Bigcommerce
Senior Security GRC Analyst (PCI ISA Specialist)
Austin, TX, USA · Senior
No sponsorship$89k-$150kDetected 24 days ago
CybersecurityComplianceLeadershipCommunicationAdaptability
About the role
- As a Senior Security GRC Analyst and Internal Security Assessor (ISA), you will serve as the primary Subject Matter Expert (SME) for our global PCI DSS program at Commerce.
- While your primary focus is PCI, you will be a key player in our broader GRC function, supporting our SOC2 and ISO 27001 certifications.
- You will act as the technical bridge between our Engineering, Infrastructure, and IT teams and external auditors, ensuring that our high-security standards are documented, validated, and maintained.
Responsibilities
- Scoping & Segmentation: Partner with Cloud Engineering to validate PCI scope across our global footprint, ensuring effective network segmentation and data flow isolation.
- Unified Control Framework: Support the broader GRC team in managing our SOC2 Type 2, ISO 27001, and other regulatory audits (as seen on https://www.google.com/search?q=security.commerce.com).
- Technical Advisory: Provide GRC perspective on architectural designs, product launches, and infrastructure changes to ensure "compliance by design."
- Remediation Management: Track and drive the remediation of audit findings and security gaps, working closely with asset owners to find pragmatic, secure solutions.
- Provide GRC perspective on architectural designs, product launches, and infrastructure changes to ensure "compliance by design."
- Track and drive the remediation of audit findings and security gaps, working closely with asset owners to find pragmatic, secure solutions.
Requirements
- Regulatory Expertise: Thorough understanding of PCI DSS 4.0 requirements and the practical application of the standard in modern environments.
- Audit Fluency: Proven experience leading Level 1 Service Provider assessments.
- Communication: Ability to explain complex compliance requirements to developers and business leaders in a way that emphasizes enablement rather than "blockage."
- Ability to explain complex compliance requirements to developers and business leaders in a way that emphasizes enablement rather than "blockage."
- Experience with SOC2 and ISO 27001:2022.
- Experience with GRC automation and familiarity with modern cloud-native security and observability tools.
- You enjoy the challenge of a high-paced environment where scale and security must coexist and evolve together.
Nice to have
- Broad Framework Knowledge: Experience with SOC2 and ISO 27001:2022.
- Cloud Security: Experience with GRC automation and familiarity with modern cloud-native security and observability tools.
- Automation Mindset: Experience using GRC platforms and a desire to automate manual evidence collection to reduce audit fatigue.
- You understand the "Why": You don't just "do compliance"
- you understand the security intent behind every control and can help teams meet the requirement in a way that actually improves our security posture.
- Technical Curiosity: You are comfortable diving into technical configurations (IAM policies, VPC flow logs, etc.) to verify control effectiveness yourself.
- Adaptable: You enjoy the challenge of a high-paced environment where scale and security must coexist and evolve together.
- (Pay Transparency Range: $ 88,951.00 - $150,432.00 )
Skills
- Welcome to the Agentic Commerce Era
- Operationalize PCI requirements (e.g., quarterly scans, penetration test remediation) into automated workflows.
- Multi-Framework Audit Management
Compensation
- The national base salary range for this role is posted above in this job post.
- Final compensation will be determined based on factors such as relevant experience, skills, qualifications and geographic location.
- We also consider internal equity to help ensure fair and consistent pay practices across our teams.
- Where applicable, this role may also be eligible for variable compensation (such as bonus or commission), equity, and benefits in accordance with local policies.
- Details will be shared during the hiring process.
- We are committed to equitable and transparent pay practices that align to market data, internal equity, and individual contribution.
Benefits
- We also consider internal equity to help ensure fair and consistent pay practices across our teams.
- Where applicable, this role may also be eligible for variable compensation (such as bonus or commission), equity, and benefits in accordance with local policies.
- We are committed to equitable and transparent pay practices that align to market data, internal equity, and individual contribution.
Company info
- At Commerce, we believe that celebrating the unique histories, perspectives and abilities of every employee makes a difference for our company, our customers and our community.
- We are committed to creating an inclusive and accessible hiring experience for all candidates.
Equal opportunity
- We are an equal opportunity employer and the inclusive atmosphere we build together will make room for every person to contribute, grow and thrive.
Visa & Work Authorization
- solicit money to complete visa requirements as part of a job offer.
Apply directly at Bigcommerce →Create a free account for alerts like thisView Bigcommerce immigration profile
This listing is sourced directly from Bigcommerce's careers page and normalized into a canonical job model.