Ernst & Young - New York, NY

posted 18 days ago

Full-time - Mid Level
New York, NY
Professional, Scientific, and Technical Services

About the position

As a Senior Consultant specializing in PCI Security within EY's Cybersecurity practice, you will lead the implementation of security solutions for clients, focusing on data protection and privacy. This role involves navigating complex cybersecurity frameworks and ensuring compliance with various regulations, while working collaboratively with an international team of specialists to enhance clients' business resilience against cyber threats.

Responsibilities

  • Lead the delivery of multiple processes, solutions, or projects in the realm of data protection and privacy.
  • Plan and execute PCI assessment engagements for clients, focusing on payment card compliance and security (PCI-DSS).
  • Coordinate & report on project deliverables and track project status with clients' management and key stakeholders.
  • Validate PCI requirements testing results and collaborate with clients to remediate compliance gaps.
  • Engage in client working sessions and serve as a team lead or workstream member as required.
  • Support sales opportunities by contributing to service proposals and RFP responses.

Requirements

  • A Bachelor's degree in a relevant field such as Computer Science, Information Systems, Engineering, Business, or related major.
  • 2 to 4 years of experience conducting and leading PCI assessment and audits with a strong understanding of PCI DSS.
  • Experience executing PCI DSS Reports of Compliance and Self-Assessment Questionnaires, along with remediation activities to achieve compliance.
  • Strong understanding of various compliance frameworks, including ISO, NIST, SOX, HIPAA, and GDPR.
  • Ability to interpret and apply regulatory requirements to client environments.

Nice-to-haves

  • Relevant cybersecurity certifications such as CISSP, CISM, CISA, and CEH, with PCI QSA certification highly preferred.
  • Proficiency in security controls and best practices for information security.
  • Familiarity with security technologies and tools (e.g., firewalls, intrusion detection/prevention systems, encryption, vulnerability scanners).
  • Proficiency in using GRC (Governance, Risk, and Compliance) tools.
  • Knowledge of cloud security and emerging technologies.
  • Familiarity with automation tools and scripting languages (e.g., Python, PowerShell) for security tasks.

Benefits

  • Comprehensive compensation and benefits package based on performance.
  • Medical and dental coverage.
  • Pension and 401(k) plans.
  • Wide range of paid time off options including flexible vacation policy and designated EY Paid Holidays.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service