Skip to main content
Zobhira
Home
Jobs
Certifications
Zobhira
JobsCertificationsTodayAbout
Log inSign up
Zobhira

New job and contest openings, updated every morning on one searchable board.

Find work

  • All jobs
  • Fresher roles
  • Remote roles
  • Certifications

Compete

  • Added today

Popular cities

  • India
  • Bangalore, Karnataka, India
  • Hyderabad, Telangana, India
  • Pune, Maharashtra, India
  • Chennai, Tamil Nadu, India
  • Mumbai, Maharashtra, India

Company

  • About
  • Contact
  • Privacy
  • Terms

Stay updated

One email a week with new roles.

Secure infrastructure
Free to use, no account needed to search

Board updated daily · © 2026 Zobhira. All rights reserved.

Privacy PolicyTerms of Service
Home / Jobs / Teamified

Security Operations Engineer - PCI DSS

Teamified

IndiaremotePosted 16 days ago
Teamified logo

Skill Required

PCIDSS-ComplianceSecurity-Operations-EngineeringInfosecCompliance-EngineeringSecurity-EngineeringSecurity-Operations-EngineerCybersecurity-Operations-EngineerSenior-Security-Operations-EngineerSenior-PCI-Compliance-ConsultantSecurity-Operations-(SOC)-AnalystSecurity-Operations-AnalystInformation-Systems-Security-EngineerSecurity EngineersecurityISO 27001Penetration TestingEngineeringObservabilityCryptographybuildingTestNGdesignDevOpsCloudSIEMAWSIAMandContract

Key highlights

  • Contract: Three-month contract
  • Required experience: Demonstrated experience taking an organisation through PCI DSS compliance, ideally more than once
  • Key benefit: Flexibility in work hours and location, with a focus on managing energy rather than time
  • Key requirement: Excellent written English — significant portion is documentation and evidence that must be read and accepted by others
  • Notable requirement: Willingness to record a control as not in place where that is the accurate position
  • Platform: Cloud-hosted payment platform validating against PCI DSS v4.0.1

Role overview

Our client is an innovative payments technology company transforming the way businesses send, receive, pay, and reconcile invoices. With a strong focus on simplifying complex payment processes, they provide a seamless billing and payments ecosystem designed to give businesses and their customers greater flexibility, visibility, and control over cash flow. By integrating with existing accounting platforms and payment workflows, they help reduce manual administration, streamline reconciliation, improve payment experiences, and create more efficient and secure financial processes. As the business continues to grow, they are seeking an experienced security engineer on a three-month contract to run the annual PCI DSS compliance cycle to completion. This is a hands-on engineering role combined with programme ownership, working alongside the client's existing engineering and operations teams.

Responsibilities

  • Implement and verify technical controls across the cardholder data environment: access management, secure configuration, logging and monitoring, vulnerability management, encryption and key management, and secure development practices.
  • Deliver the logging and monitoring requirements to the standard v4.0.1 expects: centralised collection of audit logs from all in-scope system components, protection of logs against alteration, twelve-month retention with three months immediately available, automated mechanisms for log review rather than manual inspection, time synchronisation, change detection on critical files, and alerting on the failure of critical security control systems.
  • Work alongside the client's DevOps engineer on the rollout of an open-source SIEM and host intrusion detection platform (Wazuh). The DevOps engineer owns the infrastructure build; this role owns the compliance outcome — defining required log sources and coverage, developing and tuning detection and correlation rules, configuring file integrity monitoring and retention to meet the standard, validating that the deployment actually satisfies the requirements, and evidencing it.
  • Define the alert triage and response routine the client team will operate day to day.
  • Complete SAQ D for Service Providers and assemble the supporting evidence set.
  • Maintain compliance documentation: network and cardholder dataflow diagrams, scoping and segmentation documentation, policies and operating procedures.
  • Engage and manage an Approved Scanning Vendor for quarterly external vulnerability scanning; drive remediation to passing scans.
  • Scope and co-ordinate penetration testing with a qualified independent provider; manage remediation and retest.
  • Maintain third-party service provider due diligence, including partner AOC collection and shared responsibility documentation.
  • Own the delivery plan: schedule, dependencies, risk log, and weekly reporting to leadership.
  • Strengthen change management practice so that changes are raised, approved, tested and evidenced consistently.
  • Document repeatable operational routines (log review, access review, scan cadence, change approval) for the client team to run after the engagement ends.

