Direct Travel is a leading provider of corporate travel management services. By leveraging both the expertise of its people and innovative solutions, Direct Travel enables clients to derive the greatest value from their travel program in terms of superior service, progressive technologies, and significant cost savings. The company is led by CEO Christal Bemont and Executive Chairman Steve Singh, noted business investor and founder of Concur. Direct Travel has offices in over 80 locations and is currently ranked among the top providers of travel on Travel Weekly’s Power List. For more information, visit www.dt.com . Direct Travel is an EOE/AA/Veteran/People with Disabilities employer. If you're ready to chart a new course and advance your career with the valuable moments and travel experiences that await, we welcome you to submit your resume for consideration at Direct Travel. #LI-Remote
Sr. GRC/PCI Compliance Analyst
Location
United States
Posted
25 days ago
Salary
0
Seniority
Senior
No structured requirement data.
Job Description
Sr. GRC/PCI Compliance Analyst
Direct Travel
Role Description We are seeking a detail-oriented and execution-focused GRC / PCI Compliance Analyst to support a critical enterprise initiative: achieving PCI DSS Level 1 Service Provider compliance and delivering a successful, audit-ready Report on Compliance (ROC). This role will work closely with the PCI Program Director to drive control implementation, documentation, and audit readiness across the organization. The ideal candidate has hands-on experience supporting PCI audits, managing evidence collection, and operationalizing controls in complex environments. This is a high-impact, execution-heavy role responsible for ensuring controls are not only designed, but documented, validated, and audit-ready. This is a remote position. Key Responsibilities - PCI Control Implementation & Support - Support the implementation and operationalization of PCI DSS v4.0 controls across infrastructure, applications, and business processes. - Partner with control owners to ensure requirements are clearly understood and effectively implemented. - Track control status, gaps, and remediation progress. - Documentation & Evidence Management - Develop and maintain policies, standards, and procedures aligned to PCI DSS. - Create control narratives and process documentation. - Manage evidence artifacts required for audit. - Build and manage a centralized evidence repository mapped to PCI requirements. - Ensure all documentation is accurate, complete, and audit-defensible. - Audit Readiness & Support - Prepare the organization for PCI assessment by validating control implementation. - Conduct internal readiness reviews. - Identify and remediate documentation gaps. - Support the QSA audit process, including responding to evidence requests, coordinating interviews and walkthroughs, and tracking audit findings and follow-ups. - Scope Documentation & Control Mapping - Assist in maintaining data flow diagrams, system inventories, and Cardholder Data Environment (CDE) documentation. - Map controls to PCI DSS requirements and ensure traceability between requirements, controls, and evidence. - Risk & Gap Management - Support PCI gap assessments across systems, applications, and vendors. - Track and manage remediation items, ensuring timely closure. - Identify control weaknesses and escalate risks to the Program Director. - Cross-Functional Coordination - Work closely with IT / Security, Business and Operations teams, Application Development teams, and Legal / Compliance / Risk. - Ensure alignment between technical implementation and compliance requirements. - Tokenization & Scope Reduction Support - Support documentation and validation of scope reduction initiatives, including tokenization implementations and segmentation strategies. - Ensure evidence clearly demonstrates reduction of PCI scope and removal of PAN from systems where applicable. Qualifications - Bachelor’s degree in Computer Science, Information Technology, or a related field or equivalent experience. - 5+ years of experience in GRC, compliance, or information security. - Hands-on experience supporting PCI DSS audits or compliance programs. - Strong understanding of PCI DSS requirements and control structure. - Control documentation and evidence expectations. - Experience managing audit evidence and documentation repositories. - Strong organizational skills with high attention to detail. Preferred Qualifications - Experience supporting a PCI DSS ROC (merchant or service provider). - ISA (Internal Security Assessor) certification. - Experience with GRC tools (e.g., OneTrust (preferred), Archer, ServiceNow GRC, Audit/evidence management platforms). - Familiarity with ISO 27001, SOC 1 / SOC 2, GDPR or data privacy frameworks. Key Competencies - Strong attention to detail and documentation discipline. - Ability to translate compliance requirements into clear, actionable documentation. - High accountability and ownership mindset. - Strong organizational and project tracking skills. - Ability to manage multiple workstreams and deadlines simultaneously. Benefits - Medical, Dental, and Vision benefits. - Employee rewards and recognitions program. - Total Rewards Package which includes Wellness, Sustainability, DE&I initiatives, and Mental Health Support. Company Description Direct Travel is a leading provider of corporate travel management services. The company has been providing travel management for over 40 years, working with clients to develop highly customized travel programs. By leveraging both the expertise of its people and innovative solutions, Direct Travel enables clients to derive the greatest value from their travel program in terms of superior service, progressive technologies and significant cost savings. Direct Travel has offices in over 70 locations across North America and the UK and is currently ranked 12th on Travel Weekly’s Power List.
