Job Description
Join a world-class academic healthcare system, UChicago Medicine , as a Payment Card Industry data Security Standards (PCI DSS) Risk Analyst on our Information Security and Privacy GRC team. This is a remote, work from home opportunity, and you may be based outside of the greater Chicagoland area.
The Payment Card Industry Data Security Standards (PCI DSS) Risk Analyst – Intermediate, reporting to the Director, Information Security and Privacy Governance, Risk, and Compliance, will be responsible for ensuring PCI DSS compliance across relevant business units by understanding payment-related business processes, and, maintaining and validating documentation and communicating PCI requirements. The position will act as a subject matter expert for Payment Card Industry Data Security Standards by helping define the cardholder data environment, overseeing the implementation of PCI controls, and escalating matters of risk or non-compliance. This role contributes to the organization’s broader information risk management goals by supporting secure handling of payment data and minimizing regulatory exposure.
Essential Job Functions
- Develop and maintain PCI DSS compliance programs and ensure alignment with organizational goals
- Develop and communicate PCI related policies, procedures, standards, and training / awareness
- Define and document the scope of the cardholder data environment (CDE), systems connected to the CDE, and business processes within applicable business units
- Implement all applicable PCI standards and requirements and ensure ongoing maintenance of applicable controls
- Coordinate, and where applicable, conduct internal assessments and support external audits addressing identified gaps effectively
- Assess risks associated with PCI compliance and recommend appropriate actions such as risk acceptance, mitigation or remediation; Participate in risk management initiatives related to data protection and information security including, but not limited to, engaging with third-party vendors / service providers that handle cardholder data to review PCI compliance
- Monitor and investigate PCI-related security incidents in collaboration with IT security operations and applicable IT teams
- Other duties as assigned
Required Qualifications
Bachelor's degree required in Information Security, Computer Science, Information Technology, or a related field or equivalent work experienceMinimum of 2+ years of applicable PCI DSS experienceDemonstrated proficiency with the HIPAA Security, NIST and other relevant healthcare regulations and standardsAbility to define and implement a multi-year operationally sound technology-focused set of strategic goalsProven ability to build positive team relationships with all levels of the enterprise and across a diverse set of departmentsAbility to prepare both executive and detailed reports on risk findings and statusAbility to develop remediation plans and guide departments with remediation strategySkilled in project management and work plan development and implementationKnowledge and ability to direct a team in integrating informational technology services with the work requirements and deliverables of units and departmentsEffective oral and written communication skills and interpersonal skillsPreferred Qualifications
Academic medical center and / or health care consulting experienceOne or more of the following security certifications are preferred : CISSP, PCIP, CISA or CRISCPosition Details
Job Type / FTE : Full TimeShift : DaysLocation : RemoteUnit / Department : Information Security OfficeCBA Code : Non-Union