The opportunity
Adyen provides payments, data, and financial products in a single solution for customers like Meta, Uber, H&M, and Microsoft - making us the financial technology platform of choice. At Adyen, everything we do is engineered for ambition.
What you'll do
Lead the process: Take central ownership of PCI Certifications for our Payments Solution, encompassing PIN/KMO, P2PE, PTS, MPoC, and SSF.
Manage the portfolio: Maintain a comprehensive, up-to-date inventory of all PCI certifications across hardware devices, software applications, and solution-level certifications.
Plan proactively: Track expiry dates, re-evaluation windows, and delta certification triggers. Anticipate deadlines, engage leadership, and ensure engineering teams are prepared well in advance of audit cycles.
Collaborate with assessors: Act as the primary point of contact with QSAs and external assessors, managing timelines, preparing assessment materials, coordinating interviews, and navigating follow-up inquiries.
Partner with Engineering: Join vulnerability analysis and threat modeling sessions to provide practical, compliance-informed security guidance to engineers. Translate compliance requirements into actionable engineering tasks without slowing down the development lifecycle.
Maintain documentation: Take full ownership of all security documentation required for assessments (asset inventories, threat models, data flow diagrams, etc.), ensuring audit readiness year-round.
What they're looking for
- Engage with the industry: Represent Adyen at PCI SSC working groups and industry forums, contributing to the development of standards that will shape the future of payment security.
- You have deep subject matter expertise in PCI frameworks and standards such: as PIN/KMO, P2PE, PTS-POI, MPoC, SSF.
- You have a proven track record of orchestrating complex compliance pipelines,: juggling multiple certifications, deadlines, and external assessors simultaneously.
- You are technically fluent enough to sit with hardware and software: engineers, understand what they are building, and give them compliance guidance that is actually useful.