Tech Stack
Cloud LoggingAWSCloud Monitoring
Job Description, Responsibilities & Requirements
Description language:
About the Position
Information Security Specialist for our partner Paysation.
Paysation is a product company that develops its own payment gateway and anti-fraud solutions for e-commerce. The company works with clients in the markets of Europe and the USA.
We are looking for a specialist who will become a key expert in the field of information security and compliance with PCI DSS requirements, help build and improve security processes, and develop this direction within the company.
Responsibilities
- Ensuring the company's compliance with PCI DSS requirements;
- Defining and maintaining the boundaries of the Cardholder Data Environment (CDE);
- Preparing the company for PCI DSS audits and interacting with QSA;
- Developing, implementing, and updating information security policies;
- Building information security monitoring processes;
- Organizing and controlling security scans;
- Managing vulnerabilities and controlling their remediation;
- Conducting risk assessments and gap analysis;
- Developing and maintaining an information security incident response plan, particularly related to the compromise of payment data;
- Analyzing architectural solutions from a security perspective;
- Collaborating with DevOps and Engineering teams to integrate security requirements into the infrastructure;
- Interacting with external auditors and certification bodies;
- Conducting internal consultations or training on information security as needed.
Requirements
- 4+ years of experience in Information Security;
- Practical experience with PCI DSS requirements;
- Deep understanding of information security principles: IAM, encryption, key management, network segmentation, logging, monitoring;
- Experience with cloud infrastructure (AWS is a plus);
- Experience in risk management, vulnerabilities, and incident response;
- Understanding of ISO 27001, SOC 2, NIST standards is a plus;
- Ability to transform standard requirements into practical processes, documentation, and internal policies.
Nice to Have
- Certifications in information security: CISSP, CISM, PCI ISA/PCIP, or equivalent;
- Experience in the payments/fintech or other regulated industries;
- Practical experience with Infrastructure as Code and ensuring the security of CI/CD (policy-as-code, IaC scanning, secrets management);
- Experience in threat modeling and implementing Secure SDLC practices;
- Scripting skills (Python/Bash) for automating compliance evidence collection and verification.
We Offer
- The opportunity to become a key Information Security expert and influence the development of the security direction in the company;
- Paid vacation and sick leave;
- 50% compensation for foreign language courses, sports, psychological consultations, and health insurance;
- Work format at the candidate's choice: remote, hybrid, on-site (the office is located in Kyiv).
Hi! My name is Yana, and I'm always open to new acquaintances. I'll be happy to help you find the job that inspires and motivates you every day.
@recruiter_jana
Show email
Send your resume