roles & responsibilities:
• identifying, collecting, organizing, and reviewing pertinent evidence across multiple platforms and
applications to determine compliance with relevant pci dss controls.
• validating the scope of the cardholder data environment (cde) as determined by the assessed organization.
• conducting an on-site assessment, examining the cde which is in scope.
• assessing with a sampling approach (as approved by the pci dss audit standard) and selecting employees,
facilities, systems, and system components accurately representing the assessed environment and which is
in scope.
• evaluate all the compensating controls as applicable.
• providing an opinion on whether or the assessed organization is compliant and meets pci dss
requirements.
• draft and generate a roc effectively based on the assessment findings.
based on the assessment and validation of the findings, provide an aoc to the assessed organization’s pci
dss compliance status.
• maintaining documents, paper works, and recordings of interviews that were collected during the pci dss
assessment as evidence and using it to validate the findings.
• applying and maintaining independent judgment in all pci dss assessment decisions.
• conducting follow-up assessments as and when needed.
• pci ssc periodically performs qa reviews on a qsa’s roc to ensure that the documentation of testing
procedures performed is sufficient to support the results of the pci dss assessment.
required skills:
• minimum three years experience as a qualified security assessor actively performing pci assessments
and/or remediation engagements.
• demonstrated ability to work independently as well as in a team to meet delivery obligations.
• demonstrated effective communication skills both written and verbal.
• effective presentation skills.
• ability to travel.