Jobs and Careers
RS

Cyber Compliance Director- Payment Card Security

RSM
Kansas City, United Statesfull_timeVerifiedPosted 28 Jun 2024
💰 $276,100/yr($137,200/yr – $276,100/yr)

About the role

We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their full potential. Our exceptional people are the key to our unrivaled, inclusive culture and talent experience and our ability to be compelling to our clients. You’ll find an environment that inspires and empowers you to thrive both personally and professionally. There’s no one like you and that’s why there’s nowhere like RSM.

CyberCompliance Director (Payment Card Security and Technology/Media/Entertainment)

In order to address the most critical needs of our clients, RSM US LLP has established the Security and Privacy Risk Consulting (SPRC) group, comprised of dedicated cybersecurity professionals dedicated exclusively to serving the cyber security and information protection needs of our clients. This group includes experienced consultants located throughout the country dedicated to helping clients with preventing, detecting, and responding to security threats that may affect their critical systems and achieving regulatory compliance related to the handling, processing and protection of sensitive information. We serve a diverse client base within a variety of industries, and we are relied upon to provide expertise within areas of information security risk management, security testing, enterprise architecture, governance, regulatory privacy compliance, and digital forensics.

We are looking to hire a Director for our Security and Privacy Risk practice, specifically to build and enable the growth of our cybersecurity compliance services across the Technology, Media and Entertainment industry focused on cybersecurity frameworks and related data protection requirements (e.g., payment card security) .The Director of CyberCompliance will be responsible for enabling the broad growth of cybersecurity service offerings, while understanding industry specific cybersecurity risks, payment card security requirements, through assisting organizations with establishing an effective data protection program designed to safeguard critical assets, including but not limited to the cardholder data environment. This team will focus on assessing, designing and implementing cybersecurity risk management practices including network segmentation, vulnerability program management, data classification, encryption, de-identification, and sensitive data monitoring solutions to enable cyber regulatory alignment for data rich organizations.

Responsibilities

  • Continue building our payment card industry practice through expansion of team size and skill sets
  • Provide oversight and training to managers and staff during the delivery of payment card industry and other cybersecurity services to ensure quality delivery while allowing staff to learn and grow
  • Use proven business development skills to acquire additional clients and expand relationships with existing clients
  • Identify business opportunities and enhance go-to-market strategies targeting consumer product and service organizations needing payment card industry compliance services
  • Be able to communicate to clients regarding the strategic and tactical risks of account data protection, regulatory compliance, breach response, etc.
  • Assess payment card compliance maturity and help clients in building and implementing sustainable PCI compliance program
  • Support organizations through assessing, developing and implementing information governance frameworks.
  • Support clients in designing and supporting their payment card industry and cyber compliance programs including operation processes, technology and guidelines
  • Communicate complex technical issues to client senior management through the ability to transform and summarize such data into layman and executive style reports and presentations
  • Ensure revenue goals are being met and client service offerings are responsive to the changing needs in the business environment

Required Qualifications

  • Active or former PCI QSA certification, with experience preparing Level 1 and Level 2 PCI DSS Reports on Compliance (ROCs) or 3+ years PCI DSS experience with one or more of the certifications below
  • Experience with or basic working knowledge of at least some typical cybersecurity program components and common supporting workflows, including but not limited to:
    • Regulatory monitoring
    • Business requirements definition
    • Data inventory and information flow mapping
    • Cybersecurity risk management
    • Third party vendor management
    • Interactions with consumers / individuals (data subject requests)
    • Incident management and breach notifications
  • Bachelo

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

RSM

View company profile →