency, and the ability to effectively facilitate assessments across diverse stakeholder groups including external assessors, technical teams, and non-technical business partners to deliver quality outcomes within established timeframes.
Job responsibilities
- Oversee and manage multiple concurrent PCI assessments within firm Standards & Procedures according to established methodology and frameworks, adhering to time-sensitive deadlines through effective project management and stakeholder coordination
- Capture, review and analysis of PCI required documentation, ensuring quality and suitability that meets PCI SSC requirements while exercising professional judgment on complex technical and compliance matters.
- Work with Business Leads & control owners and other members of the PCI team to determine and validate scope (people, processes and technologies etc.)
- Partner strategically with external QSAs to facilitate assessment processes while ensuring alignment with business objectives and regulatory requirements
- Proactively monitor Key Risk Parameters to identify non-compliance and assist in remediation including potential compensating controls to address security, risk and control gaps where appropriate.
- Provide guidance on remediation activities as it pertains to the business area, ensuring appropriate resolution of issues, action plans, breaks and remedies and support the closure verification process
- Develop and maintain strong business and technology relationships, becoming a trusted partner.
- Communicate risk and other control findings with key stakeholders, develop recommendations and provide accurate metrics and management reports on a timely basis.
- Leverage emerging technologies, including AI and automation tools, to enhance assessment efficiency, documentation quality, and risk identification processes
Required qualifications, capabilities, and skills
- Candidates must possess demonstrable experience in technology risk and controls, risk-based consulting, risk assessments, audit and regulatory activities, with specific emphasis on PCI Data Security Standards
Bachelor’s degree in computer science, Management Information Systems, Accounting Information Systems, or a related field. Experience within financial services areas is preferred.
- Comprehensive knowledge and practical experience across all domains of Technology Infrastructure and PCI DSS requirements. Experience with implementation and oversight of technology risk and controls, coordination of activities for audits and assessing in an assigned environment.
- Detail-oriented professional with strong conceptual, analytical, decision-making, planning, time management, and prioritization capabilities.
- Exceptional oral and written communication skills with ability to articulate complex technical concepts to diverse audiences at all organizational levels and influence without direct authority.
- Proven experience in planning, coordination, and implementation with ability to work across teams and functions to execute and deliver quality outcomes.
- Demonstrated aptitude to upskill and learn new technologies based on business requirements.
Preferred qualifications, capabilities, and skills
- Proficiency in reviewing, understanding, and evaluating technical and software documentation and applying knowledge to assess control suitability.
- Experience operating in environments that are heavily governed under compliance, regulatory, or risk reduction controls.
- Advanced understanding of industry best practices, regulatory requirements, and company policies.
- Knowledge of process-focused methodologies for IT related activities (Change Management, Incident Management, and SDLC).
- Working knowledge of IT Risk & Process frameworks: COSO, COBIT, NIST CF, ITIL
- Demonstrated interest and practical application of AI, automation, and emerging technologies to enhance compliance and assessment processes
- Ability to exercise sound judgment in ambiguous situations, balancing regulatory requirements with business realities to develop pragmatic solutions