Security Advisor - PCI Practice

Security Advisor - PCI Practice

15 Oct 2024
District of Columbia, Washington, 20001 Washington USA

Security Advisor - PCI Practice

CampusGuard, a Nelnet Company, provides information security services for campus-based organizations including higher education institutions, healthcare providers, city, county and state government agencies and hospitality markets. As a full-service information security firm, we leverage our knowledge combined with the industry standards for compliance and information security issues to provide our customers with world class information security & compliance services.CampusGuard, a Nelnet company, provides cybersecurity and compliance services for campus-based organizations including higher education institutions, healthcare providers, state and local government agencies, utilities and hospitality markets. As a full-service firm, we leverage our knowledge combined with the industry standards for compliance and information security issues to provide our customers with world class information cybersecurity & compliance services.The Security Advisor provides information security and compliance consulting services using accepted standards, frameworks, and best practices including but not limited to PCI DSS, NIST SPs 800-53 and 800-171, NIST CSF, and ISO 27001. Security Advisors assess and report on customers’ compliance with various rules, regulations, and standards such as PCI DSS, CMMC, GDPR, FERPA, HIPAA/HITECH, GLBA, and FCRA Red Flags. The Security Advisor will gather and analyze customer information, make remote and/or physical site visits, conduct interviews, make observations, take appropriate notes, perform gap analysis, review evidence and documentation, and complete reports on findings, with remediation recommendations included where necessary. Security Advisors provide ongoing consultation services to customers via recurring and ad-hoc meetings and email communications, and assist with periodic support activities with customers, such as tabletop exercises and facilitating risk assessments, to ensure continued compliance. The Security Advisor provides sales support in the form of conference attendance/presentations, collaborates with Customer Relationship Manager (CRM) partners, and performs other tasks as needed/assigned, including but not limited to: time entry, internal meetings, create/revise both internal- and customer-facing documents and tools, and attend training seminars/webinars.JOB RESPONSIBILITIES:Security Advisors are responsible for assessing and reporting on customer business and technical environments, operations/procedures, administration of infrastructure (from network border to endpoints and everything in-between), and overall compliance programs, as measured against relevant industry standards. The PCI Practice Security Advisor will focus primarily on PCI DSS assessments and compliance (including Reports on Compliance), though work to support other service lines, including those within the Privacy Practice, can arise periodically. Customer support of general information security is a shared responsibility between the PCI and Privacy Practices.Responsibilities of the PCI Practice Security Advisor include, but are not limited to the following:

Consult both onsite and remotely with customers to collect, review, and analyze data related to current institutional policies, business practices and procedures, network infrastructure, IT system configurations and physical security as they relate to multiple compliance requirements (primarily PCI DSS).

Performing gap analysis of sampled merchant environments and overall compliance program/centralized controls.

Provide in-person or remote orientation sessions to customer personnel.

Review requirements with third-party service providers as necessary to clarify roles and help the customers achieve information security and compliance objectives.

Make recommendations for remediation steps required to achieve information security and compliance objectives.

Upon requests from ongoing customers, the Security Advisor may review customer-prepared industry reports (such as a PCI Self-Assessment Questionnaire) and provide feedback/guidance to ensure accurate reporting, or in some cases assist the customer with the preparation of required industry-standard reporting obligations.

This is a remote work position.Candidate must be able to work in a home office environment with minimal supervision.

Ability to travel required (potentially up to 50%).

Other duties as assigned.

Security Advisors use standardized procedures and methods to assess the security and monitor the on-going compliance of each customer:

Perform gap assessments through interviews, observations, evidence review, and physical/remote assessments to evaluate customer networks, infrastructure and operations as it relates to compliance objectives (primarily PCI DSS).

Report on findings and provide customers with remediation options when appropriate.

Security Advisors assist with sales and marketing activities:

Participate in sales calls as an industry expert. Attend conferences as appropriate.

Prepare and perform industry-related presentations and/or webcasts. Other sales/marketing support duties as requested.

