PCI Assurance Analyst in City of Westminster

PCI Assurance Analyst in City of Westminster

City of Westminster Full-Time 50000 - 65000 £ / year (est.) Home office (partial)
S

At a Glance

  • Tasks: Ensure compliance with PCI DSS and protect cardholder data across processes and technology.
  • Company: Join a leading firm in IT security and compliance based in London or Leicester.
  • Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
  • Other info: Collaborative environment with a focus on compliance culture and career advancement.
  • Why this job: Be the expert in PCI compliance and make a real difference in data security.
  • Qualifications: Experience in information security governance and strong knowledge of PCI DSS required.

The predicted salary is between 50000 - 65000 £ per year.

Reporting to the IT Security and IT GRC Manager, the PCI Assurance Analyst acts as our Payment Card Industry Data Security Standard (PCI DSS) subject matter expert and lead for the PCI-DSS compliance process.

Our PCI Assurance Analyst is responsible for ensuring compliance with the PCI DSS by assessing, validating, and evidencing how cardholder data is protected across people, processes, and technology. The role involves interpreting PCI requirements, conducting control assessments and gap analyses, coordinating self-assessments or external audits, reviewing technical and procedural evidence, and working closely with IT, security, and business teams to remediate compliance gaps. Our PCI Assurance Analyst also maintains compliance documentation, tracks remediation plans, supports Qualified Security Assessor (QSA) engagements, and provides clear assurance reporting to stakeholders, helping reduce regulatory, financial, and reputational risk associated with payment card data. The role can be based in either London or Leicester.

Role responsibilities:

  • Interpret and apply PCI DSS requirements to our payment card environment across people, process, and technology.
  • Perform PCI DSS gap assessments against current controls and identify areas of non-compliance or control weakness.
  • Coordinate and manage PCI compliance activities including Self-Assessment Questionnaires (SAQs), Attestations of Compliance (AOC), and annual validation cycles.
  • Collect, review and validate evidence.
  • Act as the primary liaison with Qualified Security Assessors (QSAs), acquirers, and payment brands during audits and assessments.
  • Track and support remediation plans, ensuring issues are clearly documented, risk-assessed, prioritised, and resolved.
  • Maintain accurate PCI documentation, including scoping diagrams, risk assessments, policies, and procedures.
  • Support PCI scoping decisions, ensuring only necessary systems are in scope and controls are applied appropriately.
  • Provide assurance reporting to senior management on compliance status, risks, exceptions, and audit readiness.
  • Advise delivery teams on secure design and change impacts related to PCI-scoped systems.
  • Monitor changes to the PCI DSS standard and assess their impact on existing controls and future compliance obligations.
  • Promote a strong compliance and security culture through guidance, education, and pragmatic risk-based advice.

Skills & Experience:

  • Experience as an Information Security Governance Analyst is necessary for this role.
  • Strong working knowledge of PCI DSS (scoping, requirements, validation methods, evidence expectations).
  • Ability to interpret control intent and apply it pragmatically in real environments.
  • Understanding of risk-based assurance and control effectiveness.
  • General understanding of IT infrastructure, cloud services, networks.
  • Familiarity with payment environments, including POS, ecommerce platforms, payment gateways, tokenisation, and third-party service providers.
  • Ability to read and critique technical evidence (e.g. firewall rules, vulnerability scans, access logs).
  • Experience performing gap analyses, control testing, and evidence reviews.
  • Strong attention to detail with the ability to spot control weaknesses.
  • Ability to work effectively with IT, Security, POS, Infrastructure, DevOps.
  • Confident communicator who can explain compliance requirements to non-specialists.
  • Capable of producing clear assurance reporting for senior stakeholders.
  • Experience working in PCI DSS compliance, IT security assurance, audit, GRC.
  • PCI Professional (PCIP) (highly desirable).
  • ISO 27001 foundation / lead implementer / lead auditor.
  • CISM, CISSP, CRISC, or similar (beneficial, not always required).

PCI Assurance Analyst in City of Westminster employer: Selfridges & Co.

Selfridges & Co is an exceptional employer that values leadership and service excellence, offering a dynamic work environment in the heart of London. Employees benefit from a strong culture of collaboration, opportunities for professional growth, and the chance to be part of a prestigious brand known for its commitment to quality and customer satisfaction. With a focus on employee development and a vibrant workplace, Selfridges provides a rewarding experience for those looking to make a meaningful impact in retail.

S

Contact Details:

Selfridges & Co. Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land PCI Assurance Analyst in City of Westminster

Join Compliance Communities

Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!

Attend Industry Conferences

Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.

Leverage Your University Career Services

If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.

Showcase Your Knowledge Online

Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like Selfridges & Co. looking for candidates who are engaged and informed.

We think you need these skills to ace PCI Assurance Analyst in City of Westminster

PCI DSS
Information Security Governance
Control Assessments
Gap Analyses
Self-Assessment Questionnaires (SAQs)
Attestations of Compliance (AOC)
Risk Assessment

Some tips for your application 🫡

Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!

Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.

Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!

Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at Selfridges & Co.. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!

How to prepare for a job interview at Selfridges & Co.

Master the Regulations

Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!

Show Your Analytical Skills

Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!

Know Your Tools

Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!

Align with Company Culture

Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with Selfridges & Co.’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!