InfoSec PCI Compliance Lead
Job Description
DISH is a Fortune 200 company that continues to redefine the communications industry.
Our legacy is innovation and a willingness to challenge the status quo, including
reinventing ourselves. We disrupted the pay-TV industry in the mid-90s with the launch
of the DISH satellite TV service, taking on some of the largest U.S. corporations in the
process, and grew to be the fourth-largest pay-TV provider. We are doing it again with
the first live, internet-delivered TV service - Sling TV - that bucks traditional pay-TV
norms and gives consumers a truly new way to access and watch television.
Now we have our sights set on upending the wireless industry and unseating the
entrenched incumbent carriers.
We are driven by curiosity, pride, adventure, and a desire to win - it's in our DNA. We're
looking for people with boundless energy, intelligence, and an overwhelming need to
achieve to join our team as we embark on the next chapter of our story.
Opportunity is here. We are DISH.
Job Duties and Responsibilities
Job Duties and Responsibilities
Primary responsibilities of the Information Security PCI Compliance Program Manager include the following:
- Draft policies/procedures that govern the security of DISH PCI data across the enterprise with a specific focus on compliance requirements.
- Design, lead and execute a Compliance program focused on PCI data handling across the enterprise.
- Partner with security teams to identify and analyze security requirements to align with PCI compliance standards.
- Track, document and address PCI compliance gaps to ensure timely closure.
- Manage the annual PCI audit including evidence gathering, quality assurance of evidence, coordination of audit resource meetings, and other tasks required to successfully complete the audit.
- Ensure ASV Scans and Pentesting are conducted quarterly and annually, respectively with all remediation activities being completed within expected timelines.
- Lead security enhancement projects focused on new or changing PCI compliance requirements.
- Educate and build awareness of PCI compliance requirements.
- Coordinate with Third Party Risk management to ensure PCI compliance needs are being addressed and tracked appropriately with third party vendors.
- Coordinate with Privacy / Legal to ensure the overall compliance landscape is well understood and the program captures a complete view of our PCI compliance needs.
- Continuously improve the PCI compliance program with new information, procedures, or documentation.
- Coach and mentor junior staff.
- Other responsibilities as assigned.
The successful candidate will possess the following qualifications:
Successful candidate must be willing to relocate & work onsite.
Competencies:
- Project Management
- Self-led Learner
- Customer First Mentality
- Strong Adaptability
- Process Documentation Management
- Process Mapping Development
- Presentation Skills
- Multitasking
- Compliance + Risk Mindset
- Communication w Executives
- Team Mentorship
- Can Interpret Regulations and Compliance Requirements
- Thought Leadership
- Cross-functional Team Leadership
- Strategic Thinking and Planning (Team)
- Brand & Team Ambassador
- Solid Risk Management Foundation
- Solid Information Security Foundation
- Solid Security Control Framework Foundation
- Expert PCI-DSS Knowledge
- General Data Privacy Foundation
- Can Teach/Educate Risk & InfoSec Principles
- Can Consult Business on Risk and InfoSec Principles
Personality:
- Requires a well-organized, cheerful and persuasive individual, who can manage multiple priorities at once.
- Must have good meeting management and communication skills to keep conversations focused and productive.
- Must be self-driven; able to manage schedules, meet deadlines, coordinate with others, and perform tasks with minimal supervision.
- Must have the ability to work with a diverse audience, under tight deadlines, and negotiate successful outcomes to challenging problems.
Skills, Experience and Requirements
Skills, Experience and Requirements
Education and Experience:
- Bachelor's Degree or equivalent experience and 4-6 years of directly related experience.
- Must have a solid understanding of SOX, PCI, CPNI, CCPA, FACTA and similar IT Compliance and Privacy regulations.
- Experience with compliance audits such as PCI and/or CPNI. Former QSA preferred.
- Experience with NIST, ISO and other industry standards.
- Expert user of Microsoft/Google Suite and an eGRC tool.
Other Qualifications:
- Professional certification (CISSP, CISA, CSIM, CIA or similar) is highly desired.
#LI-CS5
Salary Range
Compensation: $115,500.00/Year - $165,000.00/Year
Compensation and Benefits
We also offer versatile health perks, including flexible spending accounts, HSA, a 401(k) Plan with company match, ESPP, career opportunities, and a flexible time away plan; all benefits can be viewed here: DISH Benefits .
The base pay range shown is a guideline. Individual total compensation will vary based on factors such as qualifications, skill level, and competencies; compensation is based on the role's location and is subject to change based on work location. Candidates need to successfully complete a pre-employment screen, which may include a drug test and DMV check.
Date Posted
10/25/2023
Views
6
Similar Jobs
Compliance Researcher - Accurate Background
Views in the last 30 days - 0
Accurate Background is seeking a Compliance Researcher to join their team The role involves maintaining the Global Services Register conducting compli...
View DetailsSystems Engineer - Mission Operations Lead - York Space Systems
Views in the last 30 days - 0
York Space Systems is seeking a Systems Engineer Mission Operations Lead The role involves acting as the mission operations focal point leading the de...
View DetailsSenior Lead, Partner Marketing - SMB Demand Generation - Klaviyo
Views in the last 30 days - 0
Klaviyo is seeking a Sr Partner Marketing Manager for SMB Demand Generation The role involves driving direct engagement with SMB partners creating imp...
View DetailsSenior Electrical Engineer - Red 6
Views in the last 30 days - 0
Red 6 is a pioneering AR technology startup specializing in synthetic air combat training The company is seeking a Senior Electrical Engineer to contr...
View DetailsColorado JCC Salesforce Administrator - OpenTent
Views in the last 30 days - 0
OpenTent a dedicated team of data specialists is seeking a Salesforce Administrator to support the Boulder and Denver Jewish Community Centers The rol...
View DetailsImplementation Consultant I-1 - Vertafore
Views in the last 30 days - 0
Vertafore a leading technology company in the insurance industry is seeking dynamic and passionate individuals to join their Professional Services Org...
View Details