Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Security GRC Analyst (PCI ISA Specialist)

$88.95k - $150.43k
Full-time

Commerce

Welcome to the Agentic Commerce Era At Commerce, our mission is to empower businesses to innovate, grow, and thrive with our open, AI-driven commerce ecosystem. As the parent company of BigCommerce, Feedonomics, and Makeswift, we connect the tools and systems that power growth, enabling businesses to unlock the full potential of their data, deliver seamless and personalized experiences across every channel, and adapt swiftly to an ever-changing market. We believe in harnessing AI responsibly to unlock new possibilities, and we’re looking for individuals who use it intentionally to solve problems, accelerate outcomes, and expand what’s possible in their role. Our purpose is to help businesses confidently solve complex commerce challenges so they can build smarter, adapt faster, and grow on their own terms. If you want to be part of a team of bold builders, sharp thinkers, and technical trailblazers who shape the future of commerce, this is the place for you. As a Senior Security GRC Analyst and Internal Security Assessor (ISA), you will serve as the primary Subject Matter Expert (SME) for our global PCI DSS program at Commerce. We operate a highly mature PCI DSS 4.0 environment; your mission is to lead the continuous evolution of this program, ensuring that compliance is integrated into our "business as usual" (BAU) operations. While your primary focus is PCI, you will be a key player in our broader GRC function, supporting our SOC2 and ISO 27001 certifications. You will act as the technical bridge between our Engineering, Infrastructure, and IT teams and external auditors, ensuring that our high-security standards are documented, validated, and maintained. What You'll Do: PCI SME & Internal Security Assessor (ISA) ISA Leadership: Serve as the officially designated PCI ISA for the organization. Manage the annual assessment lifecycle, including scoping, evidence collection, and validation of controls. PCI 4.0 Evolution: Direct the ongoing maintenance of our PCI 4.0 program, with a specific focus on managing Targeted Risk Analyses (TRAs) and the customized approach where applicable. Scoping & Segmentation: Partner with Cloud Engineering to validate PCI scope across our global footprint, ensuring effective network segmentation and data flow isolation. QSA Liaison: Act as the primary point of contact for our external QSA, defending our control environment and streamlining the audit process to minimize disruption to technical teams. Continuous Compliance: Operationalize PCI requirements (e.g., quarterly scans, penetration test remediation) into automated workflows. Multi-Framework Audit Management Unified Control Framework: Support the broader GRC team in managing our SOC2 Type 2, ISO 27001, and other regulatory audits (as seen on Technical Advisory: Provide GRC perspective on architectural designs, product launches, and infrastructure changes to ensure "compliance by design." Remediation Management: Track and drive the remediation of audit findings and security gaps, working closely with asset owners to find pragmatic, secure solutions. Who You Are: Experience: 6+ years in an Information Security or IT Audit role, with at least 3 years of deep focus on PCI DSS within a major cloud-native environment. Certification: Active PCI ISA (Internal Security Assessor) or PCI QSA certification is mandatory. Regulatory Expertise: Thorough understanding of PCI DSS 4.0 requirements and the practical application of the standard in modern environments. Audit Fluency: Proven experience leading Level 1 Service Provider assessments. Communication: Ability to explain complex compliance requirements to developers and business leaders in a way that emphasizes enablement rather than "blockage." Preferred Qualifications Broad Framework Knowledge: Experience with SOC2 and ISO 27001:2022. Cloud Security: Experience with GRC automation and familiarity with modern cloud-native security and observability tools. Automation Mindset: Experience using GRC platforms and a desire to automate manual evidence collection to reduce audit fatigue. About You You understand the "Why": You don't just "do compliance"; you understand the security intent behind every control and can help teams meet the requirement in a way that actually improves our security posture. Technical Curiosity: You are comfortable diving into technical configurations (IAM policies, VPC flow logs, etc.) to verify control effectiveness yourself. Adaptable: You enjoy the challenge of a high-paced environment where scale and security must coexist and evolve together. This is a Hybrid role - Beginning March 1, 2026, employees who live within commuting distance of a Dedicated Office will be expected to be in the office three days per week. #LI-KE1 #LIHYBRID (Pay Transparency Range: $88,951.00 - $150,432.00) Compensation Transparency The national base salary range for this role is posted above in this job post. Final compensation will be determined based on factors such as relevant experience, skills, qualifications and geographic location. We also consider internal equity to help ensure fair and consistent pay practices across our teams. Where applicable, this role may also be eligible for variable compensation (such as bonus or commission), equity, and benefits in accordance with local policies. Details will be shared during the hiring process. We are committed to equitable and transparent pay practices that align to market data, internal equity, and individual contribution. Inclusion and Belonging At Commerce, we believe that celebrating the unique histories, perspectives and abilities of every employee makes a difference for our company, our customers and our community. We are an equal opportunity employer and the inclusive atmosphere we build together will make room for every person to contribute, grow and thrive. We are committed to creating an inclusive and accessible hiring experience for all candidates. If you require accommodations or adjustments at any stage of the recruitment process, please let us know and we will work with you to meet your needs. Learn more about the Commerce team, culture and benefits at Protect Yourself Against Hiring Scams: Our Corporate Disclaimer Commerce, along with many other employers, has become the subject of fraudulent job offers to hopeful prospective job seekers. Be advised: Commerce does not offer jobs to individuals who do not go through our formal hiring process. Commerce will never: require payment of recruitment fees from candidates; request personally identifiable information through unsanctioned websites or applications; attempt to solicit money from you as part of the hiring process or as part of an employment offer; solicit money to complete visa requirements as part of a job offer. If you receive unsolicited offers of employment from Commerce, we urge you to be extremely cautious and avoid engaging or responding. The Commerce story is one of global growth, incredible talent, and unstoppable passion in all we do. Despite our huge success so far, we’re still just getting started! Explore our history, mission and values. You’ll see we’re set on shaping the now - and the future - of ecommerce. Don’'t Miss Out! Like what you see but suffering from some serious FOMO? Join our Commerce Talent Community, and plug in to our latest news and career opportunities. We’re a group of clever, committed, curious people, unleashing talent in all we do. We believe in the power of togetherness, striving at the edge of what’s possible, impacting the lives of billions of people for the better. In all we do, We Do Extraordinary–and that’s no small feat! Our people are our power. It’s only through dedication, collaboration, and inspiration that we can Do Extraordinary. We’re natural problem-solvers, champions of empowering businesses, and hungry learners… but we also play nerf wars in the office, support each other, and hang out outside of work.