EDUCATION:Minimum acceptable education requirements: Bachelor’s degree, and/or 5 years’ experience in the information security industry (preferably at an institution of higher education) Minimum acceptable certification requirements: Possess at least one of the industry-recognized information security and/or audit certification(s) required to obtain the Qualified Security Assessor (QSA) certification. See lists below. Possessing both information security and audit certifications and an active QSA certification is a plus.Information Security certifications:

ISC2 Certified Information System Security Professional (CISSP)

ISACA Certified Information Security Manager (CISM)

Certified ISO 27001 Lead Implementer (when issued by an accredited certification body)

Audit certifications:

ISACA Certified Information Systems Auditor (CISA)

GIAC Systems and Network Auditor (GSNA)

Certified ISO 27001 Lead Auditor or Internal Auditor (when issued by an accredited certification body)

IRCA ISMS Auditor or higher—e.g., Auditor/Lead Auditor, Principal Auditor (“Provisional” auditor designations are not sufficient)

IIA Certified Internal Auditor (CIA)

Note: Candidates must agree to prepare for and pass the PCI Qualified Security Assessor (QSA) certification and any other certifications as directed by their manager.Pay Range for this position is -$95,000 and up (amount changes on industry certifications and PCI assessment experience.)EXPERIENCE:Minimum acceptable work experience requirements: All candidates must have a minimum of five years of relevant information security experience, to align with the minimum experience requirements for a QSA. This experience must cover at least one year each in application security, information systems security, network security, IT security auditing, and information security risk assessment or risk management. At least two years’ experience working with PCI DSS compliance is required, either as an assessor or internally to manage PCI DSS compliance.SKILLS/KNOWLEDGE/ABILITIES:Knowledge and experience with consulting, implementing, or supporting PCI DSS and other compliance/assessment efforts including:

Understanding and familiarity with PCI DSS and supporting standards/programs, including but not limited to: PTS, SSF, P2PE, SPoC, MPoC, etc.

Core PCI DSS compliance program elements, such as policy, procedure, training, service provider oversight, device protection, inventory/scope verification, and incident response.

Targeted risk analyses.

SAQs, Report on Compliance template, and other relevant guidance documents and tools provided by the PCI SSC.

Familiarity with industry-standard security and compliance documents/frameworks, such as NIST SP 800-171, NIST CSF, ISO 27001, GLBA and other standards.

Creative problem-solving and customer engagement including:

Collaborating, identifying, and addressing customer needs through relationship building and understanding customer’s business and needs.

Familiarity with Education, Healthcare, and Government institution and their structures, operations, and security needs.

Understanding of information systems, networks, and related security issues.

Communicating in written, verbal, and video formats.

Communicating both quantitative and qualitative analyses.

Creating high-quality deliverables using appropriate business and technical language.

Our benefits package includes medical, dental, vision, HSA and FSA, generous earned time off, 401K/student loan repayment, life insurance & AD&D insurance, employee assistance program, employee stock purchase program, tuition reimbursement, performance-based incentive pay, short- and long-term disability, and a robust wellness program. Click here to learn more about our benefits: LINK (http://nelnetinc.com/careers/benefits/) .Nelnet is an Equal Opportunity Employer, complies with Executive Order 11246, and takes affirmative action to ensure that qualified applicants are employed, and that employees are treated during employment, without regard to race, color, religion/creed, national origin, gender, or sex, marital status, age, disability, use of a guide dog or service animal, sexual orientation, military/veteran status, or any other status protected by Federal or State law or local ordinance.Qualified individuals with disabilities who require reasonable accommodations in order to apply or compete for positions at Nelnet may request such accommodations by contacting Corporate Recruiting at 402-486-5725 or corporaterecruiting@nelnet.net .Nelnet is a Drug Free and Tobacco Free Workplace.You may know Nelnet as the nation’s largest student loan servicer – but we do more than that. A lot more. We’re also a professional services company, consumer loan originator and servicer, payment processor, renewable energy innovator, and K-12 and higher education expert (and that’s just a shortlist). For over 40 years, we’ve been serving our customers, associates, and communities to make dreams possible.EEO Info (https://nelnetinc.com/wp-content/uploads/EEO-poster.pdf) | EEO Letter (https://nelnetinc.com/wp-content/uploads/EEO-Jeffs-Letter.pdf) | EPPA Info (https://nelnetinc.com/wp-content/uploads/Employee-Polygraph-Protection-Act-Poster.pdf) | FMLA Info (https://nelnetinc.com/wp-content/uploads/FMLA-Leave.pdf)

