Senior Security Consultant PCI QSA

4 days ago


Cochin, Kerala, India ValueMentor Full time ₹ 15,00,000 - ₹ 20,00,000 per year

Job Summary

This role will be responsible for supporting the organization's security initiatives, ensuring compliance with industry standards, and maintaining a secure, risk-aware environment. The role will work closely with clients, understand their security and compliance requirements, plan engagements, and ensure high-quality delivery of services. The role will work closely with cross-functional teams to ensure successful delivery of client projects. The role demands technical expertise, deep regulatory knowledge, client management capabilities. Focus will be on delivering value through risk framework development, vendor risk assessments, compliance training, and tailored client advisory.

Key Responsibilities, Deliverables / Outcomes

  1. Practice Delivery

  2. Conduct PCI DSS assessments for clients in line with PCI Security Standards Council guidelines.

  3. Provide consulting to implement and manage Information Security Management Systems (ISMS).

  4. Provide consulting to implement and maintenance of ISO 27001:2022 and/or NIST CSF standards within the organization.

  5. Perform Gap Assessment and threat modeling. Conduct risk assessment and create the Risk Treatment Plans (RTPs).

  6. Conduct in-depth analysis of complex security issues, identifying root causes and developing practical, data-driven solutions.

  7. Define and assess the Client's risk appetite and tolerance levels and develop and monitor Key Risk Indicators (KRIs) for Clients.

  8. Provide expert guidance to clients on remediation plans and achieving/maintaining compliance.

  9. Develop and document information security policies, processes, standards, and procedures in collaboration with other stakeholders.

  10. Identify and interpret legal, regulatory, and statutory information security compliance requirements relevant to Client operations.

  11. Conduct internal audits, assess security controls, and manage remediation plans.

  12. Deliver tailored, value-driven solutions while managing expectations, timelines, and budgets effectively.

  13. Conduct final PCI QSA audits and Develop Reports on Compliance (ROC) and Attestation of Compliance (AOC).

  14. Act as the liaison for external compliance assessments and audits, ensuring thorough preparation, evidence gathering, and successful audit outcomes.

  15. Client Engagement

  16. Ensure a Client-centric approach by actively managing expectations, delivering value, and exceeding stakeholder requirements.

  17. Communicate risk assessments and mitigation plans to senior management within Client organizations.

  18. Deliver presentations and briefings to senior management and stakeholders, communicating complex security concepts in an understandable manner.

  19. Ensure effective communication of these policies and procedures across the Client's organization and ensure these policies are integrated into business operations.

  20. Engage in Client Meetings & Interactions to identity new prospects, relationship building & gathering market intelligence and feedback on services provided.

  21. Learning & Initiatives

  22. Independently manage information security projects, ensuring adherence to deadlines and delivery goals.

  23. Take ownership of tasks and consistently meet deadlines, demonstrating accountability in managing security initiatives.

  24. Efficiently allocate and manage project resources and ensure timely and concise Project status updates to all stakeholders.

  25. Work as part of a collaborative team, fostering a culture of cooperation, open communication, and shared success.

  26. Stay up-to-date with PCI SSC updates, security threats, and regulatory changes.

  27. Deliver training and awareness sessions on compliance and security best practices.

  28. Maintain all QSA certification requirements as per PCI SSC guidelines.

  29. Identify and implement means to reduce and streamline efforts using technology.

  30. Operations Management

  31. Track performance using Balanced Scorecard that tracks key metrics like client satisfaction (e.g., NPS), delivery timelines, and learning & growth.

  32. Timely adherence to PMS initiatives like Timesheet, Bi-Weekly reviews etc

Key Skills

  • PCI QSA

  • In-depth knowledge of ISO 27001 standard

  • Extensive knowledge on application of data classification framework/concepts, Identity and Access Management Concepts, Secure Software Development Lifecycle concepts, network defense.