Vacancy posted 7 hours ago
Similar jobs that could be interesting for youBased on the Senior Security GRC Analyst (PCI ISA Specialist) in Austin, TX vacancy
  •  ...Senior Security GRC Analyst And Internal Security Assessor (ISA) At Commerce, our mission is to empower businesses to innovate, grow, and thrive with our open,...  ...primary Subject Matter Expert (SME) for our global PCI DSS program at Commerce. We operate a highly mature... 
    Senior

    BigCommerce

    Austin, TX
    4 hours ago
  •  ...Skills and Qualifications Minimum Years | Skills/Experience 3 - Experience in a GRC, cybersecurity, or compliance role. 3 - Hands-on experience with GRC platforms (Diligent preferred). - Strong understanding of NIST CISF 2.0, HIPPA and state-... 
    Suggested

    Saxon Global

    Austin, TX
    1 day ago
  •  ...Access Management Information Security Analyst We believe that, when done right, investing liberates people to create their own destiny. We are driven by our purpose to champion every client’s goals with passion and integrity. We respect and appreciate the diversity... 
    Senior

    Samprasoft

    Austin, TX
    4 days ago
  • $115k

     ...Fully remote IT Infrastructure & Network Engineering & Operations Overview GovCIO is currently hiring for Senior Information Security Analyst with an active Secret clearance to plan and coordinate IT security programs and policies. This position will be located... 
    Senior
    Full time
    Currently hiring
    Remote work
    Flexible hours

    GovCIO

    Austin, TX
    1 day ago
  •  ...RSA Archer Administration/Configuration), Preferred 10+ Years (Enterprise/Government GRC Environments) Job Description: Seeking an experienced RSA Archer GRC Security Analyst to support enterprise governance, risk, and compliance initiatives through the... 
    Suggested

    Siritech Solutions Corp

    Austin, TX
    2 days ago
  •  ...Job Description Job Description GRC Archer Network Security Analyst II (RSA Archer Specialist) Mode of Work: Onsite Job Description: Seeking an experienced GRC Archer Network Security Analyst II to support enterprise Governance, Risk, and Compliance (GRC)... 

