Skip to content

Open nowPosted 17 days ago

Security Operations Engineer - PCI DSS

Workable (global search)108,016 open roles

Where
Philippines
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Operations Engineer - PCI DSSWorkable (global search) · Philippines
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 17 days ago

Workable (global search) median: 7 days open

The posting

About the client

Our client is an innovative payments technology company transforming the way businesses send, receive, pay, and reconcile invoices. With a strong focus on simplifying complex payment processes, they provide a seamless billing and payments ecosystem designed to give businesses and their customers greater flexibility, visibility, and control over cash flow.

By integrating with existing accounting platforms and payment workflows, our client helps reduce manual administration, streamline reconciliation, improve payment experiences, and create more efficient and secure financial processes. They are committed to innovation and delivering technology solutions that make payments simpler, faster, and more customer-focused.

As the business continues to grow, they are seeking talented professionals who are passionate about technology, payments, and delivering exceptional customer experiences to join their team.

About Teamified

Teamified is a talent partner helping companies build exceptional remote teams across IT, software, product, and digital innovation. We collaborate with leading enterprises and fast-scaling tech businesses worldwide to help them access world class talent and accelerate growth. With operations across the globe our mission is to make building high performing global teams simple, fast, and cost-effective. Teamified has hundreds of clients with more than 200 engineers, testers, product managers, designers, and technology experts delivering impactful solutions every day.

Job Summary:

Our client operates a cloud-hosted payment platform and validates against PCI DSS v4.0.1 as a Level 2 service provider via SAQ D for Service Providers. They are seeking an experienced security engineer on a three-month contract to run the annual compliance cycle to completion.

This is a hands-on engineering role combined with programme ownership. The successful candidate will implement technical control changes, assemble and quality-check the evidence set, complete the self-assessment questionnaire, and prepare the Attestation of Compliance for executive sign-off. They will work alongside the client's existing engineering and operations teams.

The evidence and documentation produced should be built to a standard suitable for external assessment, as the client anticipates moving to QSA-led Level 1 validation in a future cycle.

Responsibilities:

  • Implement and verify technical controls across the cardholder data environment: access management, secure configuration, logging and monitoring, vulnerability management, encryption and key management, and secure development practices.
  • Deliver the logging and monitoring requirements to the standard v4.0.1 expects: centralised collection of audit logs from all in-scope system components, protection of logs against alteration, twelve-month retention with three months immediately available, automated mechanisms for log review rather than manual inspection, time synchronisation, change detection on critical files, and alerting on the failure of critical security control systems.
  • Work alongside the client's DevOps engineer on the rollout of an open-source SIEM and host intrusion detection platform (Wazuh). The DevOps engineer owns the infrastructure build; this role owns the compliance outcome — defining required log sources and coverage, developing and tuning detection and correlation rules, configuring file integrity monitoring and retention to meet the standard, validating that the deployment actually satisfies the requirements, and evidencing it.
  • Define the alert triage and response routine the client team will operate day to day.
  • Complete SAQ D for Service Providers and assemble the supporting evidence set.
  • Maintain compliance documentation: network and cardholder dataflow diagrams, scoping and segmentation documentation, policies and operating procedures.
  • Engage and manage an Approved Scanning Vendor for quarterly external vulnerability scanning; drive remediation to passing scans.
  • Scope and co-ordinate penetration testing with a qualified independent provider; manage remediation and retest.
  • Maintain third-party service provider due diligence, including partner AOC collection and shared responsibility documentation.
  • Own the delivery plan: schedule, dependencies, risk log, and weekly reporting to leadership.
  • Strengthen change management practice so that changes are raised, approved, tested and evidenced consistently.
  • Document repeatable operational routines (log review, access review, scan cadence, change approval) for the client team to run after the engagement ends.

Requirements:

Essential experience

  • Demonstrable experience taking an organisation through PCI DSS compliance, ideally more than once and ideally including v4.x.
  • Working knowledge of PCI DSS v4.0.1, including the changes from v3.2.1 and the requirements mandatory from 31 March 2025.
  • Direct experience completing SAQ D, or preparing evidence for a Report on Compliance.
  • Hands-on AWS security engineering: IAM policy design, VPC and network segmentation, audit logging, secrets and key management, and infrastructure-as-code. Equivalent depth in another major public cloud will be considered where the candidate can demonstrate transferable design judgement.
  • Hands-on experience with SIEM or centralised log platforms in a compliance context — log source onboarding, parsing and normalisation, correlation and alert rule development, file integrity monitoring, retention configuration, and tuning to reduce false positives. Direct Wazuh experience is a strong advantage; equivalent open-source stacks (OSSEC, Elastic Security, Graylog, Security Onion) are acceptable. Candidates should be able to name the platforms they have worked with and describe what they configured, not only what they monitored.
  • Practical experience in vulnerability management, logging and monitoring, access management and secure configuration baselines.
  • Ability to independently plan, track, report and escalate. No project manager will be assigned.
  • Excellent written English. A significant portion of this role is documentation and evidence that must be read and accepted by others.
  • Willingness to record a control as not in place where that is the accurate position.

Desirable

  • Payments, fintech or regulated financial services background.
  • Understanding of the acquirer, processor and card scheme landscape.
  • Experience of Level 1 service provider validation, or of taking an organisation from self-assessment to QSA-led assessment.
  • PCIP, ISA, CISSP, CISM or equivalent certification.
  • Jira administration and workflow configuration.
  • Familiarity with ISO 27001 or SOC 2.

Benefits:

  • Flexibility in work hours and location, with a focus on managing energy rather than time.
  • Access to online learning platforms and a budget for professional development
  • A collaborative, no-silos environment, encouraging learning and growth across teams
  • A dynamic social culture with team lunches, social events, and opportunities for creative input
  • Leave Benefits

If you possess the required skills and are eager to contribute to our team's success, we encourage you to apply for this exciting opportunity. Apply now!

#GrowWithTeamified #TeamifyYourCareer

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.