via Dover
$130K - 180K a year
Lead the security scanning team and delivery of PCI DSS external vulnerability scanning services while developing new security offerings with cross-functional partners.
Requires extensive vulnerability management and PCI DSS experience, deep ASV methodology and scanning technology expertise, and strong leadership and stakeholder communication skills.
ABOUT IXOPAY IXOPAY is the enterprise-grade global payment infrastructure platform built for the era of agentic commerce. We equip merchants and enterprises with AI-driven intelligence, payment orchestration, advanced tokenization, and the tools to optimize every stage of the payments journey. From intelligent routing and compliance to customizable modules and enterprise-scale orchestration, IXOPAY helps businesses integrate faster, improve payment performance, and expand globally with confidence. At IXOPAY, our people are our greatest strength. Our collaborative culture is built on shared values that guide how we work, innovate, and support our customers. ABOUT THE ROLE Aperia Compliance helps businesses across the payments ecosystem navigate complex security and compliance requirements with confidence. We combine deep industry expertise with modern technology and AI-driven intelligence to make vulnerability management, security scanning, and compliance simpler, more efficient, and more reliable for our clients. From PCI DSS external vulnerability scanning and remediation guidance to compliance program management and reporting, Aperia Compliance equips businesses with the tools, expertise, and insights they need to strengthen security, maintain compliance, and adapt to evolving industry requirements. We're looking for a Manager, Vulnerability Management & Security Scanning to lead and advance Aperia Compliance's security scanning and vulnerability management solutions. In this role, you'll lead the team responsible for delivering PCI DSS external vulnerability scanning services, ensuring operational excellence, technical accuracy, regulatory alignment, and a strong client experience. You'll combine people leadership with deep subject-matter expertise in PCI DSS, Approved Scanning Vendor (ASV) requirements, vulnerability assessment, and remediation practices. Beyond managing day-to-day operations, you'll help shape the future of our security offerings. Working closely with Product, Client Success, Sales, and Leadership, you'll identify opportunities to expand our capabilities beyond traditional PCI DSS scanning and develop services that address emerging client security and compliance needs. This is an opportunity to combine technical expertise, team leadership, and strategic influence to strengthen our existing services while helping grow our presence in the broader cybersecurity and compliance market. WHAT YOU'LL DO LEAD & DEVELOP THE SECURITY SCANNING TEAM * Lead, coach, and develop a team of vulnerability management and security scanning professionals, fostering technical excellence, accountability, and continuous improvement. * Oversee team performance, hiring, onboarding, development planning, and resource allocation. * Establish clear goals, performance expectations, and quality standards that support reliable service delivery and professional growth. * Build a collaborative, knowledge-sharing environment that encourages technical development, sound judgment, and ownership. OWN VULNERABILITY SCANNING OPERATIONS & COMPLIANCE * Oversee the end-to-end delivery of PCI DSS external vulnerability scanning services, including scheduling, scan execution, reporting, remediation support, and attestation. * Ensure scanning operations meet service-level agreements, quality expectations, and applicable PCI SSC ASV Program requirements. * Maintain operational practices and technical standards that support our ASV accreditation and standing. * Define and monitor operational KPIs, including scan volumes, turnaround times, remediation timelines, dispute rates, and client satisfaction. * Evaluate and improve scanning processes, workflows, and quality assurance practices to strengthen efficiency, accuracy, and scalability. * Manage scanning technologies, vendor relationships, and program budgets to support effective service delivery. PROVIDE TECHNICAL LEADERSHIP & EXPERTISE * Serve as a senior subject-matter expert in PCI DSS vulnerability scanning, CVSS scoring, vulnerability validation, false-positive handling, and risk assessment. * Provide guidance on PCI DSS v4.x requirements and translate complex technical and compliance concepts into practical recommendations. * Act as the senior escalation point for complex scanning issues, disputed findings, and high-impact client concerns. * Establish technical standards, playbooks, and dispute-resolution practices that promote consistency and defensible decisions. * Evaluate scanning tools, emerging detection capabilities, automation, and AI-assisted workflows to improve accuracy, productivity, and service quality. * Support the investigation and assessment of infrastructure and web application vulnerabilities, including common security issues such as SQL injection and cross-site scripting. DRIVE SECURITY SERVICES GROWTH & INNOVATION * Help define the strategic direction and expansion of our vulnerability management and security scanning solutions. * Identify opportunities to develop additional cybersecurity and compliance services that address evolving market needs. * Partner with Product, Sales, Client Success, and Leadership to evaluate new service offerings, establish