    Siritech Solutions Corp

    Austin, TX
    2 days ago
  • $126k - $190k

     ...leverage your technical expertise to shape security compliance at a global scale? If so,...  ...know and love! Zendesk is seeking a Senior Security Analyst to join our growing fast-paced...  ...with Legal, Engineering, Product, and GRC teams. Provide technical expertise in... 
    Senior
    Full time
    Temporary work
    Remote work

    Zendesk

    Austin, TX
    2 days ago
  •  ...Sr. Security Analyst MAHIN-JOB-33792 Demonstrate strong knowledge in IT controls, risk assessments, and testing of security measures Identify opportunities to continuously innovate and improve the program and value delivered to organization Ensure successful... 
    Senior

    Keylent Inc

    Austin, TX
    3 days ago
  • $90.78k

     ...We are seeking a seasoned Security Governance/Risk professional to support and strengthen enterprise security governance for Federal and...  ...registers, security awareness and training, and maintenance of a GRC Minimum Requirements '- Please refer to the additional information... 
    Senior
    Work at office

    MAXIMUS

    Austin, TX
    6 days ago
  • $49.73k - $84.1k

     ...Senior Security Governance Risk and Compliance Analyst At Commerce, our mission is to empower businesses to innovate, grow...  .... This role will report into our GRC function and work cross-...  ..., and legal compliance, including PCI, GDPR, ISO 27001, NIST, and SOX.... 
    Work at office
    Local area
    Flexible hours
    3 days per week

    BigCommerce

    Austin, TX
    3 hours ago
  • $70 - $80 per hour

     ...professionals with meaningful career opportunities. We are seeking a GRC Analyst to support our client's team. Created Date: April 15, 2026...  ...serve as the primary GRC resource, partnering closely with security and engineering teams to drive vendor risk, compliance, and... 
    Senior
    Hourly pay
    Contract work
    Temporary work
    Local area
    Monday to Friday
    Shift work
    Day shift

    Eastridge Workforce Solutions

    Austin, TX
    3 days ago
  • $120k - $135k

     ...A growing organization is seeking a Lead Security Analyst to serve as the senior technical escalation point within its Security Operations Center (SOC). This role focuses on leading complex incident investigations, improving detection capabilities, and advancing automation... 

    Soni Resources

    Austin, TX
    1 day ago
  •  ...life at Tesla by giving them ownership over projects that are critical to their team's success. About the Team: Security Intelligence Analysts are responsible for the protection of Tesla's intellectual property, reputation, trade secrets, and confidential information... 
    Full time
    Temporary work
    Part time
    Internship
    Flexible hours
    Shift work

    Tesla

    Austin, TX
    17 hours ago
  •  ...Security Analyst Austin, TX 12 Months The staff augmentation contractor will serve as an IT Security Analyst in support of the Upgrade Laboratory Information Management System (LIMS) project, an approved Exceptional Item. The project will modify multiple LIMs applications... 
    For contractors
    Work at office

    Keylent Inc

    Austin, TX
    3 days ago
  • $52 - $67 per hour

     ...device company based in Austin, TX is looking for Insider Threat Analyst to join their team! Responsibilities: Leverage business...  ...intrusions and complex frauds Address a variety of related risk and security concerns Minimum Qualifications: Bachelor of Science or... 
    Contract work

    OSI Engineering

    Austin, TX
    3 days ago
  •  ...Position: Security Analyst 1 Location: Austin, TX 78701 Duration: 7+ years All work products resulting from the project...  ...selecting a Worker(s). • Worker will perform highly complex (senior-level) security and business analysis work. • Worker will... 

    3B Staffing LLC

    Austin, TX
    1 day ago
  •  ...and custom software development. The Network Security Analyst II – RSA Archer Specialist is a senior‑level technical role responsible for architecting,...  ...implementing, optimizing, and sustaining enterprise RSA Archer GRC solutions . This position requires deep platform... 

