At a Glance
- Tasks: Own PCI DSS compliance and enhance Evervault's compliance and risk function.
- Company: Join a cutting-edge encryption and data security company.
- Benefits: Competitive salary, flexible work environment, and opportunities for professional growth.
- Other info: Be part of a small, high-trust team with significant ownership.
- Why this job: Make a real impact on data security while working with top-tier engineers.
- Qualifications: Deep PCI expertise and technical fluency in compliance processes.
The predicted salary is between 36000 - 60000 £ per year.
Evervault builds encryption and data security infrastructure for developers. APIs and primitives for tokenizing, encrypting, and processing sensitive data at scale, currently focused on powering the payments stack for companies like Rippling, Ramp, and Sorare.
Compliance is core to what we sell. Our customers trust us with their most sensitive data (card numbers, credentials, PII) and they need to know we meet the highest security and compliance standards in the industry. We are looking for a Legal & Compliance Officer to own PCI DSS compliance end-to-end and continue building Evervault's compliance and risk function. Our outgoing Head of Compliance has established strong foundations (policies, processes, certification workflows) so you will be inheriting a solid base and taking it further as we scale. If you are also a qualified lawyer who can support commercial legal work (contracts, privacy, regulatory), even better. But the core of this role is compliance.
What You’ll Do
- PCI DSS & Certification (Core)
- Own Evervault's PCI DSS compliance program, maintaining our current certifications and preparing for future assessments.
- Manage relationships with QSAs and auditors, coordinating evidence gathering and remediation across engineering and operations.
- Stay ahead of PCI DSS updates (including v4.x requirements) and translate them into actionable engineering and process changes.
- Own our compliance documentation: policies, procedures, and evidence repositories.
- Support customers with compliance questions, SAQs, and due diligence requests.
- Risk & Security Governance
- Maintain and improve our information security policies and risk register.
- Support SOC 2, ISO 27001, and other certifications as we scale upmarket.
- Work with engineering to embed compliance into how we build, not bolt it on after.
- Legal (Nice to Have)
- Review and negotiate customer contracts, DPAs, and vendor agreements.
- Advise on data protection (GDPR, international privacy frameworks).
- Support regulatory analysis as we expand into new markets and verticals.
Who You Are
- Deep PCI expertise. You know PCI DSS inside out. You have been through multiple assessment cycles, ideally as a QSA, ISA, or leading compliance at a PCI Level 1 service provider. You understand the standard, not just the checklist.
- Technical fluency. You can talk to engineers about encryption, tokenization, key management, and network segmentation without needing everything translated. You don’t need to write code, but you need to understand how systems work.
- Ownership mindset. We have strong foundations in place. You will need to maintain what works, improve what doesn’t, and build what’s missing as we scale into new markets and upmarket customers.
- Clear communicator. You can explain compliance requirements to engineers, translate technical architecture to auditors, and brief the CEO on risk, all in the same day.
- Pragmatic, not bureaucratic. You care about real security outcomes, not compliance theatre. You find the fastest path to compliance without slowing the business down.
Ideal Background
- Qualified Security Assessor (QSA), strongly preferred.
- Or: ISA-certified, or 3+ years leading PCI DSS compliance at a Level 1 service provider or payment processor.
- Experience with SOC 2, ISO 27001, or GDPR is a plus.
- Legal qualification (solicitor, barrister, or equivalent) is a bonus, not a requirement.
- Experience in a startup or high-growth environment preferred.
Why Evervault
- Compliance is the product, not a cost centre. Your work directly enables revenue.
- Strong compliance foundations already in place. You won’t be starting from scratch, but you will have real ownership and room to shape what comes next.
- Small team, high trust, high ownership. Work alongside deeply technical engineers building some of the most security-critical infrastructure in payments.
- We are in office Tues->Thursday, Mondays & Fridays encouraged.
- We are unable to offer sponsorship at this time.
Legal & PCI Compliance Officer employer: Evervault
Evervault is an exceptional employer that prioritises compliance as a core aspect of its product, offering employees the unique opportunity to directly influence revenue through their work. With strong foundations already established in compliance and a culture that fosters high trust and ownership within a small, technical team, employees can expect meaningful growth opportunities while contributing to critical infrastructure in the payments sector. The hybrid work model encourages collaboration and flexibility, making it an attractive workplace for those seeking impactful and rewarding careers.
StudySmarter Expert Advice🤫
We think this is how you could land Legal & PCI Compliance Officer
✨Tip Number 1
Network like a pro! Reach out to folks in the compliance and legal fields on LinkedIn or at industry events. A friendly chat can lead to opportunities that aren’t even advertised yet.
✨Tip Number 2
Show off your expertise! Prepare a portfolio or a presentation that highlights your PCI DSS experience and any successful compliance projects you've led. This will set you apart during interviews.
✨Tip Number 3
Practice makes perfect! Mock interviews with friends or mentors can help you articulate your thoughts clearly. Focus on how you can add value to Evervault’s compliance journey.
✨Tip Number 4
Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining the Evervault team.
We think you need these skills to ace Legal & PCI Compliance Officer
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the role of Legal & PCI Compliance Officer. Highlight your experience with PCI DSS compliance and any relevant legal qualifications. We want to see how your background aligns with our needs!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about compliance and how you can contribute to Evervault's mission. Be sure to mention any specific experiences that relate to the job description.
Showcase Your Technical Fluency:Since this role involves working closely with engineers, make sure to highlight your technical understanding of encryption, tokenization, and other relevant concepts. We want to know you can communicate effectively across teams!
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen on joining our team!
How to prepare for a job interview at Evervault
✨Know Your PCI DSS Inside Out
Make sure you’re well-versed in PCI DSS standards and can discuss them confidently. Brush up on the latest updates, especially v4.x requirements, so you can demonstrate your expertise and readiness to own Evervault's compliance programme.
✨Show Your Technical Fluency
Be prepared to engage in technical discussions about encryption, tokenization, and key management. You don’t need to code, but understanding how these systems work will help you communicate effectively with the engineering team.
✨Demonstrate Ownership Mindset
Highlight your experience in maintaining and improving compliance frameworks. Share examples of how you've taken initiative in previous roles to enhance compliance processes or adapt to new regulations, showing that you can build on the strong foundations already in place.
✨Communicate Clearly and Pragmatically
Practice explaining complex compliance requirements in simple terms. Be ready to discuss how you would translate technical architecture for auditors and brief executives on risk, all while keeping a focus on achieving real security outcomes without unnecessary bureaucracy.