ascio
Back to all opportunities

PCI DSS Compliance Specialist (Contract)

$85.00/hr
Category
IT & Technology
Requisition #
P05
Schedule
Contract
Location Type
Remote
Posted
Sep 22, 2026
Applications close
Nov 22, 2026
Sign in to apply
New here? Create a free account in under a minute.

ascio is hiring a PCI DSS Compliance Specialist to support our payment security and compliance work across a range of organizations and payment environments.

This role will help organizations understand and reduce their cardholder data environment, assess compliance with PCI DSS v4.0.1, complete applicable self-assessment requirements and prepare for formal assessment where required. QSA status is not required.

Responsibilities

  1. Inventory payment channels, merchant accounts and service providers and develop cardholder data flow diagrams.
  2. Determine and reduce cardholder data environment scope through approaches including segmentation, tokenization, point-to-point encryption and outsourcing.
  3. Interpret PCI DSS v4.0.1 requirements and conduct gap assessments with practical remediation plans.
  4. Determine the appropriate Self-Assessment Questionnaire and support completion of the applicable SAQ and Attestation of Compliance.
  5. Prepare assessment evidence and support coordination with Qualified Security Assessors where a Report on Compliance is required.
  6. Review remediation activity and support readiness for reassessment.
  7. Provide guidance and training on ongoing PCI DSS responsibilities and compliance requirements.

Required Skills and Experience

  1. Five or more years of experience working with PCI DSS in an assessment, compliance, advisory or implementation role.
  2. Detailed working knowledge of PCI DSS v4.0.1 requirements and appendices.
  3. Strong experience determining and reducing cardholder data environment scope, including network segmentation.
  4. Experience determining and working with applicable Self-Assessment Questionnaires, including SAQ A, A-EP, B, B-IP, C, C-VT, D and P2PE.
  5. Experience conducting PCI DSS gap assessments and developing remediation plans.
  6. Experience preparing evidence for a Report on Compliance or comparable formal assessment.
  7. Strong knowledge of payment technologies including tokenization, point-to-point encryption, hosted payment pages, payment terminals and third-party payment services.
  8. Understanding of PCI DSS vulnerability scanning and penetration testing requirements, including working with Approved Scanning Vendors.
  9. Strong written and verbal communication skills, with the ability to explain compliance requirements to both technical and non-technical audiences.

Qualifications

  1. One or more relevant current professional certifications or credentials such as PCIP, ISA, QSA or former QSA status, or CISA or CISSP combined with demonstrable PCI DSS assessment experience.
  2. Applicants must be able to provide certification or credential status and expiry dates, where applicable.
  3. Degree or diploma in information systems, accounting, cybersecurity or a related field, or equivalent professional experience.
  4. PCI Security Standards Council training is considered an asset.

Preferred Experience

  1. Multi-merchant environments with numerous payment channels.
  2. Point-of-sale and payment terminal security.
  3. Cloud-hosted payment environments.
  4. Integration of PCI DSS controls with ISO/IEC 27001 or other information security management frameworks.
  5. Experience working with third-party payment processors and service providers.

Location and Work Arrangement

  1. Remote within Canada.
  2. Some assignments may require occasional onsite work or travel within Canada.
  3. Applicants must be based in Canada and legally entitled to work in Canada.
  4. A criminal record check may be required before access to sensitive systems, information or environments.