Security Advisor - PCI Practice

Security Advisor - PCI Practice

15 Oct 2024
District of Columbia, Washington, 20001 Washington USA

Security Advisor - PCI Practice

CampusGuard, a Nelnet Company, provides information security services for campus-based organizations including higher education institutions, healthcare providers, city, county and state government agencies and hospitality markets. As a full-service information security firm, we leverage our knowledge combined with the industry standards for compliance and information security issues to provide our customers with world class information security & compliance services.CampusGuard, a Nelnet company, provides cybersecurity and compliance services for campus-based organizations including higher education institutions, healthcare providers, state and local government agencies, utilities and hospitality markets. As a full-service firm, we leverage our knowledge combined with the industry standards for compliance and information security issues to provide our customers with world class information cybersecurity & compliance services.The Security Advisor provides information security and compliance consulting services using accepted standards, frameworks, and best practices including but not limited to PCI DSS, NIST SPs 800-53 and 800-171, NIST CSF, and ISO 27001. Security Advisors assess and report on customers’ compliance with various rules, regulations, and standards such as PCI DSS, CMMC, GDPR, FERPA, HIPAA/HITECH, GLBA, and FCRA Red Flags. The Security Advisor will gather and analyze customer information, make remote and/or physical site visits, conduct interviews, make observations, take appropriate notes, perform gap analysis, review evidence and documentation, and complete reports on findings, with remediation recommendations included where necessary. Security Advisors provide ongoing consultation services to customers via recurring and ad-hoc meetings and email communications, and assist with periodic support activities with customers, such as tabletop exercises and facilitating risk assessments, to ensure continued compliance. The Security Advisor provides sales support in the form of conference attendance/presentations, collaborates with Customer Relationship Manager (CRM) partners, and performs other tasks as needed/assigned, including but not limited to: time entry, internal meetings, create/revise both internal- and customer-facing documents and tools, and attend training seminars/webinars.JOB RESPONSIBILITIES:Security Advisors are responsible for assessing and reporting on customer business and technical environments, operations/procedures, administration of infrastructure (from network border to endpoints and everything in-between), and overall compliance programs, as measured against relevant industry standards. The PCI Practice Security Advisor will focus primarily on PCI DSS assessments and compliance (including Reports on Compliance), though work to support other service lines, including those within the Privacy Practice, can arise periodically. Customer support of general information security is a shared responsibility between the PCI and Privacy Practices.Responsibilities of the PCI Practice Security Advisor include, but are not limited to the following:

Consult both onsite and remotely with customers to collect, review, and analyze data related to current institutional policies, business practices and procedures, network infrastructure, IT system configurations and physical security as they relate to multiple compliance requirements (primarily PCI DSS).

Performing gap analysis of sampled merchant environments and overall compliance program/centralized controls.

Provide in-person or remote orientation sessions to customer personnel.

Review requirements with third-party service providers as necessary to clarify roles and help the customers achieve information security and compliance objectives.

Make recommendations for remediation steps required to achieve information security and compliance objectives.

Upon requests from ongoing customers, the Security Advisor may review customer-prepared industry reports (such as a PCI Self-Assessment Questionnaire) and provide feedback/guidance to ensure accurate reporting, or in some cases assist the customer with the preparation of required industry-standard reporting obligations.

This is a remote work position.Candidate must be able to work in a home office environment with minimal supervision.

Ability to travel required (potentially up to 50%).

Other duties as assigned.

Security Advisors use standardized procedures and methods to assess the security and monitor the on-going compliance of each customer:

Perform gap assessments through interviews, observations, evidence review, and physical/remote assessments to evaluate customer networks, infrastructure and operations as it relates to compliance objectives (primarily PCI DSS).

Report on findings and provide customers with remediation options when appropriate.

Security Advisors assist with sales and marketing activities:

Participate in sales calls as an industry expert. Attend conferences as appropriate.

Prepare and perform industry-related presentations and/or webcasts. Other sales/marketing support duties as requested.

