Search jobs now Find the right job type for you Create a job alert Explore how we help job seekers Contract talent Permanent talent Learn how we work with you Executive search Finance and Accounting Technology Marketing and Creative Legal Administrative and Customer Support Technology Risk, Audit and Compliance Finance and Accounting Digital, Marketing and Customer Experience Legal Operations Human Resources 2026 Salary Guide Demand for Skilled Talent Report Job Market Outlook Press Room Tech insights Labor market overview AI in recruiting Navigating the AI era Staffing for small businesses Cost of a bad hire Browse jobs Find your next hire Our locations
Lead GRC Security Analyst
<p>We are seeking an experienced <strong>Information Security GRC professional with strong PCI DSS expertise</strong> to lead the design, implementation, and ongoing execution of an enterprise <strong>PCI DSS v4.0 compliance program</strong> within a highly regulated environment.</p><p>This role will serve as the organization’s <strong>PCI subject matter expert (SME)</strong>, responsible for ensuring accurate Cardholder Data Environment (CDE) scoping, sustainable control implementation, continuous compliance, and effective governance. The successful candidate will work cross-functionally with Security, IT, Risk, Compliance, Audit, and business stakeholders to embed PCI requirements into technology and operational processes.</p><p>This is a highly visible role requiring someone who can operate strategically while also being comfortable getting into the details of controls, evidence, assessments, remediation, and audit readiness.</p><p>Key Responsibilities</p><ul><li>Lead the enterprise <strong>PCI DSS v4.0 program</strong>, including governance, compliance, assessment, and continuous improvement activities.</li><li>Validate and maintain accurate <strong>Cardholder Data Environment (CDE) scope</strong>.</li><li>Serve as the primary <strong>PCI DSS subject matter expert</strong> across the organization.</li><li>Partner with Security, IT, Risk, Compliance, Audit, and business teams to drive cross-functional accountability for PCI requirements.</li><li>Manage relationships with <strong>Qualified Security Assessors (QSAs)</strong> and coordinate PCI assessments from preparation through remediation and closure.</li><li>Develop and manage remediation strategies for PCI and security control gaps.</li><li>Support risk acceptance processes and ensure appropriate documentation and governance.</li><li>Test and evaluate control effectiveness and maintain clear control traceability.</li><li>Manage evidence collection, assessment walkthroughs, findings, remediation, and closure activities.</li><li>Support internal and external audits as well as regulatory examinations.</li><li>Conduct security risk and control assessments.</li><li>Develop and report <strong>KRIs, KPIs, OKRs, and other security/compliance metrics</strong>.</li><li>Present security, risk, and control findings to both technical stakeholders and executive leadership.</li><li>Lead reviews, updates, and approvals of security policies, standards, and related governance documentation.</li><li>Embed PCI requirements into technology and operational lifecycles.</li><li>Drive ongoing improvements to the organization’s security compliance and risk management processes.</li></ul><p>Technical Environment</p><ul><li>PCI DSS v4.0</li><li>Information Security Governance, Risk &amp; Compliance (GRC)</li><li>ServiceNow, LogicGate, Archer, or similar GRC platforms</li><li>NIST Cybersecurity Framework (CSF) 2.0</li><li>CIS Controls v8</li><li>Security controls and compliance management</li><li>Risk assessments</li><li>Audit management</li><li>Policy and standards governance</li><li>Regulatory compliance and examination support</li></ul>
<p>Required Qualifications</p><ul><li><strong>5–8 years of experience in Information Security GRC</strong>, with at least <strong>3 years of hands-on PCI DSS experience</strong>.</li><li>Demonstrated experience owning or leading an <strong>enterprise PCI DSS program</strong>.</li><li>Strong experience with <strong>CDE scoping and PCI DSS control requirements</strong>.</li><li>Experience managing QSA relationships and leading PCI assessments through preparation, assessment, remediation, and closure.</li><li>Experience with GRC platforms such as <strong>ServiceNow, LogicGate, Archer, or similar</strong>.</li><li>Experience supporting internal/external audits, regulatory examinations, evidence collection, and remediation.</li><li>Working knowledge of <strong>NIST CSF 2.0 and CIS Controls v8</strong>, including the ability to map controls across security and compliance frameworks.</li><li>Experience developing and presenting <strong>KRIs, KPIs, OKRs, and security/risk metrics</strong>.</li><li>Strong communication skills with the ability to explain complex PCI and security control gaps to non-technical audiences and executive leadership.</li><li>Bachelor’s degree in <strong>Information Security, Computer Science, Risk Management, or a related field</strong>.</li></ul><p><br></p>
