- Assist in the transformation and implementation of GEICO’s PCI DSS program
- Ensure secure computer systems and networks comply with PCI DSS
- Communicate control deficiencies and recommend remediation
- Document policies and procedures for significant process controls, especially network and security devices
- Identify key controls, perform gap analyses, update processes, and mitigate security risks and vulnerabilities
- Evaluate, document, and monitor remediation of control deficiencies
- Support management with meeting coordination, follow-up, presentations, and documentation
- Facilitate external auditor performance or independent testing and coordinate with process owners
- Perform key report testing and walkthroughs as needed
- Assist with quarterly PCI DSS control certification surveys
- Maintain resolution of audit and assessment findings
- Assist with business continuity/disaster recovery testing and finding resolution
- Develop and implement enterprise governance, risk, and compliance strategy and solutions
- Assist with audit readiness assessments for NIST 800-53 standards
- Automate and assist in gathering audit evidence for cyber audits
- Plan, execute, and report on risk-based audit engagements
- Influence remediation and prioritization of key risks
- Establish and maintain a document request list library to create audit efficiencies
- Monitor developing regulatory concerns and changing IT and information security trends
Requirements
- Payment Card Industry Professional Certification (PCIP) required
- Minimum of 5 years of work experience in auditing, control assessment, and PCI DSS
- Minimum of 6 years of experience in Governance, Risk, and Compliance
- Minimum of 5 years of experience working with PCI DSS and NIST 800-53
- Strong experience with the PCI DSS standard
- Knowledge of information security management, governance, and compliance principles, practices, laws, regulations, and frameworks including GLBA, FFIEC, and NIST
- Experience with firewalls, intrusion detection and prevention systems, and encryption technologies
- Comprehensive understanding of cybersecurity principles, frameworks, and regulations including ITIL, NIST, MITRE, COBIT, COSO, HITRUST, SOC reports, CSF, ISO, GDPR, and PCI
- Experience working with internal and external auditors
- Knowledge of computer networking, network security practices, compliance, or computer security
- Knowledge of cyber and cloud security frameworks, architecture, design, operations, controls, technology, solutions, and service orchestration
- Hands-on experience with security testing and auditing tools and techniques
- Strong knowledge of information systems auditing, monitoring, controlling, and assessment processes
- Ability to work in a fast-paced environment
- Ability to work independently and strategically
- Expertise in identifying and analyzing controls and developing mitigation strategies
- Critical thinking, problem-solving, and decision-making skills
- Interpersonal and communication skills to collaborate with technical and non-technical peers
- Ability to manage multiple projects and prioritize tasks
- Cybersecurity certifications such as Security+, CISM, CISSP, CISA, or CRISC are highly desired
- Bachelor’s degree in engineering, Computer Science, Information Security, or a related field
- At this time, GEICO will not sponsor a new applicant for employment authorization for this position
Core Competencies
Demonstrates expertise in PCI DSS compliance, risk management, and information security governance. Proficient in auditing processes, control assessments, and implementing security frameworks such as NIST 800-53.
Highest-signal resume keywords
- Payment Card Industry Professional Certification (PCIP)
- Governance, Risk, and Compliance (GRC)
- PCI DSS Compliance
- NIST 800-53 Standards
- Information Security Management
ATS Optimization Keywords
Hard Skills
- Auditing
- Control Assessment
- Cybersecurity Principles
- Security Testing
- Risk-Based Audit Engagements
- Gap Analysis
- Mitigation Strategies
- Network Security Practices
- Compliance Monitoring
- Documenting Policies and Procedures
Soft Skills
- Critical Thinking
- Problem-Solving
- Decision-Making
- Interpersonal Skills
Certifications & Qualifications
- Security+
- CISM
- CISSP
- CISA
- CRISC
Industry Keywords
- PCI DSS
- NIST
- GLBA
- FFIEC
- ITIL
- MITRE
- COBIT
- COSO
- HITRUST
- GDPR
Tools & Technologies
- Firewalls
- Intrusion Detection Systems
- Encryption Technologies
- Security Auditing Tools
- Cybersecurity Frameworks