jobs Logo
OBRYN GUARD logo

PCI DSS Compliance Lead — QSA Background Required

OBRYN GUARDabout 22 hours ago
Remote
Senior Level
Full-Time

About the role

Role Overview OBRYN GUARD® is seeking an experienced PCI DSS Compliance Lead with current or previous Qualified Security Assessor experience to strengthen our payment-security expertise, product methodology, and customer readiness services. OBRYN GUARD® helps hotels and hospitality businesses identify cyber risks, organize compliance evidence, monitor controls, manage remediation, and prepare for PCI DSS assessments. This is not a general cybersecurity role. The successful candidate must understand PCI DSS v4.0.1, Self-Assessment Questionnaires, payment-environment scoping, evidence review, third-party service providers, control testing, and remediation planning. Unless OBRYN GUARD® becomes an approved QSA Company, this role will not issue formal Reports on Compliance, Attestations of Compliance, or QSA validations. The role will focus on readiness, scoping, SAQ guidance, evidence review, remediation, product development, and assessment preparation.

Key Responsibilities

PCI DSS and SAQ Guidance • Serve as OBRYN GUARD®’s internal PCI DSS subject-matter expert. • Interpret PCI DSS v4.0.1 requirements, testing procedures, evidence expectations, and validation methods. • Determine the likely correct SAQ based on payment channels, technology, outsourcing, storage practices, and eligibility requirements. • Guide hotel teams through SAQ questions without completing or attesting on their behalf. • Review completed SAQs for inaccurate, unsupported, incomplete, or inconsistent responses. • Explain the evidence required to support each answer. • Prepare customers for submission to their acquiring bank, payment processor, or external QSA Company.

Payment Environment Scoping

• Map how hotels accept, process, store, transmit, or interact with payment-account data. • Evaluate front-desk payments, booking engines, payment gateways, virtual terminals, telephone reservations, restaurants, property management systems, point-of-sale platforms, and third-party providers. • Identify systems that are in scope, connected to the cardholder data environment, or capable of affecting its security. • Review segmentation assumptions and supporting evidence. • Identify legitimate scope-reduction opportunities without creating hidden compliance exposure. • Document payment flows, systems, vendors, owners, and shared responsibilities.

Evidence and Control Review

Review evidence such as policies, network and data-flow diagrams, asset inventories, access listings, MFA settings, firewall configurations, vulnerability scans, penetration tests, logs, incident-response plans, training records, vendor agreements, Attestations of Compliance, responsibility matrices, patch records, data-retention procedures, and payment-device inspection records. Determine whether evidence is current, relevant, complete, approved, and sufficient. Identify outdated, generic, contradictory, or unsupported evidence and document what must be corrected.

Gap Assessments and Remediation

• Conduct or support PCI DSS readiness and gap assessments. • Identify failed, missing, weak, undocumented, or incorrectly scoped controls. • Document affected requirements, observations, risk, evidence needed, responsible owners, and deadlines. • Build practical remediation plans and prioritize findings based on payment risk, assessment impact, customer exposure, and complexity. • Identify when formal external QSA involvement is required. • Track progress until gaps are resolved or escalated.

Product and Platform Development

• Translate PCI DSS requirements into accurate OBRYN GUARD® product workflows. • Help design readiness assessments, scoping questionnaires, evidence requests, remediation trackers, dashboards, compliance calendars, vendor registers, responsibility assignments, and executive reports. • Determine which controls may be supported through integrations or automated monitoring and which require manual evidence, interviews, observation, sampling, or technical testing. • Ensure the platform does not treat a checkbox, uploaded file, or successful integration as automatic proof of compliance. • Review PCI-related language, findings, reports, and customer guidance for accuracy. • Document the limitations of automated compliance monitoring.

Hospitality Security Expertise

Apply PCI DSS requirements to hotel-specific risks, including multiple properties, franchise structures, shared accounts, high employee turnover, seasonal staff, remote vendor access, property management systems, point-of-sale platforms, booking engines, payment gateways, telephone payments, legacy technology, flat networks, third-party IT providers, and physical payment-device security. Translate technical findings into clear actions for hotel owners, general managers, finance teams, IT teams, front-desk leadership, and vendors.

Third-Party Service Providers

• Identify vendors that store, process, transmit, secure, or affect payment-account data. • Review service-provider Attestations of Compliance, scope statements, coverage dates, responsibility matrices, and customer obligations. • Identify when a provider’s compliance status does not fully cover the hotel’s responsibilities. • Track compliance documents, expiration dates, remote access, shared controls, contract responsibilities, and outstanding evidence. • Explain which obligations remain after payment functions are outsourced.

