PCI DSS & QSA LEAD (Toronto)

PCI DSS & QSA LEAD (Toronto)

29 Aug
|
OBRYN GUARD
|
Toronto

29 Aug

OBRYN GUARD

Toronto

PCI DSS & QSA LEADOBRYN GUARD INC.

Location: North America — Remote

Preferred: Canada or United States

Engagement: Independent Contractor / Equity-Based Specialist Leadership Opportunity

Department: Security, Risk & Compliance

Reports To: Head of Security, Risk & Compliance / Founder & CEO

ABOUT OBRYN GUARD

OBRYN GUARD is a cybersecurity and continuous compliance technology company building an automated cyber assurance platform for hospitality and commercial organizations.

Our platform helps organizations identify control gaps, organize evidence, monitor security and compliance readiness, manage remediation, and maintain stronger assessment preparedness.

Our core framework focus includes:

- PCI DSS v4.0.1
- SOC 2
- ISO/IEC 27001:2022
- NIST-aligned security and risk practices

We are seeking an experienced PCI DSS & QSA Lead to own the specialized payment-security and PCI readiness methodology within OBRYN GUARD. THE ROLE The PCI DSS & QSA Lead will serve as OBRYN GUARD’s senior specialist for PCI DSS, payment environments, Cardholder Data Environment scoping, SAQ methodology, evidence requirements, and PCI readiness.

This role works closely with the Head of Security, engineering, QA, product, customer-facing teams, and executive leadership.

The successful candidate will help ensure that OBRYN GUARD’s PCI methodology is technically accurate, operationally practical, scalable, and appropriately separated from formal PCI validation activities.

PCI QSA EXPERIENCE — REQUIRED / HIGHLY PREFERRED

Candidates should be

- A current PCI Qualified Security Assessor (QSA) ; or
- A recently active QSA with substantial assessment experience through a qualified QSA Company.

Candidates must have deep practical understanding of:
- PCI DSS v4.0 / v4.0.1
- Merchant environments
- Service-provider environments
- CDE scoping
- Payment-flow analysis
- Segmentation
- Scope reduction
- SAQ eligibility
- SAQ selection
- SAQ D
- Evidence requirements
- Control testing
- Remediation
- Compensating controls
- ROC/AOC processes
- Third-party service providers
- Shared responsibility
- Payment-security architecture

KEY RESPONSIBILITIES1. PCI DSS METHODOLOGY Own and maintain OBRYN GUARD’s PCI DSS readiness methodology, including:
- PCI DSS requirement mapping
- Control interpretation
- Evidence requirements
- Testing expectations
- Remediation standards
- Escalation criteria
- Readiness workflows
- Manual versus automated control classification
- Customer guidance
- PCI methodology documentation

1. CDE SCOPING & PAYMENT FLOWS

Develop standardized methodology for identifying and reviewing:
- Cardholder Data Environments
- Connected-to systems
- Security-impacting systems
- Payment channels
- Network boundaries
- Segmentation
- Third-party payment providers
- Shared services
- Scope-reduction opportunities

Support complex customer scoping questions where specialist judgment is required.
1. SAQ METHODOLOGY

Develop and oversee OBRYN GUARD’s SAQ readiness logic, including:
- SAQ eligibility
- SAQ selection
- Merchant environment considerations
- Payment-channel considerations
- Evidence requirements
- Control applicability
- Customer questionnaires
- Readiness guidance
- Escalation of complex cases





The role does not assume that automated platform findings alone establish PCI compliance.
1. HOSPITALITY PAYMENT ENVIRONMENTS

Help develop PCI methodology for hotel and hospitality environments involving:
- Property Management Systems
- Point-of-Sale systems
- Booking engines
- Payment gateways
- Virtual terminals
- Telephone payments
- E-commerce
- Mobile payment environments
- Restaurants
- Spas
- Retail outlets
- Parking
- Event operations
- Franchise environments
- Multi-property hotel groups
- Remote vendors
- Outsourced payment processors

Direct hospitality payment-security experience is highly preferred.
1. PCI EVIDENCE & CONTROL REVIEW

Define what evidence is required to support PCI readiness findings.

Responsibilities include

- Evidence sufficiency
- Evidence freshness
- Evidence mapping
- Manual evidence requirements
- Automated evidence sources
- Exceptions
- False-positive review
- Control-owner responsibilities
- Remediation evidence
- Readiness status logic

1. CONTINUOUS CONTROL MONITORING

Work with product and engineering teams to translate PCI requirements into scalable monitoring logic.

