Skip to content

Information Security Consultant PCI-DSS

eSec Forte TechnologiesGurugram, HR, IndiaSeptember 30, 2026
On-site
Full-time
GRC
Mid · 2–4 yrs

About the Role

As an Information Security Consultant specializing in PCI-DSS, you will be instrumental in guiding clients through the complexities of payment card industry compliance. This role involves conducting technical assessments, validating security controls against PCI DSS v4.0.1 requirements, and providing actionable remediation guidance to secure cardholder data environments (CDE). You will work directly with client teams to review configurations, analyze data flows, and ensure robust security postures.

Key Responsibilities

  • Review and validate client compliance evidence, including system configurations, security policies, system logs, user access reviews, and vulnerability scan reports, against PCI DSS v4.0.1 requirements.
  • Assist in mapping client network topologies and cardholder data flows to accurately define and verify the scope of the Cardholder Data Environment (CDE).
  • Perform initial assessments of cloud security configurations across major platforms such as AWS, Azure, or GCP, focusing on bucket permissions, network security groups (NSGs), and public access restrictions.
  • Examine centralized logging setups, including SIEM configurations, to ensure adherence to log retention policies, accurate time synchronization via NTP, and daily log review procedures as mandated by Requirement 10.
  • Identify and evaluate the deployment of automated security testing or AI-based security controls within client environments, such as automated patch management systems or AI-driven log analysis alerts.
  • Verify that any AI-driven tools integrated into customer workflows do not inadvertently store or mirror payment card data in non-secure databases or log files.
  • Maintain detailed remediation trackers, action logs, and client status dashboards to monitor progress and facilitate timely compliance.
  • Assist in drafting comprehensive assessment workpapers, providing support for Self-Assessment Questionnaires (SAQs), and preparing preliminary gap analysis reports for client review.

Requirements

  • Experience: 2-4 years of experience in information security, IT audit, or compliance consulting, with a focus on PCI DSS.
  • Qualifications: Graduate degree in a relevant technical field.
  • PCI Knowledge: Strong working knowledge of the 12 PCI DSS v4.0.1 control domains and core scoping concepts.
  • Technical Fundamentals: Understanding of basic network security principles (e.g., firewalls, subnets), operating system hardening (Linux/Windows), Identity and Access Management (IAM), and foundational cloud security principles.
  • AI/Tech Familiarity: Awareness of modern cloud-native architectures and an understanding of basic security risks associated with automated and AI-driven tools.
  • Certifications: Possession of or progress towards certifications such as CompTIA Security+, AWS Cloud Practitioner, Azure Fundamentals, ISO 27001 Internal Auditor, or CISA.

Nice-to-Have

  • Familiarity with vulnerability management platforms like Tenable (Nessus) or risk lifecycle management tools such as NxSAM.
  • Exposure to other GRC frameworks, including ISO 27001 or SOC 2.
  • Experience with security infrastructure from vendors like Palo Alto Networks, CrowdStrike, or Zscaler.
  • Ability to script or automate routine auditing tasks to enhance efficiency.

Benefits

  • Health insurance for the employee and dependents
  • Professional security-certification reimbursement (e.g., CISA, ISO 27001 Lead Auditor, CCSP)
  • Annual learning and skill-development allowance
  • Sponsored conference / training attendance
  • Flexible work arrangements

Qualification

Graduate

Job Details

Experience

Mid · 2–4 yrs

Tools & Tech

AWS
Azure
CrowdStrike
GCP
Linux
Nessus
Palo Alto
Tenable
Windows
Zscaler

Preferred Certs

CCSP
CISA
Security+