perience: 5+ Years
J
ob Type: Full Time
J
ob Description:
V
alor Pay Tech is a fast-growing payment technology company serving merchants, ISOs, and ISVs across the United States. As we scale our infrastructure and expand our compliance posture, we are looking for a Senior Security Compliance Engineer to join our Information Security team.
I
n this role you will own and drive compliance programs including SOC 2 Type II, PCI DSS, and PCI P2PE readiness, while partnering closely with engineering, product, and operations teams to embed security controls across the organization. You will work directly with senior leadership and report into the InfoSec team.
K
ey Responsibilities:
L
e- ad SOC 2 Type II audit readiness: gap assessments, control mapping, evidence collection, and audit liaison.
D
r- ive PCI DSS and PCI P2PE compliance efforts, including scoping, gap analysis, remediation tracking, and QSA coordination.
D
e- velop and maintain the Third-Party Risk Management (TPRM) program, including vendor assessments, compliance validation, and contract requirements.
C
o- llaborate with engineering on security reviews for cloud infrastructure, databases, APIs, and application logging requirements.
M
a- intain compliance documentation, policies, standards, and procedures; track remediation across multiple concurrent workstreams.
P
r- ovide compliance guidance on AWS services including IAM, Config, Secrets Manager, and payment cryptography key management.
R
equired Qualifications
5
+- years of experience in security compliance, GRC, or a related information security role.
H
a- nds-on experience with SOC 2 Type II audits — from gap assessment through audit completion.
W
o- rking knowledge of PCI DSS (v4.0) and PCI P2PE standards; experience in payment technology environments strongly preferred.
E
x- perience with AWS security services: IAM, Config, CloudTrail, Secrets Manager, Security Hub.
S
t- rong understanding of TPRM frameworks and third-party risk assessment processes.
E
x- cellent written and verbal communication; able to translate compliance requirements into actionable engineering tasks.
H
i- ghly organized with the ability to manage multiple compliance programs and deadlines simultaneously.
P
referred Qualifications
B
a
- chelor’s degree in Computer Science, Information Technology, Engineering, or a related technical discipline.
E
x- perience in fintech, payments, or financial services environments.
F
a- miliarity with SIEM platforms (e.g., Wazuh) and endpoint security tools (e.g., CrowdStrike).
E
x