EDUCATION:Minimum acceptable education requirements: Bachelor’s degree, and/or 5 years’ experience in the information security industry (preferably at an institution of higher education) Minimum acceptable certification requirements: Possess at least one of the industry-recognized information security and/or audit certification(s) required to obtain the Qualified Security Assessor (QSA) certification. See lists below. Possessing both information security and audit certifications and an active QSA certification is a plus.Information Security certifications:

ISC2 Certified Information System Security Professional (CISSP)

ISACA Certified Information Security Manager (CISM)

Certified ISO 27001 Lead Implementer (when issued by an accredited certification body)

Audit certifications:

ISACA Certified Information Systems Auditor (CISA)

GIAC Systems and Network Auditor (GSNA)

Certified ISO 27001 Lead Auditor or Internal Auditor (when issued by an accredited certification body)

IRCA ISMS Auditor or higher—e.g., Auditor/Lead Auditor, Principal Auditor (“Provisional” auditor designations are not sufficient)

IIA Certified Internal Auditor (CIA)

Note: Candidates must agree to prepare for and pass the PCI Qualified Security Assessor (QSA) certification and any other certifications as directed by their manager.Pay Range for this position is -$95,000 and up (amount changes on industry certifications and PCI assessment experience.)EXPERIENCE:Minimum acceptable work experience requirements: All candidates must have a minimum of five years of relevant information security experience, to align with the minimum experience requirements for a QSA. This experience must cover at least one year each in application security, information systems security, network security, IT security auditing, and information security risk assessment or risk management. At least two years’ experience working with PCI DSS compliance is required, either as an assessor or internally to manage PCI DSS compliance.SKILLS/KNOWLEDGE/ABILITIES:Knowledge and experience with consulting, implementing, or supporting PCI DSS and other compliance/assessment efforts including:

Understanding and familiarity with PCI DSS and supporting standards/programs, including but not limited to: PTS, SSF, P2PE, SPoC, MPoC, etc.

Core PCI DSS compliance program elements, such as policy, procedure, training, service provider oversight, device protection, inventory/scope verification, and incident response.

Targeted risk analyses.

SAQs, Report on Compliance template, and other relevant guidance documents and tools provided by the PCI SSC.

Familiarity with industry-standard security and compliance documents/frameworks, such as NIST SP 800-171, NIST CSF, ISO 27001, GLBA and other standards.

Creative problem-solving and customer engagement including:

Collaborating, identifying, and addressing customer needs through relationship building and understanding customer’s business and needs.

Familiarity with Education, Healthcare, and Government institution and their structures, operations, and security needs.

Understanding of information systems, networks, and related security issues.

Communicating in written, verbal, and video formats.

Communicating both quantitative and qualitative analyses.

Creating high-quality deliverables using appropriate business and technical language.

Our benefits package includes medical, dental, vision, HSA and FSA, generous earned time off, 401K/student loan repayment, life insurance & AD&D insurance, employee assistance program, employee stock purchase program, tuition reimbursement, performance-based incentive pay, short- and long-term disability, and a robust wellness program. Click here to learn more about our benefits: LINK (http://nelnetinc.com/careers/benefits/) .Nelnet is an Equal Opportunity Employer, complies with Executive Order 11246, and takes affirmative action to ensure that qualified applicants are employed, and that employees are treated during employment, without regard to race, color, religion/creed, national origin, gender, or sex, marital status, age, disability, use of a guide dog or service animal, sexual orientation, military/veteran status, or any other status protected by Federal or State law or local ordinance.Qualified individuals with disabilities who require reasonable accommodations in order to apply or compete for positions at Nelnet may request such accommodations by contacting Corporate Recruiting at 402-486-5725 or corporaterecruiting@nelnet.net .Nelnet is a Drug Free and Tobacco Free Workplace.You may know Nelnet as the nation’s largest student loan servicer – but we do more than that. A lot more. We’re also a professional services company, consumer loan originator and servicer, payment processor, renewable energy innovator, and K-12 and higher education expert (and that’s just a shortlist). For over 40 years, we’ve been serving our customers, associates, and communities to make dreams possible.EEO Info (https://nelnetinc.com/wp-content/uploads/EEO-poster.pdf) | EEO Letter (https://nelnetinc.com/wp-content/uploads/EEO-Jeffs-Letter.pdf) | EPPA Info (https://nelnetinc.com/wp-content/uploads/Employee-Polygraph-Protection-Act-Poster.pdf) | FMLA Info (https://nelnetinc.com/wp-content/uploads/FMLA-Leave.pdf)

Related jobs

  • Job Description

  • Allied Universal®, North America’s leading security and facility services company, provides rewarding careers that give you a sense of purpose. While working in a dynamic, diverse and inclusive workplace, you will be part of a team that fuels a culture that will reflect in our communities and customers we serve. We offer medical, dental and vision coverage, life insurance, retirement plan, employee assistance programs, company discounts, perks and more for most full-time positions!