  • Working knowledge about cloud security concepts and cloud platforms

  • Working Understanding of OSI communication layers and network communication protocols

Key Competencies

  • Analysis Skills

  • Customer Focus

  • Communications- Oral & written

  • Adaptability to Change

  • Problem Solving Skills



  • Cochin, Kerala, India Soffit Infrastructure Services (P) Ltd Full time US$ 90,000 - US$ 1,20,000 per year

    The Information Security Consultant will be responsible for the implementation, assessment, and management of ISO 27001:2022, ISO 27002, and SOC 2 standards for clients. This role involves working independently or alongside senior consultants to help clients achieve and maintain information security compliance and other best practices. The consultant will...


  • Cochin, Kerala, India Soffit Infrastructure Services (P) Ltd Full time

    The Information Security Consultant will be responsible for the implementation, assessment, and management of ISO 27001:2022, ISO 27002, and SOC 2 standards for clients. This role involves working independently or alongside senior consultants to help clients achieve and maintain information security compliance and other best practices. The consultant will...


  • Cochin, Kerala, India Soffit Infrastructure Services (P) Ltd Full time

    The Information Security Consultant will be responsible for the implementation, assessment, and management of ISO 27001:2022, ISO 27002, and SOC 2 standards for clients. This role involves working independently or alongside senior consultants to help clients achieve and maintain information security compliance and other best practices. The consultant will...


  • Cochin, Kerala, India Soffit Infrastructure Services (P) Ltd Full time

    The Information Security Consultant will be responsible for the implementation, assessment, and management of ISO 27001:2022, ISO 27002, and SOC 2 standards for clients. This role involves working independently or alongside senior consultants to help clients achieve and maintain information security compliance and other best practices. The consultant will...


  • Cochin, Kerala, India Soffit Infrastructure Services (P) Ltd Full time

    The Information Security Consultant will be responsible for the implementation, assessment, and management of ISO 27001:2022, ISO 27002, and SOC 2 standards for clients. This role involves working independently or alongside senior consultants to help clients achieve and maintain information security compliance and other best practices. The consultant will...


  • Cochin, Kerala, India beBeeCyberSecurity Full time ₹ 8,00,000 - ₹ 15,00,000

    Job DescriptionWe are seeking a skilled Cyber Security Consultant to join our team. As a Cyber Security Consultant, you will play a pivotal role in implementing, assessing, and managing various security standards for clients.Our ideal candidate is a highly motivated and detail-oriented individual who has excellent communication skills and the ability to work...


  • Cochin, Kerala, India beBeeSecurity Full time ₹ 18,72,000 - ₹ 25,12,000

    Job SummaryWe are seeking a skilled security professional to drive strategic initiatives and provide advisory services.Lead GRC engagements including assessments, frameworks, and implementation.Develop and maintain security strategies roadmaps and policies aligned with industry standards and client objectives.Key Responsibilities:Conduct risk assessments,...


  • Cochin, Kerala, India beBeeSeniorSecurity Full time ₹ 1,50,00,000 - ₹ 2,00,00,000

    Seeking a high-caliber Senior Security Professional to spearhead our offensive security efforts across various domains.Key responsibilities:Conduct in-depth vulnerability assessments and penetration testing on web applications, networks, cloud environments, and operational technology (OT).Execute internal infrastructure and Active Directory exploitation...


  • Cochin, Kerala, India beBeeApplication Full time ₹ 1,50,00,000 - ₹ 2,50,00,000

    Job Overview:We are seeking a seasoned Security Expert to lead security testing, vulnerability management, and threat mitigation efforts across various systems, mobile platforms, APIs, and cloud environments. This role involves securing these systems while ensuring compliance with industry standards and regulations.As a senior-level expert in application...


  • Cochin, Kerala, India beBeeCyberSecurity Full time ₹ 1,50,00,000 - ₹ 2,50,00,000

    Job Title: Cyber Security ISMS Audit Associate / ConsultantMumbai (Work From Office) Location is flexible, ideal for remote work. We are seeking a cyber security professional with strong expertise in ISMS audits and cyber security assessments.Conduct ISMS audits in line with ISO 27001 standards to ensure compliance and identify areas for improvement.Perform...