Director, Internal Security Assessor
GEICOAbout the role
About GEICO
For more than 75 years, GEICO has stood out from the rest of the insurance industry! As a wholly owned subsidiary of Berkshire Hathaway, we are one of the nation's largest, fastest-growing and financially stable auto insurers thanks to our low rates, outstanding service and clever marketing. In 2023, GEICO earned premiums worth over $40 billion U.S. dollars.
GEICO is going through a massive digital transformation to re-platform the Insurance industry, removing friction across Customers, Partners, Marketplace, Segments, Channels, and Experiences as we grow our reach and market share. Our success is no secret - it's the result of investing in dedicated and hardworking associates who provide exceptional service and solutions to our clients.
We are seeking an experienced Internal Security Assessor (ISA) to lead our Payment Card Industry (PCI) Data Security Standard (DSS) compliance and internal controls program. You will be integral to ensuring the organization’s systems, processes, and controls meet PCI DSS requirements while fostering collaboration across IT, business, and corporate functions. You’ll ensure the security of customer data while shaping the future of our compliance programs. You bring extensive Big 4 or comparable consulting experience, CISO-level leadership expertise, a proven track record in board reporting, and the ability to deliver impactful PCI-focused technology, security initiatives and transformative solutions.
Location:
Hybrid (3 days per week in office) in our Manhattan, NY; Chevy Chase, MD; Chicago, IL; or Dallas, TX office
Periodic (25%) travel to New York, NY and Chevy Chase, MD
Key Responsibilities:
As GEICO’s Internal Security Assessor, you will be accountable for:
PCI DSS Compliance: Lead the transformation and execution of GEICO’s PCI DSS compliance program, conducting gap analyses, managing remediation efforts, and preparing for audits.
Control Frameworks: Design, implement, and monitor controls to ensure continuous PCI DSS compliance, addressing areas such as access management, encryption, logging, and monitoring.
Technology and Security Initiatives: Deliver PCI-specific security solutions, such as tokenization, centralized MFA for PCI environments, and advanced threat detection to safeguard payment card data.
Partner Integrations: Conduct PCI DSS-focused due diligence during merger & acquisition, vendor engagements or integration activities, ensuring seamless integration of internal and external partners into GEICO’s compliance framework and mitigating risks related to cardholder data security.
Automation and Efficiency: Drive automation of PCI DSS evidence collection, audit preparation, and reporting processes to improve compliance efficiency and reduce manual effort.
Senior Leadership Reporting: Provide regular updates to senior leadership on PCI DSS compliance status, key risks, and remediation plans, ensuring alignment with business goals.
Collaboration: Partner with Technology, infrastructure, and business teams to integrate PCI DSS requirements into all relevant processes, ensuring compliance is embedded in day-to-day operations.
Governance and Risk Management: Align PCI DSS compliance efforts with broader governance frameworks, such as NIST CSF and ISO 27001, to support enterprise risk management.
Training and Awareness: Develop and lead PCI DSS-specific training programs to increase organizational awareness and foster a culture of compliance.
Qualifications:
Bachelor’s degree in Computer Science, or a related field. An MBA or advanced Technology degree (completed or in progress) is preferred.
Leadership experience as a CISO or CISO-adjacent role, managing PCI DSS compliance programs and reporting to executive stakeholders.
Extensive Big 4 or comparable consulting experience, delivering PCI DSS solutions for enterprise clients.
Proven success in developing and implementing PCI DSS compliance strategies, conducting audits, and managing remediation projects.
Expertise in conducting PCI DSS-focused due diligence for M&A activities and integrating compliance into acquired entities.
Technical Skills: In-depth knowledge of PCI DSS requirements and security technologies such as tokenization, SIEM, DLP, encryption, and logging solutions within PCI environments.
Soft Skills: Strong communication (verbal and written) and leadership skills, with the ability to engage both technical and non-technical stakeholders in PCI DSS initiatives.
#LI-AN1
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s