  • Allied Universal®, North America’s leading security and facility services company, provides rewarding careers that give you a sense of purpose. While working in a dynamic, diverse and inclusive workplace, you will be part of a team that fuels a culture that will reflect in our communities and customers we serve. We offer medical, dental and vision coverage, life insurance, retirement plan, employee assistance programs, company discounts, perks and more for most full-time positions!

  • Summary

  • Our Mission

  • Summary This position is in the Public Safety and Homeland Security Bureau (PSHSB), Cybersecurity and Communications Reliability (CCR) Division. Relocation expenses will not be paid. THIS VACANCY ANNOUNCEMENT MAY BE USED TO FILL ADDITIONAL POSITIONS WITHIN 90 DAYS. Responsibilities Incumbent provides oral and written legal advice, guidance, interpretation, opinions and assistance on a wide range of legal and policy matters; performs legal research; determines implications of novel and complex legal issues; develops factual, legal, and precedent-setting positions on disputed matters. Responds to inquiries from the Division, Bureau, and/or Commission leadership as well as from other components of the Commission and other government agencies, Congress, and the public; addresses novel legal questions pertaining to CCR issues involving communications reliability issues; prepares memoranda or opinions outlining the facts and legal issues involved in disputed matters, and fully justifies conclusions and recommendations. Reviews and evaluates proposed legislation, regulations and policies to analyze their effect on existing laws and regulations and on Division/Bureau programs, policies, regulations and overall operations. Identifies facts, applies analysis, develops policy, and prepares rule making orders and decisions assuring that documents adhere to Division/Bureau/Commission policy while evaluating objectives and clearly identifying all available options. Ensures that Commission-level documents submitted for review are: legally and demonstrably supported by accurate facts, comprehensive and internally consistent, and in conformance with existing policy, precedent, decisions, processes and procedures. Develops potential projects to address the need for communications networks to be reliable, resilient, and secure within the purview of the Division by recommending establishing new policy, or by altering or clarifying established policy and/or established legal precedents. Resolves legal questions and addresses issues that may have no precedents or no clearly applicable precedents, requiring significant, independent legal research and coordination, and determining when to brief matters to CCR leadership. Identifies major policy issues requiring interpretation by higher legal authority and develops and prepares recommended interpretation outlining the facts and applicable law. Performs extensive research; determines implications of novel and complex legal issues; develops factual, legal, and precedent-setting positions on disputed matters. The scope of legal problems encountered is broad, highly complex and technical. Draft rules, regulations, and policies, including those pertaining to communications reliability (such as network outage reports, disaster information reporting and 911 reliability certifications) and public safety, homeland security, national security, disaster management, and related issues. Represents CCR leadership at meetings, hearings and conferences to: (1) gather facts, investigate circumstances and events, and formulate the best legally supportable course of action for resolving complex issues, often in coordination with technical and other Commission staff with regard to alleged violations of statue or regulations; and (2) coordinate with Bureau/Commission offices on policy issues requiring interpretation and developing and preparing recommended interpretation outlining the facts and applicable laws. Requirements Conditions of Employment FCC Employees Only US Citizenship. Suitable for employment as determined by a background investigation. SF-50 Documenting One Year of Time in Grade Required Bar Membership documentation required upon selection Transcripts required upon selection Financial Disclosure may be required Current FCC employees must provide SF-50 verifying grade & status. To be considered for this position, applicants must: Currently be employed in the Federal Communications Commission in positions serving under career, career conditional, or excepted service (Schedule A appointments under authority 213.3102(d)-Attorneys) appointments. SF-50 Required: ALL FCC EMPLOYEES MUST provide a legible Personnel Action, SF-50, that verifies your status and highest permanently held grade. If an SF-50 is not submitted, the application will be rated as ineligible. To request a copy of your SF-50 please send an email to PersonnelRecordsRequest@fcc.gov Qualifications Applicants must meet eligibility and qualification requirements by the closing date of this announcement. Current Federal employees must meet time-in-grade requirements by the closing date of this announcement. Professional law experience is experience that has equipped the applicant with the particular knowledge, skills, and abilities to perform successfully the duties of the position and is typically in or related to the work of the position to be filled. In order to be deemed as \"BEST QUALIFIED\" candidates must meet both the educational requirements and the specialized experience requirements outlined below. A. Education You must meet the minimum basic educational requirements for Attorney positions. Education requirements include: a professional law degree JD, LL.B., and/or LL.M. If transcripts are not submitted at the time of application, a copy of the transcript must be submitted at the time of selection. AND B. Specialized Experience Specialized Experience: Specialized experience is experience which is in or directly related to the line of work of the position to be filled and which has equipped the applicant with the knowledge, skills, and abilities to successfully perform the duties of the position. Applicants must have a minimum of one year of specialized experience in or equivalent to the next lower grade level in the Federal Service. To Qualify for the GS-13: Applicant must possess at least two years of professional law experience and at least one year of the experience must be specialized experience at or equivalent to the GS-12 grade level in the Federal service. For this position, specialized experience includes: 1. Experience interpreting communication laws, statutes, regulations and/or rule making documents; 2. Skill analyzing legal issues, identifying potential problems and proposing solutions; 3. Experience preparing legal documents to include briefs, issue papers, and report summaries; 4. Ability to communicate legal issues/positions. To Qualify for the GS-14: Applicant must possess at least three years of professional law experience and at least one year of the experience must be specialized experience at or equivalent to the GS-13 grade level in the Federal service. For this position, specialized experience includes: 1. Experience interpreting communication laws, statutes, regulations and/or rule making documents; 2. Skill analyzing legal issues, identifying potential problems and proposing solutions; 3. Experience preparing legal documents to include briefs, issue papers, and report summaries with analysis and recommendations; 4. Ability to communicate legal issues/positions while representing the Bureau in meetings with both internal stakeholders for the purpose of providing, receiving, persuading or negotiating legal positions. To Qualify for the GS-15: Applicant must possess at least four years of professional law experience and at least one year of the experience must be specialized experience at or equivalent to the GS-14 grade level in the Federal service. For this position, specialized experience includes: 1. Experience interpreting communication laws, statutes, regulations and/or rule making documents; 2. Skill analyzing legal issues, identifying potential problems and proposing solutions; 3. Experience preparing legal documents (e.g., briefs, issue papers, and report summaries with analysis and recommendations; 4. Ability to communicate legal issues/positions while representing the Bureau in meetings with both internal stakeholders for the purpose of providing, receiving, persuading or negotiating legal positions; and 5. Providing advice, guidance, direction and leadership to other attorneys or professionals in meetings, discussions, or legal proceedings. PART-TIME OR UNPAID EXPERIENCE: Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional; philanthropic; religious; spiritual; community, student, social). Volunteer work helps build critical competencies, knowledge, and skills and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience. Education Refer to information outlined under the \"Qualifications\" subheading. Additional Information EEO Policy Statement Reasonable Accommodation Policy Statement Veterans Information Legal and Regulatory Guidance NOTE-This position is in the bargaining unit. The exclusive representative is NTEU Chapter 209.

  • Summary This position is located in the IT Security Operations and Monitoring Division within the Office of Technology, Services, and Innovation (TSI). The selectee reports to the Division Director and provides technical expertise to protect the availability, integrity, and confidentiality of agency information that is stored or processed on computing systems managed by TSI on behalf of the agency. Position is Local Remote Work Eligible. Please see Additional Information for more details. Responsibilities As an IT Cybersecurity Specialist (Information Security), you will be responsible for duties to include, but are not limited to: Serves as senior member of core Computer Incident Response Team (CIRT) to address security incidents, investigations, and resolution. Serves as a member of the IT Security Operations Center (SOC) to lead or assist in \"search and destroy\" tasks, event and alert configuration and monitoring, and reporting on operations and findings. Installs, maintains, and administrates security tools in an enterprise with cloud-based and on-premises systems. Conducts and supports investigations. Analyzes events and alerts from agency systems and networks to identify suspicious activity for potential incidents. This may include investigating activities that indicate data loss, data mishandling, account compromise, etc. This could concern PII, criminal or policy violations, phishing, etc. Investigation may involve the analysis of system logs, security tools, file stores, email or other messaging, etc. Ensure the safety of information systems assets and to protect systems and data from intentional or inadvertent access or destruction, while preserving, and where possible, enhancing information system usability. Participates in strategic planning to ensure that USAGM\'s enterprise networks have the appropriate tools and employs the correct techniques to thwart an increasing cyber-crime and cyber espionage threat. Supports the development and deployment of the agency\'s IT Security Awareness Training Program. This may come in the form of reviewing curriculum, making suggestions based on predictions and observed trends, and supporting digital security training/briefs for travelers going to high threat locations. May also include participating in briefing staff onboarding into the agency. May serve as Contracting Officer\'s Representative; required to obtain and maintain COR level 1 to manage and oversee contracts. Evaluates contractor performed services on behalf of USAGM, verifies materials delivered, and approves contractor invoices for payment. Assists with engagement of other agencies such as partial details to joint task forces relevant to USAGM and IT security operations while bringing information back to IT Security Operations on latest trends and threats. Requirements Conditions of Employment Qualifications Applicants applying for the GS-14 grade level must meet the following requirements: Have IT-related experience demonstrating EACH of the four competencies AND one year of specialized experience equivalent to the GS-13 level in the Federal service as described below. COMPETENCY REQUIREMENTS: Attention to Detail - Is thorough when performing work and conscientious about attending to detail. This skill may be demonstrated by assignments actively finding and addressing cybersecurity threats. Customer Service - Works with clients and customers (that is, any individuals who use or receive the services or products that your work unit produces, including the general public, individuals who work in the agency, other agencies, or organizations outside the Government) to assess their needs, provide information or assistance, resolve their problems, or satisfy their expectations; knows about available products and services; is committed to providing quality products and services. This skill is generally demonstrated by assignments where the applicant is the point of contact for resolving customer IT issues and ensuring their satisfaction. Oral Communication - Expresses information (for example, ideas or facts) to individuals or groups effectively, taking into account the audience and nature of the information (for example, technical, sensitive, controversial); makes clear and convincing oral presentations; listens to others, attends to nonverbal cues, and responds appropriately. This skill is generally demonstrated by assignments where the applicant serves on panels, committees, or task forces as a representative for the organization on technical or professional issues Problem Solving - Identifies problems; determines accuracy and relevance of information; uses sound judgment to generate and evaluate alternatives, and to make recommendations. This skill is generally demonstrated by assignments where the applicant troubleshoots complex IT issues and finds effective solutions. SPECIALIZED EXPERIENCE REQUIREMENTS Applicants must have a minimum of one year of specialized experience at a level of difficulty and responsibility comparable to the GS-13 or comparable pay band in the Federal service or equivalent experience in the private sector. Specialized Experience is experience that has equipped the applicant with the knowledge, skills and abilities to successfully perform the duties of the position and includes all of the following: Detecting, analyzing, and responding to IT security threats; Integrating new tools, tactics, and technologies into incident detection and response workflows; and Developing IT security procedures and recommendations to respond to IT security incidents. NOTE: Applicants must ensure their resumes reflect their experience with all of the above specialized experience criteria. Education Education is not required for this grade level. It cannot be used for qualification purposes. Additional Information Local Remote Work Possible: The selectee of this position can request a remote work agreement for a home duty station within the Washington-Baltimore-Arlington, DC-MD-VA-WV-PA pay locality area. This position does have occasional, irregular on-site responsibilities that require reporting to Washington, D.C. so home duty stations outside the Washington DC local commuting area will not be considered through this announcement. USAGM is committed to fostering a diverse and inclusive work environment. To build and retain a workforce that reflects the diverse experiences and perspectives of the American people, we welcome applicants from the many communities, identities, races, ethnicities, backgrounds, abilities, religions, and cultures of the United States who share our commitment to public service. Applicants must meet all qualification requirements by closing date of the announcement to be considered. 1. If you are a male applicant who was born after 12/31/59 and are required to register under the Military Selective Service Act, the Defense Authorization Act of 1986 requires that you be registered or you are not eligible for appointment in this agency. For Military Selective Service Act requirement information, please visit Selective Service 2. Your application to this vacancy announcement will only allow consideration for this announcement. We cannot electronically or manually move your application to corresponding announcements, if applicable. 3. Additional vacancies not reflected in the announcement that occur after the opening date of the vacancy announcement for position(s) identical (same grade, series and title) to the original vacancy may be filled from the selection certificate during the validity of the certificate. 4. Budgetary conditions may delay or otherwise affect filling this vacancy. However, all interested candidates should apply now.

Job Details

Jocancy Online Job Portal by jobSearchi.