    Stragistics Technology

    Austin, TX
    1 day ago
  •  ...Archer, Governance Risk & Compliance (GRC), REST APIs, Web Services, JavaScript...  ...Integration, Risk Management, Security Compliance, NIST, ISO 27001, SOC Compliance...  ...seeking an experienced Network Security Analyst II – RSA Archer Specialist to support enterprise Governance,... 
    Contract work

    Dutech Systems, inc

    Austin, TX
    6 days ago
  •  ...We are looking for an experienced Network Security Analyst II with strong RSA Archer expertise for a 3+ month contract engagement with possible...  ...: • Design, configure, and support RSA Archer GRC solutions • Implement A&A, Controls Assurance, Issues Management... 
    Contract work

    Indotronix Avani Group

    Austin, TX
    3 days ago
  •  ...transferring information and funds to eliminate wire fraud and provide a secure, easy-to-use platform for title companies, law firms, and other...  ...We are seeking a detail-oriented Compliance & Security Analyst to support our Head of IT & Compliance in maintaining and... 
    Work at office

    Closinglock

    Austin, TX
    17 hours ago
  •  ...Hi All, *** Greetings from My3tech *** Role: Network Security Administrator Location: Onsite(Austin, TX) Duration: 12+ Months Minimum Yrs of Experience, Skills, and Qualifications Years Skills/Experience 7 Experience in identity... 

    My3Tech Inc

    Austin, TX
    2 days ago
  •  ...Data Security Analyst Intern 2 Office of the Attorney General of Texas requires the services of 1 Data Security Analyst Intern 2, hereafter referred to as Candidate(s), who meets the general qualifications of Data Security Analyst Intern 2, Security and the specifications... 
    Hourly pay
    Daily paid
    Internship
    Work at office
    Remote work
    Monday to Friday
    Weekend work
    Afternoon shift

    Samprasoft

    Austin, TX
    4 days ago
  • $76k - $100k

     ...The Bonterra Information Security Risk and Compliance department...  ...looking to hire a Compliance Specialist to our team. If you enjoy problem...  ...in dealing with Bonterra senior management. ~ Proficient...  ...software systems, including GRC, ticketing and project management... 
    Full time
    Local area

    Social Solutions Global

    Austin, TX
    3 days ago
  • $76.4k - $138.6k

    A global consulting firm is seeking an Offensive Security Analyst in Austin, Texas. The candidate will evaluate and manage vulnerabilities, ensuring security standards are upheld. This role requires at least 3 years of experience in vulnerability management and a strong... 

    EY

    Austin, TX
    3 days ago
  • AtWork Group is seeking an experienced Network Security Analyst II in Austin, TX to support a Texas state agency. This role focuses on designing, configuring, and supporting Governance, Risk, and Compliance solutions within the RSA Archer platform. The ideal candidate... 

    AtWork Group

    Austin, TX
    1 day ago
  • Junior Information Security Analyst Location: Austin, Texas (ONSITE 5 days/week) Contract Position: 12 month Contract (with strong potential for extension and career advancement) Our client is seeking a Junior Information Security Analyst to assist in supporting and... 
    Contract work

    Genius Road, LLC

    Austin, TX
    2 days ago
  •  ...Principal IAM GRC Analyst The Principal IAM GRC Analyst provides technical guidance, implementation...  ..., especially as it relates to written security and access controls. ~2-4 years of Big...  ...of regulatory compliance (SOX, PCI, GDPR, GLBA, etc.). ~ Familiarity with... 

    Professional Recruiters

    Austin, TX
    3 days ago
  • $79.1k - $129.95k

     ...Security Operations Lead Security Analyst Salary Range $79,100.00 - $129,950.00 Salary/year Position Type Full Time Description Security Operations...  ...Summary: The Lead Security Analyst serves as the senior technical escalation point within the Security... 
    Weekly pay
    Full time
    Temporary work
    Work experience placement
    Work at office
    Flexible hours

    Continental General

    Austin, TX
    13 days ago
  • $70k

    Job Posting Title: Epic Security and Access Analyst II ---- Hiring Department: Dell Medical School ---- Position Open To: All Applicants ---- Weekly...  ...IAM teams for issue resolution Escalate complex issues to senior analysts as appropriate Supports Change Management and... 
    Full time
    For contractors
    Work at office
    Local area
    Immediate start

    University of Texas at Austin

    Austin, TX
    7 hours ago
  • $30 per hour

     ...Senior Accounts Receivable Specialist (Contract – Long Term) Location: Austin, TX (Hybrid/Onsite) Pay: $30/hour Employment Type: Long-Term Contract (via LHH / Accounting Principals) About the Opportunity LHH is partnering with a growing organization to add a Senior... 
    Senior
    Hourly pay
    Long term contract
    Contract work
    Temporary work
    Local area

    LHH

    Austin, TX
    14 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Security GRC Analyst (PCI ISA Specialist). Be the first to apply!