PCI Assurance Analyst

PCI Assurance Analyst

Full-Time 50000 - 60000 £ / year (est.) No working from home possible
S

At a Glance

  • Tasks: Ensure compliance with PCI DSS and protect cardholder data across people, processes, and technology.
  • Company: Join a leading firm in IT security and compliance based in London or Leicester.
  • Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
  • Other info: Collaborative environment with a focus on compliance culture and career advancement.
  • Why this job: Be the expert in PCI compliance and make a real difference in data security.
  • Qualifications: Experience in Information Security Governance and strong knowledge of PCI DSS required.

The predicted salary is between 50000 - 60000 £ per year.

Reporting to the IT Security and IT GRC Manager, the PCI Assurance Analyst acts as our Payment Card Industry Data Security Standard (PCI DSS) subject matter expert and lead for the PCI-DSS compliance process. Our PCI Assurance Analyst is responsible for ensuring compliance with the PCI DSS by assessing, validating, and evidencing how cardholder data is protected across people, processes and technology. The role involves interpreting PCI requirements, conducting control assessments and gap analyses, coordinating self-assessments or external audits, reviewing technical and procedural evidence and working closely with IT, security, and business teams to remediate compliance gaps. Our PCI Assurance Analyst also maintains compliance documentation, tracks remediation plans, supports Qualified Security Assessor (QSA) engagements, and provides clear assurance reporting to stakeholders, helping reduce regulatory, financial, and reputational risk associated with payment card data. The role can be based in either London or Leicester.

Role responsibilities

  • Interpret and apply PCI DSS requirements to our payment card environment across people, process, and technology.
  • Perform PCI DSS gap assessments against current controls and identify areas of non‑compliance or control weakness.
  • Coordinate and manage PCI compliance activities including Self‑Assessment Questionnaires (SAQs), Attestations of Compliance (AOC), and annual validation cycles.
  • Collect, review and validate evidence.
  • Act as the primary liaison with Qualified Security Assessors (QSAs), acquirers, and payment brands during audits and assessments.
  • Track and support remediation plans, ensuring issues are clearly documented, risk‑assessed, prioritised, and resolved.
  • Maintain accurate PCI documentation, including scoping diagrams, risk assessments, policies, and procedures.
  • Support PCI scoping decisions, ensuring only necessary systems are in scope and controls are applied appropriately.
  • Provide assurance reporting to senior management on compliance status, risks, exceptions, and audit readiness.
  • Advise delivery teams on secure design and change impacts related to PCI‑scoped systems.
  • Monitor changes to the PCI DSS standard and assess their impact on existing controls and future compliance obligations.
  • Promote a strong compliance and security culture through guidance, education, and pragmatic risk‑based advice.

Skills & Experience:

  • Experience as an Information Security Governance Analyst is necessary for this role.
  • Strong working knowledge of PCI DSS (scoping, requirements, validation methods, evidence expectations).
  • Ability to interpret control intent and apply it pragmatically in real environments.
  • Understanding of risk‑based assurance and control effectiveness.
  • General understanding of IT infrastructure, cloud services, networks, and payment environments, including POS, ecommerce platforms, payment gateways, tokenisation, and third‑party service providers.
  • Ability to read and critique technical evidence (e.g. firewall rules, vulnerability scans, access logs).
  • Experience performing gap analyses, control testing, and evidence reviews.
  • Strong attention to detail with the ability to spot control weaknesses.
  • Ability to work effectively with IT, Security, POS, Infrastructure, DevOps.
  • Confident communicator who can explain compliance requirements to non‑specialists.
  • Capable of producing clear assurance reporting for senior stakeholders.
  • Experience working in PCI DSS compliance, IT security assurance, audit, GRC, or PCI Professional (PCIP) (highly desirable).
  • ISO 27001 foundation / lead implementer / lead auditor.
  • CISM, CISSP, CRISC, or similar (beneficial, not always required).

PCI Assurance Analyst employer: Selfridges & Co.

Selfridges & Co is an exceptional employer that values leadership and service excellence, offering a dynamic work environment in the heart of London. Employees benefit from a strong culture of collaboration, opportunities for professional growth, and the chance to be part of a prestigious brand known for its commitment to quality and customer satisfaction. With a focus on employee development and a vibrant workplace, Selfridges provides a rewarding experience for those looking to make a meaningful impact in retail.

S

Contact Details:

Selfridges & Co. Recruitment Team

We think you need these skills to ace PCI Assurance Analyst

PCI DSS
Control Assessments
Gap Analyses
Self-Assessment Questionnaires (SAQs)
Attestations of Compliance (AOC)
Qualified Security Assessor (QSA) Engagements
Risk Assessments