Security Compliance Manager – PCI DSS Specialist

Company: Virgin Media
Apply for the Security Compliance Manager – PCI DSS Specialist
Location: Reading
Job Description:

Overview

As Security Compliance Manager, you safeguard cardholder data and payment environments by driving PCI DSS v4.01 compliance with robust controls and clear evidence. You lead PCI-related assessments, audits, and remediation while guiding ISO27001 and other security accreditations. You enjoy shaping best practice, reducing risk, and ensuring controls actually work. This role suits a detail-driven security professional who thrives in a collaborative, fast-paced tech environment.

Pay / Benefits

  • bumper reward package
  • benefits and extras to support you and loved ones

Responsibilities

  • Lead PCI DSS assessments, ROC activities, and assessor engagement
  • Coordinate and guide teams to ensure PCI controls map to obligations
  • Manage audit processes with clear evidence, reporting, and remediation follow-up
  • Support ISO27001, Cyber Essentials, and other security accreditations
  • Oversee network security concepts, segmentation, and secure design principles
  • Advise on OS and application hardening, encryption, key management, and IAM
  • Drive risk management initiatives and remediation planning
  • Foster cross-functional collaboration and clear security communication

Key requirements

  • Hands-on PCI DSS assessments experience including ROC activity
  • Deep understanding of PCI DSS v4.01 and its application in payment environments
  • Ability to interpret and map technical and procedural controls to PCI obligations
  • Experience in information security, governance, risk, or compliance roles
  • Experience with ISO 27001 and Cyber Essentials
  • Auditing experience with evidence collection, reporting, and remediation follow-up
  • Knowledge of network security, segmentation, and secure design
  • Understanding of OS/app hardening, encryption, and key management
  • Knowledge of identity and access management and privileged access practices
  • Risk management knowledge with remediation capabilities
  • Strong collaboration and relationship-building
  • Clear, confident communication tailored to audiences
  • Solution-focused, proactive and detail-oriented
  • PCI DSS v4.01
  • PCI ROC activities
  • ISO 27001

…

Posted: October 1st, 2026