Related Guides
Related Categories
Related Job Pages
More Compliance Jobs
Senior Specialist, Regulatory Affairs – Operations
Telix Pharmaceuticals LimitedDeveloping theranostics (nuclear medicine) for prostate, kidney, glioblastoma, haematologic cancers and rare diseases.
• Support the planning, coordination, and execution of global regulatory submissions, including INDs, CTAs, BLAs, NDAs, MAAs, and amendments, ensuring compliance with global regulatory requirements and timelines. • This role interfaces with external publishing vendor(s) for the preparation of submissions, and internal stakeholders to provide operational oversight and support for eCTD regulatory submission activities. • Maintain regulatory documentation, submission records, and regulatory information within regulatory systems and document management platforms. • Oversee regulatory document management, tracking, and archival activities. • Support regulatory systems (e.g., Veeva RIM), and serve as internal subject matter expert (SME) for training and support to internal stakeholders. • Coordinate regulatory submission activities including document readiness, publishing, quality control, and electronic submission (eCTD) processes. • Support preparation and operational coordination of regulatory agency interactions, including briefing document planning and submission logistics. • Monitor and track submission deliverables and milestones, identifying risks and proactively working with stakeholders to mitigate potential delays. • Ensure compliance with global regulatory submission standards, including eCTD structure, formatting, and publishing requirements. • Contribute to the development and implementation of regulatory operations processes, tools, and best practices to improve efficiency and consistency across programs. • Support lifecycle management activities, including post-approval submissions, amendments, annual reports, and regulatory correspondence.
Regulatory Affairs and Compliance Advisor
Edison InternationalEdison International has been a leader in electricity services since it was established in southern California in 1886. Today, through its subsidiaries, the com
Identify and analyze regulatory issues impacting business divisions, maintain relationships with stakeholders, and advise on compliance strategies while ensuring adherence to regulations and monitoring compliance processes.
• Perform independent QC reviews of AML, KYC/CDD/EDD, and Sanctions screening work completed for US correspondent and intermediary banking clients • Review customer due diligence files, risk assessments, transaction monitoring outputs, sanctions alerts, and periodic reviews for accuracy, completeness, and regulatory compliance • Identify control gaps, regulatory deficiencies, and documentation weaknesses • Maintain strong understanding of US regulatory expectations applicable to correspondent and intermediary banking.
Research Compliance Analyst II
University of CaliforniaSince 1869, the University of California has been providing excellent college educational programs for students seeking bachelor's to doctoral degrees. The Univ
Title: Research Compliance Analyst II Location: Los Angeles United States Job Description: General Information Press space or enter keys to toggle section visibility Work Location: Los Angeles, CA, USA Onsite or Remote Flexible Hybrid Work Schedule Monday through Friday, 8:00am to 5:00pm Salary Range: $31.51 - 62.64 Hourly Employment Type 2 - Staff: Career Duration Indefinite Job # 30029 Primary Duties and Responsibilities Press space or enter keys to toggle section visibility This position coordinates regulatory activities for clinical research studies across assigned units, departments, or divisions. The incumbent conducts detailed reviews of clinical research protocols and prepares, manages, and submits all required regulatory documents and applications to meet UCLA, FDA, sponsor, and other regulatory requirements. The role works closely with study monitors to collect, review, and maintain regulatory documentation, ensuring timely submissions and full compliance with federal, state, and university regulations. The full salary range for this position is $31.51 - $62.64 per hour. The budgeted salary range that the university expects to pay $31.51 - $36.00 per hour. Job Qualifications Press space or enter keys to toggle section visibility Required: - Minimum of 1+ years of experience as a clinical researcher - Interpersonal skills to effectively communicate information in a timely, professional manner and establish and maintain cooperative and effective working relationships with students, staff, faculty, external collaborators and administration and to work as a member of a team. - Organization skills to create and maintain administrative and regulatory files effectively as well as independently balance the various tasks to ensure deadlines are met. - Demonstrated proficiency with Adobe and Microsoft suite software, especially Excel, to perform daily tasks efficiently and accurately. - Working knowledge of clinical research concepts, policies and procedures, and human safety protection regulations and laws. - Knowledge of and experience working with a variety of local and external IRBs, scientific review and other research committees, national cooperative group sponsors, industry sponsors, federal and foundation funding organizations, etc. Preferred: - Bachelors degree As a condition of employment, the final candidate who accepts an offer of employment will be required to disclose if they have been subject to any final administrative or judicial decisions within the last seven years determining that they committed any misconduct; or have filed an appeal of a finding of substantiated misconduct with a previous employer.


