Senior Security GRC Analyst (PCI ISA Specialist)

CommerceAustin, TX
$88,951 - $150,432Hybrid

About The Position

At Commerce, our mission is to empower businesses to innovate, grow, and thrive with our open, AI-driven commerce ecosystem. As the parent company of BigCommerce, Feedonomics, and Makeswift, we connect the tools and systems that power growth, enabling businesses to unlock the full potential of their data, deliver seamless and personalized experiences across every channel, and adapt swiftly to an ever-changing market. We believe in harnessing AI responsibly to unlock new possibilities, and we’re looking for individuals who use it intentionally to solve problems, accelerate outcomes, and expand what’s possible in their role. Our purpose is to help businesses confidently solve complex commerce challenges so they can build smarter, adapt faster, and grow on their own terms. If you want to be part of a team of bold builders, sharp thinkers, and technical trailblazers who shape the future of commerce, this is the place for you. As a Senior Security GRC Analyst and Internal Security Assessor (ISA), you will serve as the primary Subject Matter Expert (SME) for our global PCI DSS program at Commerce. We operate a highly mature PCI DSS 4.0 environment; your mission is to lead the continuous evolution of this program, ensuring that compliance is integrated into our "business as usual" (BAU) operations. While your primary focus is PCI, you will be a key player in our broader GRC function, supporting our SOC2 and ISO 27001 certifications. You will act as the technical bridge between our Engineering, Infrastructure, and IT teams and external auditors, ensuring that our high-security standards are documented, validated, and maintained.

Requirements

  • 6+ years in an Information Security or IT Audit role, with at least 3 years of deep focus on PCI DSS within a major cloud-native environment.
  • Active PCI ISA (Internal Security Assessor) or PCI QSA certification is mandatory.
  • Thorough understanding of PCI DSS 4.0 requirements and the practical application of the standard in modern environments.
  • Proven experience leading Level 1 Service Provider assessments.
  • Ability to explain complex compliance requirements to developers and business leaders in a way that emphasizes enablement rather than "blockage."
  • You understand the "Why": You don't just "do compliance"; you understand the security intent behind every control and can help teams meet the requirement in a way that actually improves our security posture.
  • Technical Curiosity: You are comfortable diving into technical configurations (IAM policies, VPC flow logs, etc.) to verify control effectiveness yourself.
  • Adaptable: You enjoy the challenge of a high-paced environment where scale and security must coexist and evolve together.

Nice To Haves

  • Experience with SOC2 and ISO 27001:2022.
  • Experience with GRC automation and familiarity with modern cloud-native security and observability tools.
  • Experience using GRC platforms and a desire to automate manual evidence collection to reduce audit fatigue.

Responsibilities

  • Serve as the officially designated PCI ISA for the organization. Manage the annual assessment lifecycle, including scoping, evidence collection, and validation of controls.
  • Direct the ongoing maintenance of our PCI 4.0 program, with a specific focus on managing Targeted Risk Analyses (TRAs) and the customized approach where applicable.
  • Partner with Cloud Engineering to validate PCI scope across our global footprint, ensuring effective network segmentation and data flow isolation.
  • Act as the primary point of contact for our external QSA, defending our control environment and streamlining the audit process to minimize disruption to technical teams.
  • Operationalize PCI requirements (e.g., quarterly scans, penetration test remediation) into automated workflows.
  • Support the broader GRC team in managing our SOC2 Type 2, ISO 27001, and other regulatory audits.
  • Provide GRC perspective on architectural designs, product launches, and infrastructure changes to ensure "compliance by design."
  • Track and drive the remediation of audit findings and security gaps, working closely with asset owners to find pragmatic, secure solutions.

Benefits

  • variable compensation (such as bonus or commission)
  • equity
  • benefits in accordance with local policies
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service