Commerce has been recognized on not just one… but SEVEN of Built In’s Best Places to Work 2026 lists!
Commerce Logo

Commerce

Senior Security GRC Analyst (PCI ISA Specialist)

Posted Yesterday
Be an Early Applicant
In-Office
Austin, TX
89K-150K Annually
Senior level
In-Office
Austin, TX
89K-150K Annually
Senior level
Lead the PCI DSS program, ensuring compliance integration into operations while supporting SOC2 and ISO 27001 audits, and provide continuous security assessments.
The summary above was generated by AI
Welcome to the Agentic Commerce Era

At Commerce, our mission is to empower businesses to innovate, grow, and thrive with our open, AI-driven commerce ecosystem. As the parent company of BigCommerce, Feedonomics, and Makeswift, we connect the tools and systems that power growth, enabling businesses to unlock the full potential of their data, deliver seamless and personalized experiences across every channel, and adapt swiftly to an ever-changing market. Simply said, we help businesses confidently solve complex commerce challenges so they can build smarter, adapt faster, and grow on their own terms. If you want to be part of a team of bold builders, sharp thinkers, and technical trailblazers, working together to shape the future of commerce, this is the place for you.

As a Senior Security GRC Analyst and Internal Security Assessor (ISA), you will serve as the primary Subject Matter Expert (SME) for our global PCI DSS program at Commerce. We operate a highly mature PCI DSS 4.0 environment; your mission is to lead the continuous evolution of this program, ensuring that compliance is integrated into our "business as usual" (BAU) operations.

While your primary focus is PCI, you will be a key player in our broader GRC function, supporting our SOC2 and ISO 27001 certifications. You will act as the technical bridge between our Engineering, Infrastructure, and IT teams and external auditors, ensuring that our high-security standards are documented, validated, and maintained.

What You'll Do:PCI SME & Internal Security Assessor (ISA)
  • ISA Leadership: Serve as the officially designated PCI ISA for the organization. Manage the annual assessment lifecycle, including scoping, evidence collection, and validation of controls.

  • PCI 4.0 Evolution: Direct the ongoing maintenance of our PCI 4.0 program, with a specific focus on managing Targeted Risk Analyses (TRAs) and the customized approach where applicable.

  • Scoping & Segmentation: Partner with Cloud Engineering to validate PCI scope across our global footprint, ensuring effective network segmentation and data flow isolation.

  • QSA Liaison: Act as the primary point of contact for our external QSA, defending our control environment and streamlining the audit process to minimize disruption to technical teams.

  • Continuous Compliance: Operationalize PCI requirements (e.g., quarterly scans, penetration test remediation) into automated workflows.

Multi-Framework Audit Management
  • Unified Control Framework: Support the broader GRC team in managing our SOC2 Type 2, ISO 27001, and other regulatory audits (as seen on https://www.google.com/search?q=security.commerce.com).

  • Technical Advisory: Provide GRC perspective on architectural designs, product launches, and infrastructure changes to ensure "compliance by design."

  • Remediation Management: Track and drive the remediation of audit findings and security gaps, working closely with asset owners to find pragmatic, secure solutions.

Who You Are:
  • Experience: 6+ years in an Information Security or IT Audit role, with at least 3 years of deep focus on PCI DSS within a major cloud-native environment.

  • Certification: Active PCI ISA (Internal Security Assessor) or PCI QSA certification is mandatory.

  • Regulatory Expertise: Thorough understanding of PCI DSS 4.0 requirements and the practical application of the standard in modern environments.

  • Audit Fluency: Proven experience leading Level 1 Service Provider assessments.

  • Communication: Ability to explain complex compliance requirements to developers and business leaders in a way that emphasizes enablement rather than "blockage."

Preferred Qualifications
  • Broad Framework Knowledge: Experience with SOC2 and ISO 27001:2022.

  • Cloud Security: Experience with GRC automation and familiarity with modern cloud-native security and observability tools.

  • Automation Mindset: Experience using GRC platforms and a desire to automate manual evidence collection to reduce audit fatigue.

About You
  • You understand the "Why": You don't just "do compliance"; you understand the security intent behind every control and can help teams meet the requirement in a way that actually improves our security posture.

  • Technical Curiosity: You are comfortable diving into technical configurations (IAM policies, VPC flow logs, etc.) to verify control effectiveness yourself.

  • Adaptable: You enjoy the challenge of a high-paced environment where scale and security must coexist and evolve together.

#LI-KE1

#LIHYBRID

(Pay Transparency Range: $88,951.00 - $150,432.00)

The exact salary will be dependent on the successful candidate’s location, relevant knowledge, skills, and qualifications.

Inclusion and Belonging

At Commerce, we believe that celebrating the unique histories, perspectives and abilities of every employee makes a difference for our company, our customers and our community. We are an equal opportunity employer and the inclusive atmosphere we build together will make room for every person to contribute, grow and thrive.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the interview process, to perform essential job functions and to receive other benefits and privileges of employment. If you need an accommodation in order to interview at Commerce, please let us know during any of your interactions with our recruiting team.

Learn more about the Commerce team, culture and benefits at https://www.commerce.com/careers/

Protect Yourself Against Hiring Scams: Our Corporate Disclaimer 

Commerce, along with many other employers, has become the subject of fraudulent job offers to hopeful prospective job seekers.
Be advised:
Commerce does not offer jobs to individuals who do not go through our formal hiring process.
Commerce will never:

  • require payment of recruitment fees from candidates;

  • request personally identifiable information through unsanctioned websites or applications;

  • attempt to solicit money from you as part of the hiring process or as part of an employment offer;

  • solicit money to complete visa requirements as part of a job offer.

If you receive unsolicited offers of employment from Commerce, we urge you to be extremely cautious and avoid engaging or responding.

Top Skills

Cloud Security
Grc Platforms
Iso 27001
Pci Dss
Soc2

Similar Jobs at Commerce

Yesterday
In-Office
Austin, TX, USA
60K-90K Annually
Mid level
60K-90K Annually
Mid level
Artificial Intelligence • Cloud • Consumer Web • eCommerce • Information Technology • Software
The Legal Analyst will support commercial contracting, project management, legal operations, and litigation tasks while leveraging AI tools to streamline processes.
Top Skills: ChatgptClaudeDocusignGeminiGoogle WorkspaceIroncladMS OfficeSalesforce
7 Days Ago
In-Office
Austin, TX, USA
160K-240K Annually
Expert/Leader
160K-240K Annually
Expert/Leader
Artificial Intelligence • Cloud • Consumer Web • eCommerce • Information Technology • Software
The Director of Total Rewards leads global compensation and benefits strategy, ensuring alignment with business goals and market competitiveness while overseeing a team and innovative programs that enhance employee experience.
Top Skills: ExcelMarket Pricing ToolsWorkday Advanced Compensation
7 Days Ago
In-Office
Austin, TX, USA
134K-201K Annually
Senior level
134K-201K Annually
Senior level
Artificial Intelligence • Cloud • Consumer Web • eCommerce • Information Technology • Software
The Senior Manager, Strategic Purchasing at BigCommerce will drive procurement strategies, manage supplier relationships, negotiate contracts, and improve cost efficiencies while collaborating with internal stakeholders.
Top Skills: ExcelPowerPointWord

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account