Requirements

  • Demonstrable experience taking an organisation through PCI DSS compliance, ideally more than once and ideally including v4.x.
  • Working knowledge of PCI DSS v4.0.1, including the changes from v3.2.1 and the requirements mandatory from 31 March 2025.
  • Direct experience completing SAQ D, or preparing evidence for a Report on Compliance.
  • Hands-on AWS security engineering: IAM policy design, VPC and network segmentation, audit logging, secrets and key management, and infrastructure-as-code. Equivalent depth in another major public cloud will be considered where the candidate can demonstrate transferable design judgement.
  • Hands-on experience with SIEM or centralised log platforms in a compliance context — log source onboarding, parsing and normalisation, correlation and alert rule development, file integrity monitoring, retention configuration, and tuning to reduce false positives. Direct Wazuh experience is a strong advantage; equivalent open-source stacks (OSSEC, Elastic Security, Graylog, Security Onion) are acceptable. Candidates should be able to name the platforms they have worked with and describe what they configured, not only what they monitored.
  • Practical experience in vulnerability management, logging and monitoring, access management and secure configuration baselines.
  • Ability to independently plan, track, report and escalate. No project manager will be assigned.
  • Excellent written English. A significant portion of this role is documentation and evidence that must be read and accepted by others.
  • Willingness to record a control as not in place where that is the accurate position.

Nice to have

  • Payments, fintech or regulated financial services background.
  • Understanding of the acquirer, processor and card scheme landscape.
  • Experience of Level 1 service provider validation, or of taking an organisation from self-assessment to QSA-led assessment.
  • PCIP, ISA, CISSP, CISM or equivalent certification.
  • Jira administration and workflow configuration.
  • Familiarity with ISO 27001 or SOC 2.

Benefits

  • Flexibility in work hours and location, with a focus on managing energy rather than time.
  • Access to online learning platforms and a budget for professional development
  • A collaborative, no-silos environment, encouraging learning and growth across teams
  • A dynamic social culture with team lunches, social events, and opportunities for creative input
  • Health insurance
  • Leave Benefits
  • Provident Fund
  • Gratuity

Additional details

  • About the client: Innovative payments technology company transforming how businesses send, receive, pay, and reconcile invoices. Strong focus on simplifying complex payment processes. Provides seamless billing and payments ecosystem for greater flexibility, visibility, and control over cash flow. Integrates with existing accounting platforms and payment workflows. Reduces manual administration, streamlines reconciliation, improves payment experiences, and creates efficient and secure financial processes. Committed to innovation and delivering technology solutions that make payments simpler, faster, and more customer-focused.
  • About Teamified: Talent partner helping companies build exceptional remote teams across IT, software, product, and digital innovation. Collaborates with leading enterprises and fast-scaling tech businesses worldwide. Has operations across the globe. Mission is to make building high performing global teams simple, fast, and cost-effective. Has hundreds of clients with more than 200 engineers, testers, product managers, designers, and technology experts delivering impactful solutions every day.
  • Job type: Three-month contract
  • Payment platform: Cloud-hosted
  • PCI DSS validation: Level 2 service provider via SAQ D for Service Providers
  • Future goal: Anticipates moving to QSA-led Level 1 validation in a future cycle
  • Tools and platforms: Wazuh (open-source SIEM and host intrusion detection platform)
  • Contract specifics: Hands-on engineering role combined with programme ownership. Works alongside client's existing engineering and operations teams.

Similar jobs open now

Twilio logo
remote
Digital Marketing Manager
Twilio
Remote - India
View details
ABB logo
Senior Project Engineer -SIS
ABB
Bangalore, Karnataka, India
View details
Cognyte logo
Product Manager
Cognyte
Pune, Maharashtra, India
View details
IBM logo
Data Engineer-Data Platforms-AWS
IBM
Pune, Maharashtra, India
View details
Apply now
LocationIndia
TypeContract
Posted8/22/2026
Apply by10/21/2026

Links are checked every day. If this one stops working, tell us and we'll pull it.

More like this

View all
Twilio logo
Digital Marketing Manager
Twilio
ABB logo
Senior Project Engineer -SIS
ABB
Cognyte logo
Product Manager
Cognyte
Apply now