
201 - 500 employees
Founded 2021
💼 Consulting
👥 HR Tech
🎯 Recruiter
Consulting • HR Tech • Recruitment
Teamified is a global talent powerhouse that specializes in connecting businesses to offshore talent. They offer a comprehensive platform that simplifies the hiring process by providing access to a diverse range of skilled professionals from multiple industries. With a focus on data security and a people-first approach, Teamified aims to reduce hiring times and costs while ensuring high-quality talent matches for organizations.
🔥 0 minutes ago
🇵🇭 Philippines – Remote
⏳ Contract/Temporary
🟡 Mid-level
🟠 Senior
🛡️ Security Operations
👻 Ghost score 13%
Improve your chances of getting an interview by checking your resume score before you apply.

201 - 500 employees
Founded 2021
💼 Consulting
👥 HR Tech
🎯 Recruiter
Consulting • HR Tech • Recruitment
Teamified is a global talent powerhouse that specializes in connecting businesses to offshore talent. They offer a comprehensive platform that simplifies the hiring process by providing access to a diverse range of skilled professionals from multiple industries. With a focus on data security and a people-first approach, Teamified aims to reduce hiring times and costs while ensuring high-quality talent matches for organizations.
• Implement and verify technical controls across the cardholder data environment, including access management, secure configuration, logging and monitoring, vulnerability management, encryption and key management, and secure development practices. • Implement PCI DSS v4.0.1 logging and monitoring requirements, including centralised audit-log collection, log protection, retention, automated log review, time synchronisation, critical-file change detection, and failure alerting. • Work alongside the client's DevOps engineer on rollout of Wazuh, owning compliance outcomes, required log-source coverage, detection and correlation rules, file-integrity monitoring, retention, validation, and evidence. • Define the alert triage and response routine for the client team. • Complete SAQ D for Service Providers and assemble supporting evidence. • Maintain network and cardholder dataflow diagrams, scoping and segmentation documentation, policies, and operating procedures. • Engage and manage an Approved Scanning Vendor for quarterly external vulnerability scanning and drive remediation to passing scans. • Scope and coordinate penetration testing with a qualified independent provider; manage remediation and retesting. • Maintain third-party service-provider due diligence, including partner AOC collection and shared-responsibility documentation. • Own the delivery plan, schedule, dependencies, risk log, and weekly leadership reporting. • Strengthen change-management practices so changes are raised, approved, tested, and evidenced consistently. • Document repeatable operational routines for the client team after the engagement ends. • Run the annual PCI DSS compliance cycle to completion during a three-month contract and prepare the Attestation of Compliance for executive sign-off.
• Demonstrable experience taking an organisation through PCI DSS compliance, ideally more than once and ideally including v4.x. • Working knowledge of PCI DSS v4.0.1, including the changes from v3.2.1 and the requirements mandatory from 31 March 2025. • Direct experience completing SAQ D, or preparing evidence for a Report on Compliance. • Hands-on AWS security engineering: IAM policy design, VPC and network segmentation, audit logging, secrets and key management, and infrastructure-as-code. • Equivalent depth in another major public cloud will be considered where the candidate can demonstrate transferable design judgement. • Hands-on experience with SIEM or centralised log platforms in a compliance context, including log source onboarding, parsing and normalisation, correlation and alert rule development, file integrity monitoring, retention configuration, and tuning to reduce false positives. • Direct Wazuh experience is a strong advantage; equivalent open-source stacks (OSSEC, Elastic Security, Graylog, Security Onion) are acceptable. • Ability to name platforms worked with and describe what was configured, not only what was monitored. • Practical experience in vulnerability management, logging and monitoring, access management and secure configuration baselines. • Ability to independently plan, track, report and escalate; no project manager will be assigned. • Excellent written English. • Willingness to record a control as not in place where that is the accurate position. • Payments, fintech or regulated financial services background is desirable. • Understanding of the acquirer, processor and card scheme landscape is desirable. • Experience of Level 1 service provider validation, or taking an organisation from self-assessment to QSA-led assessment, is desirable. • PCIP, ISA, CISSP, CISM or equivalent certification is desirable. • Jira administration and workflow configuration is desirable. • Familiarity with ISO 27001 or SOC 2 is desirable.
• Flexibility in work hours and location, with a focus on managing energy rather than time. • Access to online learning platforms and a budget for professional development • A collaborative, no-silos environment, encouraging learning and growth across teams • A dynamic social culture with team lunches, social events, and opportunities for creative input • Leave Benefits
Apply Now