Skip to content
← Back to job listings

Application Security Compliance Specialist (PCI-SSF/PA-DSS))

NCR Atleos Careers APAC · GURGAON, India

Corporate LawImported listingfull-time15 days ago

About The Role

About NCR Atleos
NCR Atleos, headquartered in Atlanta, is a leader in expanding financial access. Our dedicated 20,000 employees optimize the branch, improve operational efficiency and maximize self-service availability for financial institutions and retailers across the globe.
Title: Application Security Compliance Specialist
Location: Gurgaon or Hyderabad, India
About NCR Corporation
NCR Corporation (NYSE: NCR) is a global technology company leading how the world connects, interacts and transacts with business. NCR’s assisted- and self-service solutions and comprehensive support services address the needs of retail, financial, travel, healthcare, hospitality, entertainment, gaming and public sector organizations in more than 100 countries. NCR (www.ncr.com) is headquartered in Atlanta, Georgia, U.S.A.
The opportunity
As an Application Security Compliance Specialist, you will help ensure that NCR Atleos software products and development practices meet applicable security,privacyand regulatory requirements. Working within our global Application Security team, you will turn complex requirements into practical guidance, prepare teams forassessments,and helpdemonstratethat security and privacy are embedded throughout the software lifecycle.
A major focus isorganization-levelPCI Software Security Framework(SSF)activities: support product teams to achieve andretainPCI Secure Software Standard listings andmaintainvalidation of our Secure Software Lifecycle practices. This role suits someone who combines complianceexpertisewith software development and application security knowledge.

What you will do

-
Govern the Secure SDLC. Maintain and improve practices aligned with thePCI Secure SLC Standard.
-
Enable PCI SSF validation. Guide teams through externalassessment, self-assessment, annualattestationand periodic revalidation activities.
-
Interpret requirements. Translate security, privacy, legal and industry requirements into clear, proportionate guidance.
-
Assess readiness and close gaps. Coordinate reviews, evidence, gap analysis,remediationand resolution of findings.
-
Engage and influence. Partner with engineering, Legal, risk,complianceand security teams,QSAsand the PCI SSC.
-
Build capability. Create training and reusable guidance; monitor developments and communicate material changes.
-
Drivecontinual improvement.Useindustry changes, stakeholder feedback, internal audits,assessment outcomes, recurringfindings,and incidentsto strengthen controls and processes.
What you will bring
Essential experience and capabilities
-
Typically,7+ years of relevant experiencein application security, software security assurance, secure software development, technology risk, privacy, compliance,or audit.
-
Practical experience developing,operating,governingor assessing aSecure SDLC.
-
Experience interpreting security or compliance requirements and supporting assessments, evidence collection, gapanalysisand remediation.
-
Working knowledge of threat modelling, vulnerability management, securitytesting,and risk-based decision-making.
-
Technical understanding of cloud services, source-codemanagement,and CI/CD practicessufficientto engage credibly with engineering teams.
-
Ability to convert complex requirements into pragmatic guidance and make evidence-based recommendations.
-
Strong stakeholder management, communication, analytical and problem-solving skills, including the ability to influence without direct authority.
-
Ability to work independently and effectively within a globally distributed team.
-
Comfortable using AI assistants, such asCopilot, responsibly in day-to-day work to improve personal productivity, quality,and speed of delivery.
-
A bachelor’s degree in a STEM discipline, orequivalentrelevant professional experience and qualifications.
Desirable experience and capabilities
-
Direct experience ofPCI SSFvalidationor a comparable software security assurance framework.
-
Knowledge ofpayment-card security,GDPRrequirements,NIST CSF and OWASPstandards andguidance.
-
Experience delivering application security or compliance-relatedtraining.
-
Knowledge of security and governance for AI-enabled software developmentandproducts.
-
A relevant certification, such as CISSP, CSSLP, CIPP, CIPT or CIPM.
How you will succeed
-
Teams receive clear,timely,and actionable compliance guidance.
-
PCI SSF validation activities are well planned, appropriatelyevidenced,and progressed effectively.
-
Compliance gaps and findings are clearly owned, prioritized,tracked,and resolved.
-
Secure SDLC requirementsremainpractical,current,and consistently understood.
-
Assessment and incident lessons lead to sustainable improvements and strong stakeholder relationships.
Evidence we value
In your application, we would particularly welcome examples of how you have interpreted a security standard, prepared a product ororganizationfor assessment, resolved a significant compliance gap, or influenced an engineering team to adopt a more effective security practice.
Offers of employment are conditional upon passage of screening criteria applicable to the job.
EEO Statement
NCR Atleos is an equal-opportunity employer. It is NCR Atleos policy to hire, train, promote, and pay associates based on their job-related qualifications, ability, and performance, without regard to race, color, creed, religion, national origin, citizenship status, sex, sexual orientation, gender identity/expression, pregnancy, marital status, age, mental or physical disability, genetic information, medical condition, military or veteran status, or any other factor protected by law.
Statement to Third Party Agencies
To ALL recruitment agencies: NCR Atleos only accepts resumes from agencies on the NCR Atleos preferred supplier list. Please do not forward resumes to our applicant tracking system, NCR Atleos employees, or any NCR Atleos facility. NCR Atleos is not responsible for any fees or charges associated with unsolicited resumes.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing