Senior PCI Compliance & Risk Officer

Senior PCI Compliance & Risk Officer

Full-Time 70000 - 90000 £ / year (est.) Home office (partial)
Evervault Inc.

At a Glance

  • Tasks: Own PCI DSS compliance, manage audits, and improve security policies.
  • Company: Evervault, a leading encryption and data security infrastructure provider.
  • Benefits: Competitive salary, flexible work environment, and strong ownership opportunities.
  • Other info: Join a small, high-trust team in a fast-paced startup environment.
  • Why this job: Make a real impact on data security while working with top-tier engineers.
  • Qualifications: Deep PCI expertise and technical fluency in compliance and security.

The predicted salary is between 70000 - 90000 £ per year.

Evervault builds encryption and data security infrastructure for developers. APIs and primitives for tokenizing, encrypting, and processing sensitive data at scale, currently focused on powering the payments stack for companies like Rippling, Ramp, and Sorare.

Team: Reporting to the CEO

About the Role

Compliance is core to what we sell. Our customers trust us with their most sensitive data (card numbers, credentials, PII) and they need to know we meet the highest security and compliance standards in the industry. We're looking for a Legal & Compliance Officer to own PCI DSS compliance end-to-end and continue building Evervault's compliance and risk function. Our outgoing Head of Compliance has established strong foundations (policies, processes, certification workflows) so you'll be inheriting a solid base and taking it further as we scale. If you're also a qualified lawyer who can support commercial legal work (contracts, privacy, regulatory), even better. But the core of this role is compliance.

What You’ll Do

  • PCI DSS & Certification (Core)
    • Own Evervault's PCI DSS compliance program, maintaining our current certifications and preparing for future assessments.
    • Manage relationships with QSAs and auditors, coordinating evidence gathering and remediation across engineering and operations.
    • Stay ahead of PCI DSS updates (including v4.x requirements) and translate them into actionable engineering and process changes.
    • Own our compliance documentation: policies, procedures, and evidence repositories.
    • Support customers with compliance questions, SAQs, and due diligence requests.
  • Risk & Security Governance
    • Maintain and improve our information security policies and risk register.
    • Support SOC 2, ISO 27001, and other certifications as we scale upmarket.
    • Work with engineering to embed compliance into how we build, not bolt it on after.
  • Legal (Nice to Have)
    • Review and negotiate customer contracts, DPAs, and vendor agreements.
    • Advise on data protection (GDPR, international privacy frameworks).
    • Support regulatory analysis as we expand into new markets and verticals.

Who You Are

  • Deep PCI expertise. You know PCI DSS inside out. You've been through multiple assessment cycles, ideally as a QSA, ISA, or leading compliance at a PCI Level 1 service provider. You understand the standard, not just the checklist.
  • Technical fluency. You can talk to engineers about encryption, tokenization, key management, and network segmentation without needing everything translated. You don't need to write code, but you need to understand how systems work.
  • Ownership mindset. We have strong foundations in place. You'll need to maintain what works, improve what doesn't, and build what's missing as we scale into new markets and upmarket customers.
  • Clear communicator. You can explain compliance requirements to engineers, translate technical architecture to auditors, and brief the CEO on risk, all in the same day.
  • Pragmatic, not bureaucratic. You care about real security outcomes, not compliance theatre. You find the fastest path to compliance without slowing the business down.

Ideal Background

  • Qualified Security Assessor (QSA), strongly preferred.
  • Or: ISA‑certified, or 3+ years leading PCI DSS compliance at a Level 1 service provider or payment processor.
  • Experience with SOC 2, ISO 27001, or GDPR is a plus.
  • Legal qualification (solicitor, barrister, or equivalent) is a bonus, not a requirement.
  • Experience in a startup or high‑growth environment preferred.

Why Evervault

  • Compliance is the product, not a cost centre. Your work directly enables revenue.
  • Strong compliance foundations already in place. You won't be starting from scratch, but you will have real ownership and room to shape what comes next.
  • Small team, high trust, high ownership. Work alongside deeply technical engineers building some of the most security‑critical infrastructure in payments.
  • We are in office Tues‑>Thursday, Mondays & Fridays encouraged.
  • We are unable to offer sponsorship at this time.

Senior PCI Compliance & Risk Officer employer: Evervault Inc.

Evervault is an exceptional employer that prioritises compliance as a core aspect of its product, offering employees the unique opportunity to directly influence revenue through their work. With strong foundations already established in compliance and a culture that fosters high trust and ownership within a small, dedicated team, employees can expect meaningful growth opportunities while collaborating with highly technical engineers on critical security infrastructure. Located in a dynamic environment, Evervault encourages a flexible work schedule, promoting a healthy work-life balance.

Evervault Inc.

Contact Details:

Evervault Inc. Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior PCI Compliance & Risk Officer

Tip Number 1

Network like a pro! Reach out to folks in the compliance and risk space, especially those who work with PCI DSS. Attend industry events or webinars to meet potential colleagues and get your name out there.

Tip Number 2

Show off your expertise! Prepare to discuss your deep knowledge of PCI DSS during interviews. Be ready to share specific examples of how you've navigated compliance challenges in the past.

Tip Number 3

Don’t just apply anywhere—apply through our website! It shows you’re genuinely interested in Evervault and helps us see your application faster. Plus, it’s a great way to stand out from the crowd.

Tip Number 4

Be prepared for technical chats! Brush up on your understanding of encryption, tokenization, and key management. You’ll need to communicate effectively with engineers, so being fluent in their language is key.

We think you need these skills to ace Senior PCI Compliance & Risk Officer

PCI DSS Compliance
Risk Management
Information Security Policies
Technical Fluency in Encryption and Tokenization
Communication Skills
Project Management
Compliance Documentation Management

Some tips for your application 🫡

Show Off Your PCI Expertise:Make sure to highlight your deep understanding of PCI DSS in your application. We want to see that you know the ins and outs of compliance, not just the basics. Share specific examples of your experience with assessments and how you've navigated the complexities of PCI compliance.

Communicate Clearly:Since you'll be liaising with both technical teams and auditors, it's crucial to demonstrate your ability to communicate complex ideas simply. Use your application to showcase how you've successfully translated compliance requirements to different audiences in the past.

Emphasise Ownership Mindset:We love candidates who take ownership! In your application, talk about times when you've improved existing processes or built new ones from scratch. Show us that you're proactive and ready to take charge of our compliance programme as we scale.

Apply Through Our Website:Don't forget to apply through our website! It’s the best way for us to keep track of your application and ensure it gets the attention it deserves. Plus, it shows you're keen on joining our team at Evervault!

How to prepare for a job interview at Evervault Inc.

Know Your PCI DSS Inside Out

Make sure you’re well-versed in PCI DSS standards and recent updates, especially v4.x requirements. Be ready to discuss your past experiences with compliance assessments and how you've navigated challenges in previous roles.

Speak the Tech Language

Brush up on technical terms related to encryption, tokenization, and key management. You should be able to engage in conversations with engineers without needing everything explained. This will show that you can bridge the gap between compliance and technical teams.

Demonstrate Ownership Mindset

Prepare examples of how you've taken ownership in previous roles, particularly in maintaining and improving compliance processes. Highlight your ability to adapt and scale compliance functions as the company grows.

Communicate Clearly and Effectively

Practice explaining complex compliance concepts in simple terms. You might need to communicate with various stakeholders, from engineers to the CEO, so being able to tailor your message is key. Think of scenarios where you’ve successfully communicated compliance needs in the past.