<h3 class="rh-display-3--rich-text">Technology Doesn't Change the World, People Do.<sup>®</sup></h3> <p>Robert Half is the world’s first and largest specialized talent solutions firm that connects highly qualified job seekers to opportunities at great companies. We offer contract, temporary and permanent placement solutions for finance and accounting, technology, marketing and creative, legal, and administrative and customer support roles.</p> <p>Robert Half works to put you in the best position to succeed. We provide access to top jobs, competitive compensation and benefits, and free online training. Stay on top of every opportunity - whenever you choose - even on the go. <a href="https://www.roberthalf.com/us/en/mobile-app" target="_blank">Download the Robert Half app</a> and get 1-tap apply, notifications of AI-matched jobs, and much more.</p> <p>All applicants applying for U.S. job openings must be legally authorized to work in the United States. Benefits are available to contract/temporary professionals, including medical, vision, dental, and life and disability insurance. Hired contract/temporary professionals are also eligible to enroll in our company 401(k) plan. Visit <a href="https://roberthalf.gobenefits.net/" target="_blank">roberthalf.gobenefits.net</a> for more information.</p> <p>© 2025 Robert Half. An Equal Opportunity Employer. M/F/Disability/Veterans. By clicking “Apply Now,” you’re agreeing to Robert Half’s <a href="https://www.roberthalf.com/us/en/terms">Terms of Use</a> and <a href="https://www.roberthalf.com/us/en/privacy">Privacy Notice</a>.</p>
  • Middleton, WI
  • remote
  • Temporary / Contract
  • 50 - 65 USD / Hourly
  • <p>We are seeking an experienced <strong>Information Security GRC professional with strong PCI DSS expertise</strong> to lead the design, implementation, and ongoing execution of an enterprise <strong>PCI DSS v4.0 compliance program</strong> within a highly regulated environment.</p><p>This role will serve as the organization’s <strong>PCI subject matter expert (SME)</strong>, responsible for ensuring accurate Cardholder Data Environment (CDE) scoping, sustainable control implementation, continuous compliance, and effective governance. The successful candidate will work cross-functionally with Security, IT, Risk, Compliance, Audit, and business stakeholders to embed PCI requirements into technology and operational processes.</p><p>This is a highly visible role requiring someone who can operate strategically while also being comfortable getting into the details of controls, evidence, assessments, remediation, and audit readiness.</p><p>Key Responsibilities</p><ul><li>Lead the enterprise <strong>PCI DSS v4.0 program</strong>, including governance, compliance, assessment, and continuous improvement activities.</li><li>Validate and maintain accurate <strong>Cardholder Data Environment (CDE) scope</strong>.</li><li>Serve as the primary <strong>PCI DSS subject matter expert</strong> across the organization.</li><li>Partner with Security, IT, Risk, Compliance, Audit, and business teams to drive cross-functional accountability for PCI requirements.</li><li>Manage relationships with <strong>Qualified Security Assessors (QSAs)</strong> and coordinate PCI assessments from preparation through remediation and closure.</li><li>Develop and manage remediation strategies for PCI and security control gaps.</li><li>Support risk acceptance processes and ensure appropriate documentation and governance.</li><li>Test and evaluate control effectiveness and maintain clear control traceability.</li><li>Manage evidence collection, assessment walkthroughs, findings, remediation, and closure activities.</li><li>Support internal and external audits as well as regulatory examinations.</li><li>Conduct security risk and control assessments.</li><li>Develop and report <strong>KRIs, KPIs, OKRs, and other security/compliance metrics</strong>.</li><li>Present security, risk, and control findings to both technical stakeholders and executive leadership.</li><li>Lead reviews, updates, and approvals of security policies, standards, and related governance documentation.</li><li>Embed PCI requirements into technology and operational lifecycles.</li><li>Drive ongoing improvements to the organization’s security compliance and risk management processes.</li></ul><p>Technical Environment</p><ul><li>PCI DSS v4.0</li><li>Information Security Governance, Risk &amp; Compliance (GRC)</li><li>ServiceNow, LogicGate, Archer, or similar GRC platforms</li><li>NIST Cybersecurity Framework (CSF) 2.0</li><li>CIS Controls v8</li><li>Security controls and compliance management</li><li>Risk assessments</li><li>Audit management</li><li>Policy and standards governance</li><li>Regulatory compliance and examination support</li></ul>
  • 2026-08-28T00:00:00Z

Lead GRC Security Analyst Job in Middleton, WI | Robert Half