Bigcommerce

Bigcommerce

Senior Security GRC Analyst (PCI ISA Specialist)

Austin, TX, USA · Senior

No sponsorship$89k-$150kDetected 24 days ago
CybersecurityComplianceLeadershipCommunicationAdaptability

About the role

  • As a Senior Security GRC Analyst and Internal Security Assessor (ISA), you will serve as the primary Subject Matter Expert (SME) for our global PCI DSS program at Commerce.
  • While your primary focus is PCI, you will be a key player in our broader GRC function, supporting our SOC2 and ISO 27001 certifications.
  • You will act as the technical bridge between our Engineering, Infrastructure, and IT teams and external auditors, ensuring that our high-security standards are documented, validated, and maintained.

Responsibilities

  • Scoping & Segmentation: Partner with Cloud Engineering to validate PCI scope across our global footprint, ensuring effective network segmentation and data flow isolation.
  • Unified Control Framework: Support the broader GRC team in managing our SOC2 Type 2, ISO 27001, and other regulatory audits (as seen on https://www.google.com/search?q=security.commerce.com).
  • Technical Advisory: Provide GRC perspective on architectural designs, product launches, and infrastructure changes to ensure "compliance by design."
  • Remediation Management: Track and drive the remediation of audit findings and security gaps, working closely with asset owners to find pragmatic, secure solutions.
  • Provide GRC perspective on architectural designs, product launches, and infrastructure changes to ensure "compliance by design."
  • Track and drive the remediation of audit findings and security gaps, working closely with asset owners to find pragmatic, secure solutions.

Requirements

  • Regulatory Expertise: Thorough understanding of PCI DSS 4.0 requirements and the practical application of the standard in modern environments.
  • Audit Fluency: Proven experience leading Level 1 Service Provider assessments.
  • Communication: Ability to explain complex compliance requirements to developers and business leaders in a way that emphasizes enablement rather than "blockage."
  • Ability to explain complex compliance requirements to developers and business leaders in a way that emphasizes enablement rather than "blockage."
  • Experience with SOC2 and ISO 27001:2022.
  • Experience with GRC automation and familiarity with modern cloud-native security and observability tools.
  • You enjoy the challenge of a high-paced environment where scale and security must coexist and evolve together.

Nice to have

  • Broad Framework Knowledge: Experience with SOC2 and ISO 27001:2022.
  • Cloud Security: Experience with GRC automation and familiarity with modern cloud-native security and observability tools.
  • Automation Mindset: Experience using GRC platforms and a desire to automate manual evidence collection to reduce audit fatigue.
  • You understand the "Why": You don't just "do compliance"
  • you understand the security intent behind every control and can help teams meet the requirement in a way that actually improves our security posture.
  • Technical Curiosity: You are comfortable diving into technical configurations (IAM policies, VPC flow logs, etc.) to verify control effectiveness yourself.
  • Adaptable: You enjoy the challenge of a high-paced environment where scale and security must coexist and evolve together.
  • (Pay Transparency Range: $ 88,951.00 - $150,432.00 )

Skills

  • Welcome to the Agentic Commerce Era
  • Operationalize PCI requirements (e.g., quarterly scans, penetration test remediation) into automated workflows.
  • Multi-Framework Audit Management

Compensation

  • The national base salary range for this role is posted above in this job post.
  • Final compensation will be determined based on factors such as relevant experience, skills, qualifications and geographic location.
  • We also consider internal equity to help ensure fair and consistent pay practices across our teams.
  • Where applicable, this role may also be eligible for variable compensation (such as bonus or commission), equity, and benefits in accordance with local policies.
  • Details will be shared during the hiring process.
  • We are committed to equitable and transparent pay practices that align to market data, internal equity, and individual contribution.

Benefits

  • We also consider internal equity to help ensure fair and consistent pay practices across our teams.
  • Where applicable, this role may also be eligible for variable compensation (such as bonus or commission), equity, and benefits in accordance with local policies.
  • We are committed to equitable and transparent pay practices that align to market data, internal equity, and individual contribution.

Company info

  • At Commerce, we believe that celebrating the unique histories, perspectives and abilities of every employee makes a difference for our company, our customers and our community.
  • We are committed to creating an inclusive and accessible hiring experience for all candidates.

Equal opportunity

  • We are an equal opportunity employer and the inclusive atmosphere we build together will make room for every person to contribute, grow and thrive.

Visa & Work Authorization

  • solicit money to complete visa requirements as part of a job offer.

This listing is sourced directly from Bigcommerce's careers page and normalized into a canonical job model.