Security Compliance Manager - PCI DSS specialist
Security Compliance Manger - PCI DSS Specialist
Location
Birmingham, London, Reading
Job Family
Corporate Functions
Job Type
Full Time
Posted Date
23-Feb-2026
#
71954
Are you the kind of person who spots a misplaced data packet the way others spot typos? Do you get a tiny spark of joy from a perfectly documented process or a beautifully segmented network diagram? If so… we should definitely talk.
As our Security Compliance Manager, you’ll be the guardian of our most prized digital treasure, our information assets and payment environments. Think of yourself as the protector of our Cardholder Data Kingdom: part detective, part strategist, part compliance wizard!
Your mission? To make sure our organisation not only meets PCI DSS v4.01 standards but absolutely nails them, with robust controls, airtight evidence, and a compliance rhythm smoother than a freshly patched server.
You’ll be the go-to expert on all things PCI, orchestrating assessments, guiding teams, taming audit chaos, charming QSAs, decoding vulnerabilities, and making sure our controls not only exist but actually work. And because your superpowers extend beyond PCI, you’ll also help steer ISO
27001, support our security accreditations, and champion continuous improvement across our security ecosystem.
If you love diving into detail, shaping best practice, keeping systems honest, and sleeping soundly knowing you’ve prevented chaos before it even thought about happening, this is your kind of playground!
Who we areThe UK’s fastest broadband network. The nation’s best-loved mobile brand. And, one of the UK's biggest companies too. We put our customers first, making life simpler, smoother, and more joyful. With big ambitions and a brilliant team, we’re building a more connected future for everyone.
Our ways of workingWe’re a flexible-first organisation, because we know people do their best work when they have choice and clarity. To support meaningful collaboration, we ask everyone to spend at least eight days each month connecting in person.
That doesn’t just mean time in the office, it could be team meetings, offsites, volunteering days, multi-functional projects, or away days - anywhere meaningful collaboration happens. What matters is making those moments purposeful, so when we come together, it really counts.
Accessible, inclusive and equitable for allVirgin Media O2 is an
equal opportunities
employer, and we're working hard to remove bias and barriers for our people and candidates. So, we build equity and inclusion into everything we do, from the policies we craft to the relationships we shape. We support and encourage you to be your authentic self throughout your application journey with us.
In order to be considered, you must have the following experience;
- Proven hands-on experience supporting PCI DSS assessments, including full ROC activity and assessor engagement.
- Deep, practical understanding of PCI DSS v4.01 requirements, their intent, and how they apply within real-world payment environments.
- Good ability to interpret, validate, and map both technical and procedural controls to PCI obligations.
- A demonstrated ability in information security, governance, risk, or compliance roles.
- Solid experience operating and maintaining controls aligned to frameworks such as ISO 27001 and Cyber Essentials.
- Demonstrated ability to deliver or support internal and external audits, ensuring clear evidence, accurate reporting, and timely follow‑up on findings.
- Robust knowledge of network security and segmentation, with practical experience applying secure design principles.
- Good understanding of operating system and application hardening, following industry benchmarks and practice standards.
- Confident knowledge of encryption and key management, including secure handling processes and lifecycle controls.
- Good grasp of identity and access management, covering authentication, access control models, and privileged access practices.
- Good working knowledge of risk management principles, with the ability to identify, assess, prioritise, and support remediation of security risks.
We'd also love you to bring;
- Builds strong, collaborative…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: