Jobs and Careers
ST

cybersecurity analyst senior, PCI compliance

Starbucks
United Statesfull_timeVerifiedPosted 30 Jul 2026

About the role

Now Brewing - cybersecurity analyst senior, PCI compliance! #tobeapartner


This role supports Starbucks Technology as a technical PCI DSS v4.0 SME, partnering with architecture, infrastructure, application, and platform teams to design, validate, and automate controls across payment environments.  The role combines hands-on understanding of network architecture, segmentation, encryption, data flows, and cardholder data environment (CDE) scoping with the ability to translate PCI requirements into practical engineering patterns to reduce risk and minimize compliance scope. The cybersecurity analyst sr partners with engineering teams to design and validate solutions that meet PCI requirements while minimizing scope. This role leads PCI scoping and segmentation efforts, translates requirements into technical implementations, and supports GRC capabilities including automation, continuous monitoring, and evidence orchestration. Operates independently to identify risks and drive cross-functional improvements.


As a cybersecurity analyst senior, PCI compliance you will....

PCI Architecture & Engineering

  • Lead technical PCI architecture reviews by evaluating segmentation models, network paths, trust boundaries, service-to-service interactions, cloud and hybrid connectivity, and system components that store, process, transmit, or could impact cardholder data.
  • Provide technical guidance on encryption for data at rest and in transit, tokenization, certificate and key management, cryptographic control design, and implementation patterns that satisfy PCI requirements without adding unnecessary scope or operational friction.
  • Lead PCI scoping by validating data-flow diagrams, payment transaction paths, CHD lifecycle stages, connected systems, compensating controls, and segmentation assumptions across applications, infrastructure, networks, cloud platforms, and third-party integrations.
  • Identify opportunities to eliminate or reduce cardholder data storage and shrink PCI scope


     

Compliance Program Operations 

  • Translate PCI DSS requirements into technical requirements and control implementations
  • Support PCI assessments (QSA-facing), including evidence validation, control testing, and remediation planning
  • Design and maintain risk and control matrices aligned to PCI and enterprise standards
  • Track remediation, risk acceptance, and exceptions with stakeholders
  • Provide guidance on use of compliance and risk management tools and processes
  • Develop documentation and training for compliance processes and tooling

Solution Design and Automation 

  • Design and build automated approaches for continuous PCI control validation and evidence collection, using integrations, APIs, data models, workflow automation, and telemetry from security, infrastructure, cloud, and GRC/IRM platforms.
  • Develop metrics, dashboards, and control-health views that use system data and control telemetry to show PCI coverage, remediation status, exception trends, and risk exposure.
  • Gather, analyze, and document solution requirements. Facilitate user story creation and backlog grooming in an agile delivery environment
  • Utilize agile delivery methodologies and participates on scrum teams to deliver on projects
  • Effectively assess overall improvement opportunities (productivity/efficiency gains, cost savings, etc.)

Collaboration & Delivery 

  • Partner with engineering teams to embed PCI requirements into system design 
  • Provide guidance aligned to policies, standards, and risk reduction
  • Develop reusable templates, documentation, and training
  • Support delivery of compliance capabilities and program metrics (KPIs)
  • Self-directed; is successful with minimal direction from more senior analysts providing escalation when necessary

 

We'd love to hear from people with...
 

Basic Qualifications

  • Bachelor's degree in computer science, information systems, cybersecurity, engineering, or a related field, or 3+ years of relevant experience in cybersecurity, infrastructure, application, cloud, compliance automation, or technology risk roles.
  • Translate business, technology, and compliance objectives into practical technical requirements, implementation guidance, and control outcomes across cross-functional engineering and risk activities.
  • Apply analytical and problem-solving skills to evaluate system designs, data flows, control evidence, root causes, and remediation options in complex technology environments.
  • Create clear technical documentation, including data-flow narratives, control evidence, implementation guidance, process documentation, and materials that help engineeri

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Starbucks

View company profile →