Coupa Software
Spend is the fuel to help your company deliver performance, profitability, and purpose!
Payment Security & Compliance Program Manager
Security EngineerSecurity EngineerFull TimeRemoteTeam 1,001-5,000Since 2006H1B SponsorCompany SiteLinkedIn
Location
United States
Posted
112 days ago
Salary
$83K - $108K / year
Bachelor Degree5 yrs expEnglishAWSAzureCloudService NowSwift
Job Description
• Own and manage end-to-end PCI DSS and SWIFT CSCF programs, including scope maintenance, control applicability, compensating controls, authoritative documentation, and annual assessment readiness.
• Operate continuous compliance and evidence management, maintaining a validated, audit-ready evidence library in our GRC Platform with structured refresh cadences for all PCI/SWIFT controls.
• Provide scoping, segmentation, and architecture governance by partnering with Engineering and Cloud Ops to review CDE boundaries, trust zones, architectural changes, and enforce required technical controls.
• Monitor and validate technical security controls across IAM, encryption, segmentation, logging/monitoring, vulnerability management, and incident response; maintain control monitoring logs and drive hardening improvements.
• Lead internal-facing audit support and remediation governance, partnering with QSA/CSCF assessors, preparing audit populations, managing walkthroughs, and driving remediation tracking, prioritization, and validated closure.
• Maintain system-of-record documentation and emerging standards readiness, ensuring PCI/SWIFT artifacts meet regulatory expectations while monitoring framework updates, leading impact analyses, and planning for new requirements.
Job Requirements
- 5–8+ years of experience in security compliance, cloud security, technical audit, or payment security programs.
- Deep expertise in PCI DSS (ideally PCI DSS v4.0) with hands-on experience supporting or preparing for QSA-led assessments; SWIFT CSCF or other high-security financial frameworks strongly preferred.
- Strong technical understanding of cloud platforms (AWS/Azure), IAM, encryption, logging/monitoring, network segmentation, and CI/CD pipelines.
- Proven success collaborating with engineering, cloud operations, SRE, and security engineering teams on control implementation and validation.
- Excellent documentation, governance, and process discipline, with the ability to drive multi-team remediation and maintain ongoing compliance rigor.
- Experience with GRC platforms such as TrustCloud, Archer, ServiceNow, or comparable tooling.
Benefits
- Health insurance
- 401(k) matching
- Flexible work hours
- Paid time off
- Professional development opportunities
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Security Engineer112 days ago
Full TimeRemoteTeam 501-1,000Since 1998H1B Sponsor
Incident Responder monitoring security attacks across Mozilla’s products and services
AWSAzureBigQueryCloudGoogle Cloud PlatformHerokuSplunk
United States
Security Engineer113 days ago
Full TimeRemoteTeam 201-500H1B No Sponsor
Red Team Specialist focused on Generative AI Models conducting security assessments
Cyber SecurityNode.jsPython
United States
Security and Compliance Internship
OpenSesameWe help companies develop the world's most productive and admired workforces.
Security Engineer115 days ago
InternshipRemoteTeam 51-200Since 2011H1B No Sponsor
Internship role in Security & Compliance team at OpenSesame
Security and Compliance Manager
OpalaConnecting data flow across healthcare so that every patient's experience is optimized.
Security Engineer115 days ago
Full TimeRemoteTeam 11-50H1B Sponsor
Security & Compliance Manager leading compliance and risk management for healthcare data startup
Cloud