Responsibilities include, but are not limited to: Leading PCI DSS compliance-related activities and certification; Supporting the evolution and execution of the SOC 2 program, including control design, testing, and evidence collection; Maintaining required evidence artifacts and ensuring traceability of evidence; Interpreting and operationalizing security and compliance requirements into actionable control activities for engineering and operations; Serving as SME for PCI DSS and SOC 2 compliance, advising internal teams and customers; Partnering with control owners to ensure controls meet PCI DSS requirements and Trust Services Criteria (Security, Availability, Confidentiality, etc.); Supporting external audits by preparing evidence, responding to auditor requests, coordinating audit activities, and tracking remediation; Driving coordination with third parties (e.g., service providers, hosting partners) to ensure shared control alignment; Ensuring audit readiness through continuous proactive gap assessments and control testing throughout the year; Identifying, assessing, and communicating compliance and security risks to stakeholders; Identifying, tracking, and driving closure of audit findings and control deficiencies; and. This role is responsible for designing and executing continuous compliance monitoring activities, identifying gaps and leading associated remediation efforts, planning and leading third-party audits, and measuring control effectiveness across cloud-based, on-prem and hybrid environments.