Principal Consultant - GRC Compliance - PCI
Listed on 2026-03-13
-
IT/Tech
Cybersecurity, Information Security
Principal Consultant - GRC Compliance - PCI
Seattle, WA
ABOUT KALLES GROUP:
Everyone deserves to be secure. Our mission at Kalles Group is to help secure the future for companies of all shapes and sizes.
While our expertise spans multiple disciplines, our method remains consistent: building trust and relationship with people -- whether you are a client, a consultant, or--in this case--a candidate.
No matter what role you come from--whether you're an executive or just starting your career-you can expect our highest level of attention and respect. We want to find the right fit for each role, but we also want you to find the right fit for your career.
We believe the best way to show you what our team is like is to treat you like you're already a part of it
. We hope you'll consider joining our team of experienced professionals who are building their careers at Kalles Group—and having fun while doing it.
THIS ROLE IS ON-SITE IN SEATTLE, WA
WHAT YOU WILL DO:
As a Principal GRC Compliance Consultant – PCI, you will support our client’s Governance, Risk, and Compliance (GRC) program by designing and leading enterprise compliance initiatives across complex technology environments. In this role, you will play a critical part in strengthening the organization’s PCI DSS compliance program while helping integrate compliance practices across broader regulatory domains.
You will work closely with senior stakeholders, auditors, and technical teams to translate complex technology architectures—including hybrid on-premises and cloud environments—into clear, actionable compliance requirements. Your responsibilities will include shaping compliance assessment methodologies, establishing operational standards, and helping embed compliance practices directly into the organization’s technology ecosystem. This position requires a strategic thinker who can balance regulatory rigor with practical implementation, ensuring programs remain scalable, audit-ready, and aligned with business objectives.
KEY RESPONSIBILITIES:
Lead the development and maturation of the organization’s PCI DSS compliance program, including policies, procedures, governance structures, and operational workflows
Design and implement enterprise compliance assessment methodologies that support multiple regulatory frameworks while aligning with business priorities
Establish operational standards, documentation practices, and quality controls that ensure consistent compliance execution across teams
Define and implement KPIs and KRIs to measure compliance program effectiveness and regulatory risk exposure
Partner with engineering and infrastructure teams to perform technical scoping and de-scoping activities within PCI environments spanning both cloud and on-premises infrastructure
Implement integrated compliance controls across technology and business domains to ensure comprehensive regulatory coverage
Serve as a key liaison with internal audit, external auditors, and regulatory stakeholders, representing the organization’s compliance posture and remediation activities
Manage third-party compliance engagements, regulatory examinations, and advisory initiatives
Facilitate workshops with senior leaders and technical teams to address complex compliance requirements and risk decisions
Drive cross-functional collaboration across Legal, IT, Finance, Security, and business teams to ensure regulatory alignment
Provide guidance and education to stakeholders on evolving regulatory requirements and compliance best practices
ABOUT YOU:
- Your values:
- Integrity: You believe in doing the right thing, even when it's uncomfortable, seemingly inefficient, or costly.
- Purposefulness: You have a desire to serve others with your skillset and an openness to continuous learning and growth.
- Ownership: You stick to your commitments, follow up with action, and seek clarity in communication & expectations.
YOUR
EXPERIENCE:
6–8 years of experience in regulatory compliance, GRC, or cybersecurity compliance programs
At least 2 years of direct experience leading or building PCI DSS compliance programs
Demonstrated experience designing and implementing enterprise compliance methodologies…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).