Related jobs

  • Job Description ​

  • Cyber Oracle Cloud Security -Consultant

  • Req ID: RQ186031

  • Job Number 24177707

  • SGI Global is seeking a Security Analyst to support the U.S. Government Publishing Office (GPO). The Security Analyst will play a pivotal role in protecting the integrity and confidentiality of classified information, adhering to established legal and policy frameworks.

  • Summary This position is located in Workforce and Inclusion, in the Personnel Security Group. This is not a remote work position. Open to the first 75 applicants or until 10/23/2024 whichever comes first. All applications submitted by 11:59 (EST) on the closing day will receive consideration. Responsibilities The major duties of the Personnel Security Assistant position include but are not limited to: Interpretation and application of security and suitability guidelines, policies, and procedures. Initiating, processing, and adjudication of employee background investigations. Provide customer service and assistance to applicants and internal customers to ensure they have an understanding of the personnel security process. Processing of employee, contractor, and volunteer Homeland Security Directive 12 (HSPD-12) and Personal Identity Verification (PIV) Cards. Duties will be developmental in nature when filled below the full performance level. Requirements Conditions of Employment U.S. Citizenship required. Appointment subject to background investigation and favorable adjudication. Meet Selective Service Registration Act requirement for males Selectee will be required to participate in the Direct Deposit Electronics Funds Transfer Program. Any individual who is currently holding, or has held within the previous 52 weeks, a General Schedule position under non-temporary appointment in the competitive or excepted service, must meet time-in-grade requirements (must have served 52 weeks at the next lower grade or equivalent in the Federal service); with few exceptions as outlined in 5 CFR 300.603(b). Time-In-Grade requirements also apply to former Federal civilian employees applying for reinstatement who have had a break in service of less than one year, as well as current employees applying for Veterans Employment Opportunities Act of 1998 (VEOA) appointments. Time-in-grade does not apply to new excepted service appointments and must be met by the closing date of this announcement. If you are a new employee or supervisor in the Federal government, you will be required to complete a one-year probationary period. You may be required to travel overnight away from home up to 1 night per month. You must obtain a government charge card for travel purposes. You may be required to complete training and obtain/maintain a government charge card with travel and/or purchase authority. Qualifications All qualifications must be met by the closing date of this announcement-10/23/2024-unless otherwise stated in this vacancy announcement. Credit will be given for all appropriate qualifying experience. For current Federal employees, if hours worked per week are not included on your resume, you must submit a non-award SF-50 for each federal position listed as part of your application to be used to validate your work schedule and determine the amount of qualifying experience that you will be granted. An award SF-50 will not be acceptable documentation for which to consider your amount of qualifying experience. For all other applicants who are not current federal employees, your resume must state either \"full-time\" (or \"40 hours a week\") or \"part-time\" with the number of hours worked per week to ensure proper crediting of specialized experience. Failure to adequately provide information needed to determine number of hours worked in each position may result in that time not being credited when evaluating qualifying experience. For periods of time that reflect military service, the DD-214 or Statement of Service is sufficient to meet the full and/or part-time hours requirement as the service dates will be reflected. Minimum Qualifications To qualify for this position at the GS-6 grade level, you must possess the following minimum qualifications by close of the announcement: EXPERIENCE: At least one full year of specialized experience comparable in scope and responsibility to the GS-5 grade level in the Federal service (obtained in either the public or private sectors). Experience at this level must include all of the following: 1) Reviewing and processing documents for Tier 1 background investigations; 2) Reviewing security packages and identifying if all required background investigation documents have been submitted; and, 3) Reviewing the status of investigations and updating into a personnel security database. You must include hours per week worked. OR To qualify for this position at the GS-7 grade level, you must possess the following minimum qualifications by close