Customer, Sales, and Internal Support

• Participate in selected discovery calls, technical meetings, product demonstrations, onboarding sessions, and enterprise security reviews. • Help sales teams describe OBRYN GUARD®’s PCI DSS capabilities accurately. • Prevent unsupported claims about certification, guaranteed compliance, QSA authority, or assessment outcomes. • Create customer guidance, templates, evidence lists, readiness reports, executive summaries, and remediation plans. • Train internal teams on PCI DSS terminology, SAQs, scoping, evidence quality, third-party responsibilities, and prohibited compliance claims. • Identify when customers require an external QSA Company, Approved Scanning Vendor, penetration tester, forensic investigator, legal adviser, or another specialist.

Required Qualifications

• Current or previous Qualified Security Assessor status, or substantial equivalent PCI DSS assessment experience within a recognized QSA Company. • Strong knowledge of PCI DSS v4.0.1. • Direct experience supporting PCI DSS assessments, readiness reviews, SAQs, Reports on Compliance, Attestations of Compliance, or remediation programs. • Experience evaluating cardholder data environments, payment flows, access controls, authentication, network security, vulnerability management, logging, incident response, and governance. • Strong understanding of scoping, segmentation, evidence requirements, service-provider responsibilities, and validation methods. • Ability to distinguish formal validation from advisory and readiness services. • Strong technical writing, documentation, report-review, and communication skills. • High attention to detail, evidence quality, and consistency. • Ability to work in an early-stage company where systems and methodologies are being built quickly.

Preferred Experience

• Experience assessing hotels, resorts, restaurants, franchises, retail organizations, or multi-location businesses. • Familiarity with property management systems, point-of-sale systems, booking engines, payment gateways, virtual terminals, e-commerce payments, and outsourced payment environments. • Experience with cloud platforms, identity providers, endpoint management, network-security systems, and security logging. • Familiarity with SOC 2, ISO 27001, NIST, cyber insurance, vendor risk, or governance, risk, and compliance programs. • Certifications such as CISSP, CISA, CISM, CRISC, ISO 27001 Lead Auditor, or ISO 27001 Lead Implementer. • Experience supporting GRC, compliance automation, evidence-management, or continuous control monitoring software.

Ideal Candidate

The ideal candidate understands that PCI DSS is not a checkbox exercise. Uploading a policy does not prove a control is operating, outsourcing payment processing does not remove every merchant responsibility, and an SAQ cannot be selected accurately without understanding the payment environment. They can review a hotel’s systems, payment flows, vendors, network structure, access model, and evidence and identify where the real exposure exists. They must be comfortable telling leadership, engineering, sales, or customers when an assumption is unsupported, a claim is too strong, an environment is incorrectly scoped, or more evidence is required. The successful candidate will be technically credible, commercially aware, highly organized, and capable of helping OBRYN GUARD® build PCI DSS capabilities that customers, partners, and enterprise decision-makers can trust.

Success Measures

Success will be measured by the accuracy of PCI DSS guidance and platform workflows, quality of SAQ preparation and evidence review, strength of customer scoping and remediation plans, customer readiness for formal submission, and the prevention of unsupported compliance conclusions.

Application Requirements

Applicants should provide: • A current résumé or professional profile. • Current or previous QSA status. • Relevant PCI DSS assessment and readiness experience. • Experience with PCI DSS v4.0 or v4.0.1. • Industries and payment environments previously supported. • Relevant security, audit, compliance, or technical certifications. • A brief explanation of how they would help a hotel determine its PCI DSS scope and appropriate SAQ. Applicants must be prepared to verify material qualifications and experience.

Thank you for your interest in OBRYN GUARD®. Sincerely, Leadership Team OBRYN GUARD Inc.

About OBRYN GUARD

Hotels and Motels
2-10 employees

OBRYN GUARD™ helps hospitality ownership groups and operators strengthen cyber risk, compliance, and audit readiness.

Built for hotel environments, we support leadership teams with cyber risk assessments, control gap analysis, vendor risk visibility, policy documentation, executive reporting, and readiness support for PCI DSS, SOC 2, ISO 27001, NIST CSF, HIPAA, and cyber insurance requirements.

Our focus is simple: help hospitality organizations move beyond checkbox compliance toward measurable risk reduction, stronger operational control, and defensible security maturity.

Similar Jobs