Skip to main content
Posted August 29, 2026
Robert Half

Lead GRC Security Analyst

Appleton, WI 53562, US Remote Temporary
Compensation: $50 to $65 Hourly

We are seeking an experienced Information Security GRC professional with strong PCI DSS expertise to lead the design, implementation, and ongoing execution of an enterprise PCI DSS v4.0 compliance program within a highly regulated environment.

This role will serve as the organization’s PCI subject matter expert (SME), responsible for ensuring accurate Cardholder Data Environment (CDE) scoping, sustainable control implementation, continuous compliance, and effective governance. The successful candidate will work cross-functionally with Security, IT, Risk, Compliance, Audit, and business stakeholders to embed PCI requirements into technology and operational processes.

This is a highly visible role requiring someone who can operate strategically while also being comfortable getting into the details of controls, evidence, assessments, remediation, and audit readiness.

Key Responsibilities

  • Lead the enterprise PCI DSS v4.0 program, including governance, compliance, assessment, and continuous improvement activities.
  • Validate and maintain accurate Cardholder Data Environment (CDE) scope.
  • Serve as the primary PCI DSS subject matter expert across the organization.
  • Partner with Security, IT, Risk, Compliance, Audit, and business teams to drive cross-functional accountability for PCI requirements.
  • Manage relationships with Qualified Security Assessors (QSAs) and coordinate PCI assessments from preparation through remediation and closure.
  • Develop and manage remediation strategies for PCI and security control gaps.
  • Support risk acceptance processes and ensure appropriate documentation and governance.
  • Test and evaluate control effectiveness and maintain clear control traceability.
  • Manage evidence collection, assessment walkthroughs, findings, remediation, and closure activities.
  • Support internal and external audits as well as regulatory examinations.
  • Conduct security risk and control assessments.
  • Develop and report KRIs, KPIs, OKRs, and other security/compliance metrics.
  • Present security, risk, and control findings to both technical stakeholders and executive leadership.
  • Lead reviews, updates, and approvals of security policies, standards, and related governance documentation.
  • Embed PCI requirements into technology and operational lifecycles.
  • Drive ongoing improvements to the organization’s security compliance and risk management processes.

Technical Environment

  • PCI DSS v4.0
  • Information Security Governance, Risk & Compliance (GRC)
  • ServiceNow, LogicGate, Archer, or similar GRC platforms
  • NIST Cybersecurity Framework (CSF) 2.0
  • CIS Controls v8
  • Security controls and compliance management
  • Risk assessments
  • Audit management
  • Policy and standards governance
  • Regulatory compliance and examination support

Qualifications:

Required Qualifications

  • 5–8 years of experience in Information Security GRC, with at least 3 years of hands-on PCI DSS experience.
  • Demonstrated experience owning or leading an enterprise PCI DSS program.
  • Strong experience with CDE scoping and PCI DSS control requirements.
  • Experience managing QSA relationships and leading PCI assessments through preparation, assessment, remediation, and closure.
  • Experience with GRC platforms such as ServiceNow, LogicGate, Archer, or similar.
  • Experience supporting internal/external audits, regulatory examinations, evidence collection, and remediation.
  • Working knowledge of NIST CSF 2.0 and CIS Controls v8, including the ability to map controls across security and compliance frameworks.
  • Experience developing and presenting KRIs, KPIs, OKRs, and security/risk metrics.
  • Strong communication skills with the ability to explain complex PCI and security control gaps to non-technical audiences and executive leadership.
  • Bachelor’s degree in Information Security, Computer Science, Risk Management, or a related field.



Compensation

$50.00-$65.00 Hourly

About Us

Technology Doesn't Change the World, People Do.®

Robert Half is the world’s first and largest specialized talent solutions firm that connects highly qualified job seekers to opportunities at great companies. We offer contract, temporary and permanent placement solutions for finance and accounting, technology, marketing and creative, legal, and administrative and customer support roles.

Robert Half works to put you in the best position to succeed. We provide access to top jobs, competitive compensation and benefits, and free online training. Stay on top of every opportunity - whenever you choose - even on the go. Download the Robert Half app and get 1-tap apply, notifications of AI-matched jobs, and much more.

All applicants applying for U.S. job openings must be legally authorized to work in the United States. Benefits are available to contract/temporary professionals, including medical, vision, dental, and life and disability insurance. Hired contract/temporary professionals are also eligible to enroll in our company 401(k) plan. Visit roberthalf.gobenefits.net for more information.

© 2025 Robert Half. An Equal Opportunity Employer. M/F/Disability/Veterans. By clicking “Apply Now,” you’re agreeing to Robert Half’s Terms of Use and Privacy Notice.

Sign up for Job Alerts