Lead Info Security Analyst
We are seeking a seasoned Lead Information Security GRC Analyst to join an information security governance team within a highly regulated financial services environment. This role will lead governance, risk, compliance, and security control initiatives with a strong emphasis on PCI DSS v4.0, control effectiveness, audit and regulatory support, risk management, and executive-level reporting.
The ideal candidate will bring deep experience in information security governance, PCI compliance, security controls, risk management, and audit practices, along with the ability to communicate effectively with both technical teams and senior leadership.
Key Responsibilities
PCI DSS & Security Compliance
- Lead the design, implementation, and ongoing execution of an enterprise PCI DSS v4.0 program, including accurate Cardholder Data Environment (CDE) scoping and sustainable control implementation.
- Serve as a subject matter expert for PCI environments and drive cross-functional accountability for PCI requirements.
- Integrate PCI requirements into technology, security, and operational lifecycles.
- Lead PCI assessment and governance activities, including QSA engagement, remediation strategies, risk acceptance, and executive reporting.
- Develop and support security control effectiveness testing and provide recommendations for identified gaps and mitigation strategies.
- Design and implement security controls aligned with industry frameworks, including NIST CSF 2.0 and CIS Controls v8.
- Maintain centralized control traceability to regulatory requirements, policies, standards, and authoritative sources.
- Translate complex security, compliance, and risk information into clear communications for both technical and non-technical audiences.
Policy & Standards Management
- Ensure security policies and standards remain aligned with applicable financial services regulatory requirements and industry best practices.
- Lead policy governance processes, including stakeholder reviews, updates, approvals, and ongoing maintenance.
- Identify opportunities for proactive policy and standards improvements to support continuous compliance and program maturity.
Qualifications:
Required Qualifications
Education
- Bachelor's degree in Information Security, Computer Science, Risk Management, or a related field.
- Master's degree or MBA with a focus on Information Assurance, Cybersecurity, or Financial Risk Management preferred.
Experience
- 5–8 years of experience in Information Security Governance, Risk, and Compliance (GRC).
- Minimum 3 years of hands-on PCI DSS experience, preferably with PCI DSS v4.0.
- Experience working within a regulated financial services or banking environment.
- Strong understanding of banking regulatory requirements, information security controls, risk management, and industry frameworks.
- Experience with GRC platforms such as ServiceNow GRC, LogicGate, or similar solutions.
- Demonstrated experience supporting audits, regulatory examinations, control testing, remediation, and risk assessments.
- Strong executive communication, presentation, documentation, and stakeholder management skills.
Required Certification
At least one of the following certifications is required:
- CISSP – Certified Information Systems Security Professional
- CISM – Certified Information Security Manager
- CRISC – Certified in Risk and Information Systems Control
- CISA – Certified Information Systems Auditor
Ideal Candidate
The successful candidate is a strategic and hands-on GRC professional who can operate effectively across security, technology, risk, compliance, audit, and executive leadership teams. This individual should be comfortable owning PCI initiatives, challenging control effectiveness, identifying risk, driving remediation, and translating complex compliance requirements into practical business and technology solutions.
Compensation
$60.00-$70.00 HourlyAbout Us
Technology Doesn't Change the World, People Do.®
Robert Half is the world’s first and largest specialized talent solutions firm that connects highly qualified job seekers to opportunities at great companies. We offer contract, temporary and permanent placement solutions for finance and accounting, technology, marketing and creative, legal, and administrative and customer support roles.
Robert Half works to put you in the best position to succeed. We provide access to top jobs, competitive compensation and benefits, and free online training. Stay on top of every opportunity - whenever you choose - even on the go. Download the Robert Half app and get 1-tap apply, notifications of AI-matched jobs, and much more.
All applicants applying for U.S. job openings must be legally authorized to work in the United States. Benefits are available to contract/temporary professionals, including medical, vision, dental, and life and disability insurance. Hired contract/temporary professionals are also eligible to enroll in our company 401(k) plan. Visit roberthalf.gobenefits.net for more information.
© 2025 Robert Half. An Equal Opportunity Employer. M/F/Disability/Veterans. By clicking “Apply Now,” you’re agreeing to Robert Half’s Terms of Use and Privacy Notice.
