Coupa Software

Spend is the fuel to help your company deliver performance, profitability, and purpose!

Payment Security & Compliance Program Manager

Security EngineerSecurity EngineerFull TimeRemoteTeam 1,001-5,000Since 2006H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

112 days ago

Salary

$83K - $108K / year

Bachelor Degree5 yrs expEnglishAWSAzureCloudService NowSwift

Job Description

• Own and manage end-to-end PCI DSS and SWIFT CSCF programs, including scope maintenance, control applicability, compensating controls, authoritative documentation, and annual assessment readiness. • Operate continuous compliance and evidence management, maintaining a validated, audit-ready evidence library in our GRC Platform with structured refresh cadences for all PCI/SWIFT controls. • Provide scoping, segmentation, and architecture governance by partnering with Engineering and Cloud Ops to review CDE boundaries, trust zones, architectural changes, and enforce required technical controls. • Monitor and validate technical security controls across IAM, encryption, segmentation, logging/monitoring, vulnerability management, and incident response; maintain control monitoring logs and drive hardening improvements. • Lead internal-facing audit support and remediation governance, partnering with QSA/CSCF assessors, preparing audit populations, managing walkthroughs, and driving remediation tracking, prioritization, and validated closure. • Maintain system-of-record documentation and emerging standards readiness, ensuring PCI/SWIFT artifacts meet regulatory expectations while monitoring framework updates, leading impact analyses, and planning for new requirements.

Job Requirements

  • 5–8+ years of experience in security compliance, cloud security, technical audit, or payment security programs.
  • Deep expertise in PCI DSS (ideally PCI DSS v4.0) with hands-on experience supporting or preparing for QSA-led assessments; SWIFT CSCF or other high-security financial frameworks strongly preferred.
  • Strong technical understanding of cloud platforms (AWS/Azure), IAM, encryption, logging/monitoring, network segmentation, and CI/CD pipelines.
  • Proven success collaborating with engineering, cloud operations, SRE, and security engineering teams on control implementation and validation.
  • Excellent documentation, governance, and process discipline, with the ability to drive multi-team remediation and maintain ongoing compliance rigor.
  • Experience with GRC platforms such as TrustCloud, Archer, ServiceNow, or comparable tooling.

Benefits

  • Health insurance
  • 401(k) matching
  • Flexible work hours
  • Paid time off
  • Professional development opportunities

Related Categories

Related Job Pages

More Security Engineer Jobs

Security Engineer112 days ago
Full TimeRemoteTeam 501-1,000Since 1998H1B Sponsor

Incident Responder monitoring security attacks across Mozilla’s products and services

AWSAzureBigQueryCloudGoogle Cloud PlatformHerokuSplunk
United States

Freelancer – Security Red Teaming Specialist

ActiveFence

Protect your users. Protect your platform.

Security Engineer113 days ago
Full TimeRemoteTeam 201-500H1B No Sponsor

Red Team Specialist focused on Generative AI Models conducting security assessments

Cyber SecurityNode.jsPython
United States

Security and Compliance Internship

OpenSesame

We help companies develop the world's most productive and admired workforces.

Security Engineer115 days ago
InternshipRemoteTeam 51-200Since 2011H1B No Sponsor

Internship role in Security & Compliance team at OpenSesame

United States
$18 / hour

Security and Compliance Manager

Opala

Connecting data flow across healthcare so that every patient's experience is optimized.

Security Engineer115 days ago
Full TimeRemoteTeam 11-50H1B Sponsor

Security & Compliance Manager leading compliance and risk management for healthcare data startup

Cloud
United States
$124K - $145K / year