Jobs and Careers
BL
Senior Consultant – PCI Qualified Security Assessor
Bloom Equity PartnersUnited States - Remote, United StatesRemotefull_timeVerifiedPosted 28 May 2026
About the role
Remote Role
Role Purpose
The Senior Consultant – Cyber Security & PCI Qualified Security Assessor (QSA) is a senior delivery and trusted-advisor role within our GRC Advisory practice, accountable for leading high-quality cyber security and compliance engagements with a primary focus on PCI DSS, supplemented by broader cyber risk, governance, and assurance services.Role Purpose
The role leads client engagements end-to-end—planning, execution, quality assurance, stakeholder management, and close-out—working independently or leading small project teams. The Senior Consultant contributes actively to the growth, capability, and reputation of the practice.
Key Responsibilities & Accountabilities
Client Delivery & Engagement Leadership- Lead cyber security and PCI DSS client engagements from initiation through delivery and closure.
- Act as primary client point of contact, ensuring clear communication, scope control, and expectation management.
- Deliver high-quality, concise, and actionable reports suitable for technical teams, senior management, and executive stakeholders.
- Apply judgement and experience to complex risk and compliance issues, ensuring pragmatic, proportionate recommendations.
- Perform PCI DSS assessments in line with PCI SSC requirements, including:
- Scoping and gap assessments
- On-site and remote assessments
- Completion of SAQs, Reports on Compliance (ROC), and Attestations of Compliance (AOC)
- Provide expert advice on PCI DSS control implementation, compensating controls, and remediation planning.
- Support clients in achieving and maintaining PCI DSS compliance across complex environments.
- Stay current with PCI DSS standard updates, guidance, and assessor program requirements.
- Deliver broader cyber security advisory services, including:
- Information security risk assessments and business impact analysis
- Governance, risk, and compliance (GRC) assessments
- Framework-based assessments (e.g. ISO/IEC 27001, ISO/IEC 42001, NIST CSF, NIST 800-53, SOC 2, HIPAA, SABSA, COBIT)
- Cyber supply chain security and third-party risk assessments
- Advise clients on the design and improvement of cyber security strategies, policies, and control environments.
- Investigate significant security incidents or control failures and recommend control improvements.
- Take responsibility for quality assurance of own work and contributions from junior team members.
- Ensure delivery is compliant with internal methodologies, standards, and contractual requirements.
- Participate in peer reviews, knowledge sharing, and continuous improvement of consulting practices and assets.
- Identify and nurture commercial opportunities during engagements and contribute to account growth.
- Support pre-sales activities including proposal writing, tender responses, and client presentations.
- Mentor consultants and junior team members, supporting their professional and technical development.
- Contribute to internal training, capability development, and thought leadership activities.
Key Performance Indicators
- Successful delivery of cyber security and PCI DSS engagements to time, quality, and budget.
- Client satisfaction and trusted-advisor status.
- Identification and support of new commercial opportunities.
- Effective stakeholder engagement and team leadership.
- Contribution to practice capability, knowledge sharing, and mentoring.
Person Specification
Knowledge & Experience (Essential)- Minimum 2+ years' experience as a PCI DSS Qualified Security Assessor (QSA) del
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s