{"schemaVersion":"jobsearcher.job.v1","id":"69458c3b8b26452e00054c16","url":"https://jobsearcher.com/jobs/69458c3b8b26452e00054c16","canonicalUrl":"https://jobsearcher.com/jobs/69458c3b8b26452e00054c16","title":"Lead GRC Security Analyst","description":"We are seeking an experienced Information Security GRC professional with strong PCI DSS expertise to lead the design, implementation, and ongoing execution of an enterprise PCI DSS v4.0 compliance program within a highly regulated environment.\nThis role will serve as the organization’s PCI subject matter expert (SME) , responsible for ensuring accurate Cardholder Data Environment (CDE) scoping, sustainable control implementation, continuous compliance, and effective governance. The successful candidate will work cross-functionally with Security, IT, Risk, Compliance, Audit, and business stakeholders to embed PCI requirements into technology and operational processes.\nThis is a highly visible role requiring someone who can operate strategically while also being comfortable getting into the details of controls, evidence, assessments, remediation, and audit readiness.\nKey Responsibilities\nLead the enterprise PCI DSS v4.0 program , including governance, compliance, assessment, and continuous improvement activities.\nValidate and maintain accurate Cardholder Data Environment (CDE) scope .\nServe as the primary PCI DSS subject matter expert across the organization.\nPartner with Security, IT, Risk, Compliance, Audit, and business teams to drive cross-functional accountability for PCI requirements.\nManage relationships with Qualified Security Assessors (QSAs) and coordinate PCI assessments from preparation through remediation and closure.\nDevelop and manage remediation strategies for PCI and security control gaps.\nSupport risk acceptance processes and ensure appropriate documentation and governance.\nTest and evaluate control effectiveness and maintain clear control traceability.\nManage evidence collection, assessment walkthroughs, findings, remediation, and closure activities.\nSupport internal and external audits as well as regulatory examinations.\nConduct security risk and control assessments.\nDevelop and report KRIs, KPIs, OKRs, and other security/compliance metrics .\nPresent security, risk, and control findings to both technical stakeholders and executive leadership.\nLead reviews, updates, and approvals of security policies, standards, and related governance documentation.\nEmbed PCI requirements into technology and operational lifecycles.\nDrive ongoing improvements to the organization’s security compliance and risk management processes.\nTechnical Environment\nPCI DSS v4.0\nInformation Security Governance, Risk & Compliance (GRC)\nServiceNow, LogicGate, Archer, or similar GRC platforms\nNIST Cybersecurity Framework (CSF) 2.0\nCIS Controls v8\nSecurity controls and compliance management\nRisk assessments\nAudit management\nPolicy and standards governance\nRegulatory compliance and examination support\n\nRequired Qualifications\n5–8 years of experience in Information Security GRC , with at least 3 years of hands-on PCI DSS experience .\nDemonstrated experience owning or leading an enterprise PCI DSS program .\nStrong experience with CDE scoping and PCI DSS control requirements .\nExperience managing QSA relationships and leading PCI assessments through preparation, assessment, remediation, and closure.\nExperience with GRC platforms such as ServiceNow, LogicGate, Archer, or similar .\nExperience supporting internal/external audits, regulatory examinations, evidence collection, and remediation.\nWorking knowledge of NIST CSF 2.0 and CIS Controls v8 , including the ability to map controls across security and compliance frameworks.\nExperience developing and presenting KRIs, KPIs, OKRs, and security/risk metrics .\nStrong communication skills with the ability to explain complex PCI and security control gaps to non-technical audiences and executive leadership.\nBachelor’s degree in Information Security, Computer Science, Risk Management, or a related field .\n\nTechnology Doesn't Change the World, People Do. ®\n\nRobert Half is the world’s first and largest specialized talent solutions firm that connects highly qualified job seekers to opportunities at great companies. We offer contract, temporary and permanent placement solutions for finance and accounting, technology, marketing and creative, legal, and administrative and customer support roles.\n\nRobert Half works to put you in the best position to succeed. We provide access to top jobs, competitive compensation and benefits, and free online training. Stay on top of every opportunity - whenever you choose - even on the go. Download the Robert Half app and get 1-tap apply, notifications of AI-matched jobs, and much more.\n\nAll applicants applying for U.S. job openings must be legally authorized to work in the United States. Benefits are available to contract/temporary professionals, including medical, vision, dental, and life and disability insurance. Hired contract/temporary professionals are also eligible to enroll in our company 401(k) plan. Visit roberthalf.gobenefits.net for more information.\n\n© 2025 Robert Half. An Equal Opportunity Employer. M/F/Disability/Veterans. By clicking “Apply Now,” you’re agreeing to Robert Half’s Terms of Use and Privacy Notice .","company":"Robert Half","rawCompany":"robert half","city":"Appleton","state":"WI","isRemote":false,"isActive":false,"createdAt":"2026-08-31T09:10:29.144Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"},{"code":"11-9199.02","title":"Compliance Managers","slug":"compliance-managers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Lead GRC Security Analyst","description":"We are seeking an experienced Information Security GRC professional with strong PCI DSS expertise to lead the design, implementation, and ongoing execution of an enterprise PCI DSS v4.0 compliance program within a highly regulated environment.