This is a great opportunity to grow your career and lead enterprise engagements as a Senior Consultant for our Payments Solution Validation team.
In this role you will lead and perform assessments of client environments against regulatory and industry security standards, with a primary focus on PCI Point-to-Point Encryption (P2PE) and PCI PIN Security standards.
As a senior member of the Payments Solution Validation team, you will evaluate technical controls, encryption architectures, and secure key-management practices for financial institutions and payment solution providers.
You will act as a trusted advisor, guiding clients on data protection strategies, encryption best practices, and overall PCI compliance while delivering high-quality assessment reports and attestations.
Leads audits and assessments including audit planning, evidence review, controls evaluation, and client interviews.
Prepare relevant frameworks assessment reports and attestations.
Manage priorities, tasks and hours on projects in coordination with project managers to meet delivery utilization targets.
Ensure all deliverables meet Coalfire quality standards and timelines.
Proactively escalate client or project risks to management.Interface with clients throughout the engagement, including executive and technical stakeholders
Build and maintain strong, collaborative client relationships
Maintain industry certifications and deepen subject matter expertise through continuous professional development.
Travel up to 30% as required
5+years in IT security, payments security and/or application development
Bachelor’s degree (four-year college or university) or equivalent combination of education and work experience.
Knowledge of industry cryptography standards such as ISO 11568 and 13491, ANSI X9.97, and NIST 140-2 Level 3
Strong understanding of PCI compliance, encryption, key management, PKI, HSMs, POI key-injection, physical security controls
Experience with security audits, risk assessments, and gap analyses.
A commitment to your profession demonstrated by participation in industry events, seminars, blogs, and memberships in professional associations
Strong consulting skills with executive leadership and technical teams; ability to advise, challenge, and influence while building trust
Excellent written and verbal communication skills
Ability to lead and facilitate meetings with small and large groups
Strong customer service, stakeholder management, and project management skills
Ability to manage multiple initiatives and projects independently in a fast‑paced consulting environment
Hold certifications in the below categories
Information security certification: CISSP, CISM, ISO Lead 27001:2022 Lead Implementer
Audit certification: CISA, GSNA, ISO 27001:2022 Lead Auditor, IRCA ISMS Auditor or higher, IIA Certified Internal Auditor (CIA)
Willingness and ability to pursue P2PE-Assessor and/or QPA (PIN Assessor) certification
- Current or former PCI-QSA certification
- Current or former P2PE certification
- Current or former PIN certification