Help determine

- Which PCI controls can be monitored automatically
- Which require questionnaires
- Which require manual evidence
- Which require professional judgment
- Which findings require escalation
- How evidence should be refreshed
- How remediation should be tracked
- How customer readiness status should be represented

1. PRODUCT & ENGINEERING COLLABORATION

Translate PCI requirements into practical product requirements. Work directly with engineering and QA to:
- Review PCI control logic
- Review product workflows
- Define evidence requirements
- Review technical interpretations
- Identify incorrect or misleading automation
- Establish QA acceptance criteria
- Review PCI-related product claims
- Provide remediation guidance where product logic is incomplete

Engineering remains responsible for software implementation.
1. CUSTOMER PCI READINESS

Provide specialist support for complex PCI-related customer matters, including:
- Payment-environment scoping
- SAQ guidance
- Evidence review
- Control interpretation
- Remediation guidance
- Scope questions
- Third-party responsibility questions
- Segmentation considerations
- PCI readiness reviews
- Customer technical discussions

Routine customer support may be handled by the broader security/customer team, with complex PCI matters escalated to the PCI DSS & QSA Lead.
1. PROFESSIONAL & REGULATORY BOUNDARIES

The PCI DSS & QSA Lead must ensure that OBRYN GUARD maintains clear boundaries between:
- PCI readiness
- Advisory services
- Evidence preparation
- Remediation
- Self-assessment support
- Formal PCI validation

An individual QSA credential does not by itself make OBRYN GUARD a QSA Company.



Formal QSA validation services must be performed through an appropriately qualified QSA Company where required.

The successful candidate must maintain applicable PCI SSC professional requirements and independence obligations.

REQUIRED QUALIFICATIONS

- Current or recent PCI QSA experience
- Deep PCI DSS v4.x expertise
- Hands-on CDE scoping experience
- Strong SAQ experience
- Payment-flow analysis experience
- Merchant and/or service-provider assessment experience
- Evidence and control-testing experience
- PCI remediation experience
- Experience working with third-party payment providers
- Strong written documentation skills
- Strong customer-facing communication
- Ability to translate PCI requirements into technical and operational controls
- Ability to collaborate with engineering, security, compliance, and executive teams

HIGHLY PREFERRED EXPERIENCE
- SAQ D
- ROC/AOC engagements
- Level 1 merchants
- Level 1 service providers
- Segmentation validation
- PCI scope reduction
- Cloud payment environments
- SaaS environments
- Hospitality or hotel environments
- PMS/POS integrations
- Multi-property organizations
- PCI readiness technology
- Continuous control monitoring
- Security automation

PREFERRED CERTIFICATIONS
- PCI QSA
- PCIP
- CISSP
- CISA
- CISM
- CRISC
- ISO/IEC 27001 Lead Auditor
- ISO/IEC 27001 Lead Implementer
- Relevant cloud-security certifications

IDEAL CANDIDATE We are looking for someone who can move confidently between:

PCI Requirement → Payment Environment → Scope → Control → Evidence → Product Logic → Remediation → Readiness The ideal candidate understands PCI at the assessment level but can also translate that knowledge into practical workflows for a modern SaaS platform.

This individual should be comfortable working with:

- Security leadership
- Engineers
- QA teams
- Hotel operators
- Enterprise customers
- Payment providers
- Acquirers
- Compliance teams
- External assessors
- Executive leadership

ENGAGEMENT STRUCTURE This position is initially structured as an independent contractor specialist leadership opportunity .

A separate equity opportunity may be provided subject to:

- Vesting
- Performance milestones
- Continued service
- Corporate approvals
- Separate equity documentation

Additional customer-specific professional-services compensation may apply where separately agreed. No fixed employee schedule is created by the independent-contractor structure.

LOCATIONNORTH AMERICA — REMOTE

Robust preference for candidates based in Canada or the United States.

Candidates should be able to collaborate effectively during North American business hours and support customers across international markets where required.

WHY OBRYN GUARD

This is an opportunity to help define the PCI and payment-security foundation of an international cybersecurity and compliance technology company.

The successful candidate will have meaningful influence over:

- PCI methodology
- Payment-security architecture
- SAQ logic
- CDE scoping methodology
- Evidence standards
- Product development
- Continuous control monitoring
- Hospitality payment security
- Customer readiness
- International expansion

OBRYN GUARD INC. Automated Cyber Assurance. Built for hospitality and modern enterprise.

📌 PCI DSS & QSA LEAD (Toronto)
🏢 OBRYN GUARD
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: pci dss & qsa lead (toronto) / toronto