\nThis role will serve as the organization’s PCI subject matter expert (SME) , responsible for ensuring accurate Cardholder Data Environment (CDE) scoping, sustainable control implementation, continuous compliance, and effective governance. The successful candidate will work cross-functionally with Security, IT, Risk, Compliance, Audit, and business stakeholders to embed PCI requirements into technology and operational processes.\nThis is a highly visible role requiring someone who can operate strategically while also being comfortable getting into the details of controls, evidence, assessments, remediation, and audit readiness.\nKey Responsibilities\nLead the enterprise PCI DSS v4.0 program , including governance, compliance, assessment, and continuous improvement activities.\nValidate and maintain accurate Cardholder Data Environment (CDE) scope .\nServe as the primary PCI DSS subject matter expert across the organization.\nPartner with Security, IT, Risk, Compliance, Audit, and business teams to drive cross-functional accountability for PCI requirements.\nManage relationships with Qualified Security Assessors (QSAs) and coordinate PCI assessments from preparation through remediation and closure.\nDevelop and manage remediation strategies for PCI and security control gaps.\nSupport risk acceptance processes and ensure appropriate documentation and governance.\nTest and evaluate control effectiveness and maintain clear control traceability.\nManage evidence collection, assessment walkthroughs, findings, remediation, and closure activities.\nSupport internal and external audits as well as regulatory examinations.\nConduct security risk and control assessments.\nDevelop and report KRIs, KPIs, OKRs, and other security/compliance metrics .\nPresent security, risk, and control findings to both technical stakeholders and executive leadership.\nLead reviews, updates, and approvals of security policies, standards, and related governance documentation.\nEmbed PCI requirements into technology and operational lifecycles.\nDrive ongoing improvements to the organization’s security compliance and risk management processes.\nTechnical Environment\nPCI DSS v4.0\nInformation Security Governance, Risk & Compliance (GRC)\nServiceNow, LogicGate, Archer, or similar GRC platforms\nNIST Cybersecurity Framework (CSF) 2.0\nCIS Controls v8\nSecurity controls and compliance management\nRisk assessments\nAudit management\nPolicy and standards governance\nRegulatory compliance and examination support\n\nRequired Qualifications\n5–8 years of experience in Information Security GRC , with at least 3 years of hands-on PCI DSS experience .\nDemonstrated experience owning or leading an enterprise PCI DSS program .\nStrong experience with CDE scoping and PCI DSS control requirements .\nExperience managing QSA relationships and leading PCI assessments through preparation, assessment, remediation, and closure.\nExperience with GRC platforms such as ServiceNow, LogicGate, Archer, or similar .\nExperience supporting internal/external audits, regulatory examinations, evidence collection, and remediation.\nWorking knowledge of NIST CSF 2.0 and CIS Controls v8 , including the ability to map controls across security and compliance frameworks.\nExperience developing and presenting KRIs, KPIs, OKRs, and security/risk metrics .\nStrong communication skills with the ability to explain complex PCI and security control gaps to non-technical audiences and executive leadership.\nBachelor’s degree in Information Security, Computer Science, Risk Management, or a related field .\n\nTechnology Doesn't Change the World, People Do. ®\n\nRobert Half is the world’s first and largest specialized talent solutions firm that connects highly qualified job seekers to opportunities at great companies. We offer contract, temporary and permanent placement solutions for finance and accounting, technology, marketing and creative, legal, and administrative and customer support roles.\n\nRobert Half works to put you in the best position to succeed. We provide access to top jobs, competitive compensation and benefits, and free online training. Stay on top of every opportunity - whenever you choose - even on the go. Download the Robert Half app and get 1-tap apply, notifications of AI-matched jobs, and much more.\n\nAll applicants applying for U.S. job openings must be legally authorized to work in the United States. Benefits are available to contract/temporary professionals, including medical, vision, dental, and life and disability insurance. Hired contract/temporary professionals are also eligible to enroll in our company 401(k) plan. Visit roberthalf.gobenefits.net for more information.\n\n© 2025 Robert Half. An Equal Opportunity Employer. M/F/Disability/Veterans. By clicking “Apply Now,” you’re agreeing to Robert Half’s Terms of Use and Privacy Notice .","datePosted":"2026-08-31T09:10:29.144Z","dateModified":"2026-08-31T09:10:29.144Z","hiringOrganization":{"@type":"Organization","name":"Robert Half","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Appleton","addressRegion":"WI","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"69458c3b8b26452e00054c16"},"url":"https://jobsearcher.com/jobs/69458c3b8b26452e00054c16"}}