Salary
💰 $95,000 - $120,000 per year
Tech Stack
Cyber SecurityGo
About the role
- Lead the end-to-end PCI DSS Level-1 Service Provider assessment process in collaboration with the external QSA, from planning through final Report on Compliance (ROC) delivery
- Serve as the primary liaison with QSAs, external auditors, and internal stakeholders to ensure timely deliverables, effective communication, and resolution of findings
- Interpret PCI DSS requirements and provide actionable guidance to technical and business teams for effective implementation
- Oversee evidence gathering, review, and validation to support PCI DSS, SOX ITGC, operational audits in conjunction with Hyatt Internal Audit, and other compliance assessments
- Manage SOX ITGC audit activities, including coordinating with control owners, addressing deficiencies, maintaining control documentation, and overseeing remediation activities with the control owners
- Support other IT compliance initiatives such as vendor risk management, ISO 27001 alignment, and regulatory or contractual audits
- Develop and maintain compliance-related policies, procedures, and control documentation
- Track, monitor, and report compliance metrics to management and senior leadership
- Stay informed on regulatory and industry changes, advising stakeholders on potential impacts and required adjustments
- Drive process improvements to strengthen the organization’s overall compliance posture and reduce risk exposure
- Act as the 2nd line of defense for IT compliance engagements
Requirements
- Bachelor’s degree in Information Security, Information Technology, Risk Management, Cyber Security, or a related field (or equivalent work experience)
- 5+ years of experience in GRC, IT compliance, or information security, with significant PCI DSS and SOX ITGC experience
- Proven history of leading PCI DSS Level-1 Service Provider assessments with a QSA
- Strong understanding of PCI DSS requirements, SOX Compliance, and general IT audit frameworks
- Experience coordinating with external auditors and managing cross-functional remediation efforts
- Excellent organizational, communication, and stakeholder management skills
- Preferred certifications: PCI Qualified Security Assessor (QSA), PCI Internal Security Assessor (ISA), CISA, CISSP, CRISC, or equivalent