of the announcement: EXPERIENCE: At least one full year of specialized experience comparable in scope and responsibility to the GS-6 grade level in the Federal service (obtained in either the public or private sectors). Experience at this level must include all of the following: 1) Preparing and processing documents for Tier 1 through 5 background investigations; 2) Analyzes security documents to ensure all required information is complete; 3) Requests missing documents and required information; 4) Initiates background investigations within an electronic system; 5) Sponsors individuals for fingerprinting through the use of an electronic system; and 6) Requesting updates from security specialists regarding the status of investigation to verify and update information into a personnel security database. You must include hours per week worked. OR To qualify for this position at the GS-8 grade level, you must possess the following minimum qualifications by close of the announcement: EXPERIENCE: At least one full year of specialized experience comparable in scope and responsibility to the GS-7 grade level in the Federal service (obtained in either the public or private sectors). Experience at this level must include all of the following: 1) Preparing and processing documents for Tier 1 through 5 background investigations; 2) Analyzes security documents to ensure all required information is complete; 3) Requests missing documents and required information; 4) Initiates background investigations within an electronic system; 5) Sponsors individuals for fingerprinting through the use of an electronic system; 6) Requesting updates from security specialist regarding the status of investigation to verify and update information into a personnel security database; and, 7) Experience drafting Identification and assessment Job Aids (IIAs) for SAC and credit checks for pre-employment cases and background investigations related to non-issues and minor-issues. You must include hours per week worked. You must include months, years and hours per week worked to receive credit for your work and/or volunteer experience. One year of specialized experience is equivalent to 12 months at 40 hours per week. Part-time hours are prorated. You will not receive any credit for experience that does not indicate exact hours per week or is listed as \"varies\". Experience listed as full-time will be credited at 40 hours per week. Volunteer Experience: Experience refers to paid and unpaid experience, including volunteer work done through National Service programs (e.g., Peace Corps, AmeriCorps) and other organizations (e.g., professional; philanthropic; religious; spiritual; community, student, social). Volunteer work helps build critical competencies, knowledge, and skills and can provide valuable training and experience that translates directly to paid employment. You will receive credit for all qualifying experience, including volunteer experience. Education There is no substitution of education for experience at the grade level(s) of this announcement. Additional Information A selectee receiving a first appointment to the Federal Government (Civil Service) is entitled only to the lowest step of the grade for which selected The display of a salary range on this vacancy shall not be construed as granting an entitlement to a higher rate of pay. This announcement may be used to fill additional positions if identical vacancies occur within 90 days of the issue date of the referral certificate. Promotion to the full performance level is neither guaranteed nor implied and will be based solely on your ability to satisfactorily perform the work of the position, existing work at the higher grade level, and recommendation by the position\'s supervisor. Physical Demands: The work is primarily sedentary, although some slight physical effort may be required. Working Conditions: Work is typically performed in an adequately lighted and climate-controlled office. May require occasional travel. The National Park Service has determined that the duties of this position are suitable for telework and the selectee may be allowed to telework with supervisor approval. Documentation for the Land Management Workforce Flexibility Act (LMWFA) eligibility, You must submit ALL SF-50s and performance information for each period of temporary/term employment that qualifies for LMWFA. Performance documentation can be obtained by contacting the supervisors for the positions you served in during your 24 months. If they did not complete performance appraisals ask them to provide a statement of performance for each period of service. The statement must specify the dates for each employment period and your level of performance consistent with your SF50s.

  • Stay inspired by joining the stunning Conrad hotel located in the heart of urban DC as a Security Officer !

Job Details

Jocancy Online Job Portal by jobSearchi.