InfoSec PCI Compliance Lead

DISH

3.4

Englewood, CO

Why you should apply for a job to DISH:

  • 4.1/5 in supportive management

  • Ratings are based on anonymous reviews by Fairygodboss members.
  • DISH invests in their employees with profit sharing – on top of 401(k) matching

  • DISH’s Paid Protected Time allows employees flexible time off for anything from vacation to emergencies or other extenuating circumstances

  • The Employee Assistance Plan is available to all employees & offers free, 1-on-1 counseling with experienced consultants available 24/7

  • #71686

    Position summary

    Department Summary

    Job Description:

    DISH Network has an exciting opportunity for an InfoSec PCI Compliance Lead at our Headquarters location in Englewood, Colorado. The InfoSec PCI Compliance Lead is a key part of our Information Security and Governance, Risk, and Compliance (GRC) teams. This position is full-time, permanent, and salaried with standard work hours, has no supervisory duties, and requires very little travel. We are looking for someone who can start immediately.

    The InfoSec PCI Compliance Lead will report to the Information Security Compliance Manager and function as a central Payment Card Information subject matter expert supporting enterprise teams looking to involve DISH PCI data in business solutions and processes. They will lead the company through the design and build out of a program that focuses on the protection, use, and control monitoring of PCI data, including any necessary certifications or audits. 

    Job Duties and Responsibilities

    Job Duties and Responsibilities 

    Primary responsibilities of the Information Security PCI Compliance Program Manager include the following:

    • Draft policies/procedures that govern the security of DISH PCI data across the enterprise with a specific focus on compliance requirements.
    • Design, lead and execute a Compliance program focused on PCI data handling across the enterprise.
    • Partner with security teams to identify and analyze security requirements to align with PCI compliance standards.
    • Track, document and address PCI compliance gaps to ensure timely closure.
    • Manage the annual PCI audit including evidence gathering, quality assurance of evidence, coordination of audit resource meetings, and other tasks required to successfully complete the audit.
    • Ensure ASV Scans and Pentesting are conducted quarterly and annually, respectively with all remediation activities being completed within expected timelines.
    • Lead security enhancement projects focused on new or changing PCI compliance requirements.
    • Educate and build awareness of PCI compliance requirements.
    • Coordinate with Third Party Risk management to ensure PCI compliance needs are being addressed and tracked appropriately with third party vendors.
    • Coordinate with Privacy / Legal to ensure the overall compliance landscape is well understood and the program captures a complete view of our PCI compliance needs.
    • Continuously improve the PCI compliance program with new information, procedures, or documentation.
    • Coach and mentor junior staff.
    • Other responsibilities as assigned.

    The successful candidate will possess the following qualifications: 

    Successful candidate must be willing to relocate & work onsite.

    Competencies:

    • Project Management
    • Self-led Learner
    • Customer First Mentality
    • Strong Adaptability
    • Process Documentation Management
    • Process Mapping Development
    • Presentation Skills
    • Multitasking
    • Compliance + Risk Mindset
    • Communication w Executives
    • Team Mentorship
    • Can Interpret Regulations and Compliance Requirements
    • Thought Leadership
    • Cross-functional Team Leadership
    • Strategic Thinking and Planning (Team)
    • Brand & Team Ambassador
    • Solid Risk Management Foundation
    • Solid Information Security Foundation
    • Solid Security Control Framework Foundation
    • Expert PCI-DSS Knowledge
    • General Data Privacy Foundation
    • Can Teach/Educate Risk & InfoSec Principles
    • Can Consult Business on Risk and InfoSec Principles

    Personality:

    • Requires a well-organized, cheerful and persuasive individual, who can manage multiple priorities at once. 

    • Must have good meeting management and communication skills to keep conversations focused and productive. 

    • Must be self-driven; able to manage schedules, meet deadlines, coordinate with others, and perform tasks with minimal supervision. 

    • Must have the ability to work with a diverse audience, under tight deadlines, and negotiate successful outcomes to challenging problems.

    Skills, Experience and Requirements

    Skills, Experience snd Requirements 

    Education and Experience:

    • Bachelor's Degree or equivalent experience and 4-6 years of directly related experience. 
    • Must have a solid understanding of SOX, PCI, CPNI, CCPA, FACTA and similar IT Compliance and Privacy regulations.
    • Experience with compliance audits such as PCI and/or CPNI. Former QSA preferred.
    • Experience with NIST, ISO and other industry standards.
    • Expert user of Microsoft/Google Suite and an eGRC tool.

    Other Qualifications:

    • Professional certification (CISSP, CISA, CSIM, CIA or similar) is highly desired. 

    #LI-AD3

    Salary Range

    Compensation: $115,500.00/Year - $165,000.00/Year
    Compensation and Benefits

    We also offer versatile health perks, including flexible spending accounts, HSA, a 401(k) Plan with company match, ESPP, career opportunities, and a flexible time away plan; all benefits can be viewed here: DISH Benefits.   

    The base pay range shown is a guideline. Individual total compensation will vary based on factors such as qualifications, skill level, and competencies; compensation is based on the role's location and is subject to change based on work location. Candidates need to successfully complete a pre-employment screen, which may include a drug test and DMV check.

    Get jobs straight to your inbox

    Anonymous company reviews, virtual recruiting events, and a supportive community for women when you sign up.

    What are DISH perks and benefits

    Lactation facilities

    Post maternity

    Fertility

    On-ramping/Off-ramping parental leave

    Care-taking PTO

    Elder care

    Unconscious bias training

    Sponsorship program

    Networking

    Diversity recruiting

    Diversity performance

    Remote work policy

    Part time policy

    Short term disability

    About the company

    Industry: Telecommunications

    Our adventure began by changing the way people watched TV, bringing DISH to where big cable wouldn’t: rural America. Since then, we have reinvented ourselves and our own industry with Sling TV to give millions of consumers more choice in entertainment. Today, we’ve officially entered the consumer wireless industry as the fourth largest wireless provider with our acquisitions of Boost Mobile, Ting Mobile ...

    Why you should apply for a job to DISH:

  • 4.1/5 in supportive management

  • Ratings are based on anonymous reviews by Fairygodboss members.
  • DISH invests in their employees with profit sharing – on top of 401(k) matching

  • DISH’s Paid Protected Time allows employees flexible time off for anything from vacation to emergencies or other extenuating circumstances

  • The Employee Assistance Plan is available to all employees & offers free, 1-on-1 counseling with experienced consultants available 24/7