This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are looking for a highly proactive and organized Senior Security Expert to join our In-Person-Payments (IPP) Security & Certifications team. Adyen's In-Person Payments platform is one of the most complex payment infrastructures in the world, processing billions of euros annually across tens of thousands of merchant locations globally. The Payment Solution is the engine behind it all, governing the payment processing, certified hardware, and the software that keeps every transaction compliant, secure, and trusted by global payment schemes. The IPP Security & Certifications team is the function that keeps this infrastructure compliant, certified, and trusted by global payment schemes. This is a high-stakes, high-autonomy role where you will take genuine ownership of the PCI certification portfolio that underpins this infrastructure. Your success will not be measured by writing code or implementing fixes, but rather defined by knowing the landscape better than anyone in the room, aligning the right stakeholders, and ensuring nothing falls through the cracks. If you treat a compliance deadline as a problem to solve six months in advance, and can walk an engineering team through a PCI requirement and a QSA through an engineering decision with equal confidence — this role was built for you.
Job Responsibility
Lead the process: Take central ownership of PCI Certifications for our Payments Solution, encompassing DSS, PIN/KMO, P2PE, PTS, MPoC, and SSF
Manage the portfolio: Maintain a comprehensive, up-to-date inventory of all PCI certifications across hardware devices, software applications, and solution-level certifications
Plan proactively: Track expiry dates, re-evaluation windows, and delta certification triggers
Collaborate with assessors: Act as the primary point of contact with QSAs and external assessors, managing timelines, preparing assessment materials, coordinating interviews, and navigating follow-up inquiries
Partner with Engineering: Join vulnerability analysis and threat modeling sessions to provide practical, compliance-informed security guidance to engineers
Maintain documentation: Take full ownership of all security documentation required for assessments (asset inventories, threat models, data flow diagrams, etc.), ensuring audit readiness year-round
Engage with the industry: Represent Adyen at PCI SSC working groups and industry forums
Requirements
Deep subject matter expertise in PCI frameworks and standards such as DSS, PIN/KMO, P2PE, PTS-POI, MPoC, SSF
Proven track record of orchestrating complex compliance pipelines, juggling multiple certifications, deadlines, and external assessors simultaneously
Technically fluent enough to sit with hardware and software engineers, understand what they are building, and give them compliance guidance that is actually useful
Build trust on both sides: QSAs trust you because you are organized and prepared
engineers trust you because you make their lives easier
Operate with high autonomy
Strong communicator who can clearly present complex compliance concepts to technical and non-technical audiences alike