paytech Achieves PCI DSS Level 1: Elevating Payment Security and Trust
Overview:
paytech is a dynamic fintech company dedicated to pushing the boundaries of innovation in the financial technology industry. Our mission is to revolutionise the way people manage and interact with their finances through cutting-edge solutions and exceptional service. We pride ourselves on fostering a culture of innovation, collaboration, and excellence.
As a Security & Compliance Engineer, you will support both client and internal compliance efforts across PCI DSS, ISO 27001, and ISO 22301. You will partner with auditors, clients, and engineering teams to translate requirements into practical processes, maintain evidence, and drive remediation—helping paytech meet security obligations efficiently without unnecessary bureaucracy.
Key Responsibilities:
Compliance and Audits
- Support paytech clients during PCI DSS audits (Merchant and Service Provider levels).
- Maintain compliance records for clients, including:
- Audit timelines
- Current audit status
- Defined audit scope
- Key stakeholders and contacts
- Audit documentation
- Prepare and maintain audit evidence, including policies, procedures, process descriptions, and system diagrams.
- Participate in internal audits and certification processes for paytech, including:
- PCI DSS v4.0
- ISO 27001
- ISO 22301
- Act as a primary point of contact for external auditors and QSA companies.
Policies and Security Processes
- Develop, maintain, and regularly review internal security policies, including but not limited to:
- Password Policy
- Access Control Policy
- Information Security Policy
- Incident Management Policy
- Vendor and Third-Party Management Policy
- Ensure policies are not only documented but effectively implemented and aligned with actual operational practices.
Internal Collaboration
- Work closely with Engineering, DevOps, and Product teams to:
- Explain security and compliance requirements
- Support remediation and closure of audit findings
- Review system architecture and processes from a security perspective
- Act as a trusted partner for internal teams, helping them meet compliance requirements efficiently and pragmatically, without unnecessary bureaucracy.
Vendor and Service Registry
- Maintain a centralized registry of third-party services and vendors, including:
- Services in use
- Payment records
- Internal ownership and responsibility
- Security and compliance requirements
- Participate in vendor risk management activities.
Requirements:
- 2–5 years of experience in information security, compliance, or GRC-related roles
- Practical experience with PCI DSS, including audit participation, evidence preparation, or remediation activities
- Familiarity with ISO 27001 and ISO 22301 standards
- Experience working with security policies, procedures, and audit documentation
- Ability to communicate clearly with both technical and non-technical stakeholders
- Comfortable working with external auditors and compliance partners
- Good written and spoken English
Nice to have:
- Experience in fintech, payments, or other regulated industries
- Understanding of cloud environments (AWS or similar) from a security and compliance perspective
- Experience maintaining documentation in Confluence or similar knowledge management systems
- Basic understanding of DevOps and modern engineering workflows
People who understand the payments ecosystem are rare.
We want to meet you!
We’re always looking for people who understand payments, payment gateways, and merchant processing. If you have the skills, upload your CV and let’s talk.
Thanks for enquiring
with us.
We’ll contact you directly to get things
moving – we may ask you for additional
information about your enquiry.
Perks
& benefits.
Hybrid working
Our hybrid model gives you more flexibility to get work done where you do it best – whether it’s from home or from our flexible office spaces worldwide.
Training & development
Challenge yourself and learn new technical or soft skills with a training budget for your growth and personal development.
Hobby groups
Join our employee-led activities. Connect with people with similar interests and contribute to shaping our dynamic culture.
Wellness programs
Feel your best with initiatives that promote physical and mental well-being, like mindfulness sessions.
Social events
Meet and mingle with your colleagues at our celebrations, social gatherings, and team-building activities, held year-round.
Related positions.
Business Development Manager | Business Development
Full-Time
Hybrid
Limassol, Cyprus
Java Developer | Backend Development
Full-time
Hybrid
Limassol, Cyprus
PSP Relationships Manager | Merchant Services & Payments
Full-Time
Office
Limassol, Cyprus
Technical Support Specialist L2 | Support
Full-time
Hybrid
Limassol, Cyprus
Integration Intelligence Specialist
Full-Time
Office/Hybrid
Limassol, Cyprus