PCI & SOX Compliance Specialist at Navan | London, England, United Kingdom | Rezi

PCI & SOX Compliance Specialist at Navan

PCI & SOX Compliance Specialist

Navan · London, England, United Kingdom

3 weeks ago

PCI & SOX Compliance Specialist

Navan · London, England, United Kingdom

a month ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

The Security Compliance Analyst will be a critical, hands-on member of the Navan Governance, Risk, Compliance, and Trust (GRCT) Team, specifically embedded in London to drive the compliance integration between Navan and Reed & Mackay. This role focuses on execution, untangling legacy systems, mapping control deficiencies, and running daily operational workflows to ensure the security of global travel and expense platforms.

Responsibilities

  • Own Vulnerability Remediation Loops: Actively track and oversee quarterly PCI ASV scans and penetration testing cycles, collaborating directly with IT and engineering teams to ensure patches are executed within strict SLA windows.
  • Lead the Integration Pipeline: Conduct continuous gap analyses and map security controls as we merge legacy travel infrastructure into Navan's modern cloud frameworks.
  • Drive SOX 404 Controls: Take ownership of testing and validating IT General Controls (ITGCs) under Sarbanes-Oxley Section 404, with a heavy emphasis on access control management (Joiners/Movers/Leavers) and secure code deployment.
  • Embed with Engineering: Partner with development teams to automate manual evidence gathering, translating rigid compliance jargon into clear, actionable JIRA tickets.
  • Collaborate Globally: Partner closely with US-based audit firms and compliance bodies, including flexible scheduling for monthly evening shifts.
  • Track Open Deficiencies: Manage the risk register and remediation tracking lifecycle from initial identification to final verification and closure.

Requirements

  • Minimum of 3+ years of hands-on, corporate operational experience in information security compliance.
  • Active experience sitting on a corporate security or IT team.
  • Proved, practical exposure executing compliance frameworks for transactional environments.
  • Understanding of Section 404 ITGCs and the technical mechanics of PCI DSS (including cardholder data protection environments and SAQs).
  • Comfortable navigating tracking platforms such as JIRA, ServiceNow GRC, or AuditBoard.
  • Baseline technical background (e.g., computer science, systems administration, or IT support).
  • Willingness to work under a hybrid model out of our London office (4 days a week).
  • Routine flexibility needed to support monthly evening shifts for US team synchronization.
  • Full proficiency in English.

Skills

  • Information security compliance
  • PCI DSS
  • SOX 404
  • IT General Controls (ITGCs)
  • Access control management
  • Secure code deployment
  • JIRA
  • ServiceNow GRC
  • AuditBoard
  • Computer science
  • Systems administration
  • IT support

Location

  • London

Work Type

  • Hybrid
  • Full-time

Experience Level

  • 3+ years

Education Level

  • CompTIA Security+ (Bonus)
  • ISO 27001 Internal Auditor (Bonus)