InfoSec PCI Compliance Specialist
PepsiCoAbout the role
Overview
The InfoSec PCI (Payment Card Industry) Compliance Specialist will be responsible for facilitating PepsiCo internal business units around the world maintain compliance to the PCI Data Security Standard (DSS) by assisting them to evaluate the applicable controls in completing the relevant PCI Self-Assessment Questionnaire (SAQ). The InfoSec PCI Compliance Specialist will also be involved in providing guidance on PCI Compliance as new business solutions around the world are being evaluated, designed, and deployed.
The InfoSec PCI Compliance Specialist will influence PepsiCo's e-commerce strategy to increase sales of our products while ensuring PepsiCo complies with regulatory and financial requirements when handling payment instruments such as credit/ debit cards around the world. The InfoSec PCI Compliance Specialist will collaborate and partner with Finance and the Business around the world to pursue PCI DSS assessments of solutions and third parties handling credit cards on behalf of PepsiCo. This position will also improve the PCI DSS assessment process based on best industry practices, the evolving threat landscape, the changing PCI standards, PepsiCo's risk appetite and capability maturity model, and unique business needs around the world. The InfoSec PCI Compliance Specialist will develop and update training material and tools, and perform necessary training sessions, that allow employees around the world to understand when the PCI DSS requirements are applicable, and how to support the corresponding assessments.
Responsibilities
PCI DSS Assessments:
- Perform PCI DSS assessments for all solutions handling payment card information.
- Maintain compliance with established PCI governance standards.
Risk Evaluation and Communication:
- Evaluate system and data flows for security risks and compliance gaps.
- Communicate results and actions to business units.
Training and Development:
- Complete annual PCI ISA training.
- Develop and update training materials and conduct necessary training sessions.
Technology and Process Improvement:
- Evaluate technologies/architectures used by PepsiCo and partners.
- Implement global process improvements for PCI compliance assessments.
- Learn and understand credit card handling technologies/architectures.
Reporting and Documentation:
- Develop reports and present findings to various organizational levels.
- Create and update PCI compliance awareness documentation.
Collaboration and Alignment:
- Facilitate alignment across diverse parties and business units.
- Review information security requirements in contracts with third parties.
- Understand technical and business arrangements with third parties to support PCI DSS compliance.
Compensation and Benefits:
- The expected compensation range for this position is between $106,400 - $178,100.
- Location, confirmed job-related skills, experience, and education will be considered in setting actual starting salary. Your recruiter can share more about the specific salary range during the hiring process.
- Bonus based on performance and eligibility target payout is 12% of annual salary paid out annually.
- Paid time off subject to eligibility, including paid parental leave, vacation, sick, and bereavement.
- In addition to salary, PepsiCo offers a comprehensive benefits package to support our employees and their families, subject to elections and eligibility: Medical, Dental, Vision, Disability, Health, and Dependent Care Reimbursement Accounts, Employee Assistance Program (EAP), Insurance (Accident, Group Legal, Life), Defined Contribution Retirement Plan.
Qualifications
Experience and Technical Skills:
- PCI Compliance: 3+ years in PCI compliance and governance (QSA, TPSRM Assessor, or ISA).
Technical/Project Management:
- 3+ years across various technologies (web, networking, firewalls, applications, cloud, etc.).
PCI SAQ Assessments:
- Expertise in performing and passing PCI ISA certification.
Information Security:
- Strong understanding of frameworks (NIST, PCI DSS, ISO), reference models (cyber kill chain, MITRE ATT&CK), and cyber concepts.
Technical Knowledge:
- In-depth experience with infrastructure, encryption, access management, payment devices, e-commerce, cloud services, and DevSecOps principles.
Non-Technical Skills:
- Communication: Strong verbal and w
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s