Security Operations Engineer - PCI DSS
๐ข Teamified ยท all Teamified jobs
๐ Remote ยท Asia
๐
Posted 2026-08-22 ยท via RemoteIO
๐ท Security,PCI DSS,AWS,Compliance,DevOps
Apply on original site โAbout the client
Our client is an innovative payments technology company transforming the way businesses send, receive, pay, and reconcile invoices. With a strong focus on simplifying complex payment processes, they provide a seamless billing and payments ecosystem designed to give businesses and their customers greater flexibility, visibility, and control over cash flow.
By integrating with existing accounting platforms and payment workflows, our client helps reduce manual administration, streamline reconciliation, improve payment experiences, and create more efficient and secure financial processes. They are committed to innovation and delivering technology solutions that make payments simpler, faster, and more customer-focused.
As the business continues to grow, they are seeking talented professionals who are passionate about technology, payments, and delivering exceptional customer experiences to join their team.
About Teamified
Teamified is a talent partner helping companies build exceptional remote teams across IT, software, product, and digital innovation. We collaborate with leading enterprises and fast-scaling tech businesses worldwide to help them access world class talent and accelerate growth. With operations across the globe our mission is to make building high performing global teams simple, fast, and cost-effective. Teamified has hundreds of clients with more than 200 engineers, testers, product managers, designers, and technology experts delivering impactful solutions every day.
Job Summary:
Our client operates a cloud-hosted payment platform and validates against PCI DSS v4.0.1 as a Level 2 service provider via SAQ D for Service Providers. They are seeking an experienced security engineer on a three-month contract to run the annual compliance cycle to completion.
This is a hands-on engineering role combined with programme ownership. The successful candidate will implement technical control changes, assemble and quality-check the evidence set, complete the self-assessment questionnaire, and prepare the Attestation of Compliance for executive sign-off. They will work alongside the client's existing engineering and operations teams.
The evidence and documentation produced should be built to a standard suitable for external assessment, as the client anticipates moving to QSA-led Level 1 validation in a future cycle.
Responsibilities:
- Implement and verify technical controls across the cardholder data environment: access management, secure configuration, logging and monitoring, vulnerability management, encryption and key management, and secure development practices.
- Deliver the logging and monitoring requirements to the standard v4.0.1 expects: centralised collection of audit logs from all in-scope system components, protection of logs against alteration, twelve-month retention with three months immediately available, automated mechanisms for log review rather than manual inspection, time synchronisation, change detection on critical files, and alerting on the failure of critical security control systems.
- Work alongside the client's DevOps engineer on the rollout of an open-source SIEM and host intrusion detection platform (Wazuh). The DevOps engineer owns the infrastructure build; this role owns the compliance outcome โ defining required log sources and coverage, developing and tuning detection and correlation rules, configuring file integrity monitoring and retention to meet the standard, validating that the deployment actually satisfies the requirements, and evidencing it.
- Define the alert triage and response routine the client team will operate day to day.
- Complete SAQ D for Service Providers and assemble the supporting evidence set.
- Maintain compliance documentation: network and cardholder dataflow diagrams, scoping and segmentation documentation, policies and operating procedures.
- Engage and manage an Approved Scanning Vendor for quarterly external vulnerability scanning; drive remedi