requirements, and support go-to-market initiatives. * Translate client feedback, industry developments, and regulatory changes into opportunities for service innovation and improvement. * Act as a trusted security and PCI DSS authority through client education, webinars, industry engagement, and thought leadership. * Champion the value of effective vulnerability management and security compliance across internal teams and external stakeholders. WHAT YOU'LL BRING REQUIRED * Extensive professional experience in vulnerability management, security scanning, PCI DSS compliance, or a related cybersecurity discipline, including experience leading technical teams or complex programs. * Deep hands-on expertise in PCI DSS external vulnerability scanning, ASV methodology, vulnerability assessment, and remediation practices. * Strong, current knowledge of PCI DSS v4.x and PCI SSC ASV Program requirements, including the operational and technical standards associated with maintaining ASV accreditation. * Experience with vulnerability scanning technologies such as Qualys, Tenable Nessus, Rapid7 Nexpose/InsightVM, or comparable platforms. * Strong understanding of CVSS scoring, vulnerability classification, false-positive validation, risk assessment, and dispute-resolution processes. * Familiarity with common infrastructure and web application vulnerabilities, including SQL injection, cross-site scripting, and related security risks. * Demonstrated ability to lead, mentor, and develop technical professionals, or substantial technical leadership experience with readiness to transition into formal people management. * Experience managing operational delivery, service-level agreements, performance metrics, and quality standards. * Ability to independently investigate complex security issues, evaluate technical evidence, and make well-reasoned, defensible decisions. * Strong communication and stakeholder management skills, including the ability to explain technical findings and compliance requirements to clients and non-technical audiences. * Commercial awareness and an interest in developing new security services, improving client value, and supporting business growth. * Ability to identify opportunities to apply automation, AI, and emerging technologies responsibly to improve security operations. * Relevant cybersecurity or compliance certification, such as CISSP, Security+, PCI-related credentials, or an equivalent industry-recognized qualification. PREFERRED * Previous experience working for a PCI SSC Approved Scanning Vendor (ASV), Qualified Security Assessor (QSA) organization, or similar security assessment provider. * Experience directly supporting ASV accreditation, quality assurance, or program compliance activities. * PCI QSA qualification or experience participating in PCI DSS assessments and implementations. * Experience developing vulnerability management frameworks, operational playbooks, scanning standards, or formal dispute-resolution procedures. * Experience implementing automation or AI-assisted workflows within cybersecurity or compliance operations. * Experience managing security technology vendors, service budgets, or operational resource planning. * Experience developing, launching, or expanding cybersecurity and compliance service offerings. * Strong understanding of evolving cybersecurity threats, vulnerability management practices, and regulatory requirements. * Experience presenting at industry events, delivering client education, publishing technical content, or participating in the PCI and cybersecurity community. WHY JOIN IXOPAY? At IXOPAY, you'll play an important role in creating the technology experience that enables our global teams to do their best work. You'll support a modern, cloud-based technology environment while gaining exposure to identity and access management, SaaS administration, automation, security, and IT operations. You'll have opportunities to improve how we work—not just resolve tickets—by identifying recurring challenges, automating manual processes, and helping evolve our internal IT practices as the company grows. We offer: * Remote work-from-home opportunity * Competitive salary and benefits * Professional growth and development opportunities * A collaborative, international team environment * Opportunities to work with modern SaaS, security, automation, and AI technologies WHAT MAKES AN IXOPAYER? We are a global team united by one standard, where every voice matters and initiative drives real change. We believe in progress over perfection—moving with purpose, embracing modern technologies and AI, and continuously improving through learning and iteration. We empower our people to take ownership, challenge the status quo, and collaborate across teams to solve meaningful problems. If you're tenaciously curious, empowered to take ownership, and passionate about delivering customer-first solutions in the fast-paced world of global payments, you'll thrive at IXOPAY. OUR COMMITMENT TO INCLUSION We know great candidates don't always meet every qualification. If you're excited about this opportunity, we encourage you to apply—we'd love to hear what you can bring to IXOPAY. EQUAL OPPORTUNITY EMPLOYER IXOPAY is committed to building an inclusive workplace where everyone can thrive. We welcome applications from all qualified candidates regardless of race, ethnicity, religion, gender, gender identity or expression, sexual orientation, age, disability, or any other characteristic protected by applicable law.
This job posting was last updated on 10/9/2026