Roles & Responsibilities:
Identifying, collecting, organizing, and reviewing pertinent evidence across multiple platforms and
applications to determine compliance with relevant PCI DSS controls.
Validating the scope of the Cardholder Data Environment (CDE) as determined by the assessed organization.
Conducting an on-site assessment, examining the CDE which is in scope.
Assessing with a sampling approach (as approved by the PCI DSS audit standard) and selecting employees,
facilities, systems, and system components accurately representing the assessed environment and which is
in scope.
Evaluate all the compensating controls as applicable.
Providing an opinion on whether or the assessed organization is compliant and meets PCI DSS
Requirements.
Draft and generate a ROC effectively based on the assessment findings.
Based on the assessment and validation of the findings, provide an AOC to the assessed organizations PCI
DSS compliance status.
Maintaining documents, paper works, and recordings of interviews that were collected during the PCI DSS
Assessment as evidence and using it to validate the findings.
Applying and maintaining independent judgment in all PCI DSS Assessment decisions.
Conducting follow-up assessments as and when needed.
PCI SSC periodically performs QA reviews on a QSAs ROC to ensure that the documentation of testing
procedures performed is sufficient to support the results of the PCI DSS Assessment.
Required Skills:
Minimum three years Experience as a Qualified Security Assessor actively performing PCI assessments
and/or remediation engagements.
Demonstrated ability to work independently as well as in a team to meet delivery obligations.
Demonstrated effective communication skills both written and verbal.
Effective presentation skills.
Ability to travel.