Hire the Best PCI Compliance Specialists
in the United States

More than 3,000 reviews on G2
Rating is 4.5 out of 5.
4.5/5
of Upwork by G2 peer reviewers
Paul T.

Carrollton, Georgia

$50/hr
5.0
25 jobs

I'm a Chartered Accountant with over 5 years of experience in Internal audit, Governance, Risk and Compliance, working in various sectors ranging from Big 4 firms, Banking, FMCG, Management Consulting, Tech startups and the Insurance sector. I have recently consulted for; -InEvent, Inc. (A cloud-based Event technology company in Atlanta, Georgia), as a Cybersecurity compliance manager where I lead SOC 2, HIPPA, ISO 27001, GDPR, Privacy Shield, PCI DSS, WCAG Level AA, FedRAMP, amongst other compliance requirements, audits and certifications within the company. Within 4 months of joining, I completed the company’s SOC 2 and HIPAA certification. -An NDIS/Aged Care/Medicinal Cannabis Consulting firm based in Melbourne, Australia where we help small healthcare businesses access government funding and help them set up top-notch governance and compliance programs whilst also helping them record 100% regulatory audit success. I am a business-minded professional driven by customer satisfaction. I have helped many organisations achieve their business objectives by providing expert services ranging from; Financial accounting advisory, Internal audit, Full cycle compliance program management, Data entry, analysis and visualisation. Kindly reach out to me for excellent professional services for your business. Available now!

  • Compliance
  • Data Entry
  • Finance & Accounting
  • Microsoft Excel
  • Lead Generation
  • Data Privacy
  • International Financial Reporting Standards
  • Internal Auditing
  • Internal Control
  • Cloud Computing
  • Data Protection
  • ISO 27001
  • GDPR
  • Policy Writing
Tom K.

Anderson, Indiana

$190/hr
5.0
1 jobs

I’m a CMMC Certified Assessor (CCA), Certified CMMC Professional (CCP), CISSP, and CRISC with over 30 years in enterprise information systems and more than 16 years working within NIST-based security control environments. I help Defense Industrial Base (DIB) contractors and regulated organizations design defensible cybersecurity and artificial intelligence governance programs that withstand real assessment scrutiny. My work focuses on integrating AI oversight into established cybersecurity and risk frameworks — not as a separate initiative, but as part of an organization’s operational governance model. As AI adoption accelerates across regulated environments, most organizations face a new challenge: meeting CMMC and NIST requirements while introducing AI-enabled capabilities. I help close that gap by aligning AI risk management with CMMC Level 2 expectations, NIST SP 800-171/800-53, and the NIST AI Risk Management Framework. Because I actively support C3PAOs on formal CMMC assessment engagements, I bring an assessor-side perspective to every project. Clients don’t just get compliance advice — they get guidance calibrated to how controls, evidence, and documentation are actually evaluated. I work directly with executives, engineers, and compliance teams to build governance structures that clarify accountability, formalize risk ownership, and produce audit-defensible documentation. Core Expertise • CMMC Level 1 & Level 2 readiness, assessment support, and evidence validation • AI risk and impact assessments aligned to NIST AI RMF and CMMC environments • Integration of AI governance into cybersecurity and enterprise risk programs • NIST SP 800-171 gap analysis, SSP/POA&M development, and remediation strategy • Governance architecture design (policies, procedures, control narratives) • ISO 27001 and NIST CSF program alignment • Supply chain and third-party risk management • Executive and technical stakeholder readiness coaching I operate at the intersection of compliance, governance, and operational trust — helping organizations not only pass assessments, but sustain programs after certification and safely introduce AI capabilities into regulated environments. If you need more than a checklist — and want a program that actually holds up under assessment — let’s talk.

  • Compliance
  • CMMC
  • Strategic Planning
  • Governance, Risk Management & Compliance
  • Cybersecurity Management
  • Business Operations
  • Policy Development
  • DevOps
  • Change Management
  • Program Management
  • Supply Chain Management
  • Training
  • NIST SP 800-53
  • ISO 27001
  • NIST Cybersecurity Framework
Travis N.

Palm Valley, Florida

$85/hr
4.4
13 jobs

Cloud Security Engineer and DevOps Consultant specializing in AWS, GCP, Terraform, Kubernetes, and CI/CD automation for HIPAA, SOC 2, and PCI DSS compliance. With 10+ years across Fortune 100 enterprises, funded startups, healthcare organizations, and SMBs, I build cloud infrastructure and deployment pipelines that are secure by design - not bolted on after an audit fails. If you need someone to architect your AWS or GCP environment, automate infrastructure with Terraform, and make sure the whole stack holds up to HIPAA, SOC 2, or PCI scrutiny, that's exactly what I do. Core Expertise: Cloud Architecture & Security (AWS, GCP, Azure) - Production cloud environments with security built in: hardened VPCs, multi-account AWS Organizations, least-privilege IAM, KMS encryption, AWS WAF, GCP Security Command Center, and guardrails that scale. Infrastructure as Code (Terraform, CloudFormation) - Reusable, peer-reviewed Terraform modules with built-in security controls, policy-as-code (OPA, Sentinel, Checkov), and drift detection. CI/CD Pipeline Automation - GitHub Actions, GitLab CI, Azure DevOps, and AWS CodePipeline with integrated SAST, SCA, secret scanning, and container image scanning. Pipelines that ship fast and safely. Kubernetes & Container Security - Docker, EKS, GKE, ECS, image hardening, runtime security, network policies, and admission controllers. DevSecOps & Compliance Automation - HIPAA, SOC 2 Type II, PCI DSS 4.0.1, and HITRUST controls automated into the build. I've taken multiple organizations through audits with zero findings by making compliance a build artifact, not a quarterly fire drill. Zero Trust & Cloud Networking - Identity-based micro-segmentation, Cloudflare, site-to-site VPNs, and secure networking for distributed teams. Monitoring & Incident Response - CloudWatch, Datadog, security event monitoring, and runbooks that turn alerts into action. Why clients hire me: Most consultants either build cloud infrastructure or audit it. I do both, so the environments I deliver are production-ready and audit-ready on day one. From greenfield AWS builds to debugging deployment issues on AI-assisted web apps, my goal is to leave your stack automated, secure, and easy for your team to own. Message me to discuss your cloud migration, DevOps automation, or compliance readiness project.

  • Google Cloud Platform
  • System Administration
  • Cybersecurity Management
  • Vulnerability Assessment
  • DevOps
  • CI/CD
  • PCI DSS
  • SaaS
  • System Security
  • Management Skills
  • Real Time Stream Processing
  • Report
  • Report Writing
  • System Deployment
Dylan C.

Burnsville, Minnesota

$85/hr
5.0
55 jobs

CISA-certified compliance leader helping high-growth SaaS & startups get audit-ready—without the bureaucracy. With over 4,000 hours and 100% client satisfaction, I embed as your fractional Head of Compliance to lead SOC 2 (Type I & II), ISO 27001, and HIPAA programs end-to-end. What I Can Help You With: • Audit Readiness & Gap Analysis (SOC 2, HIPAA & ISO 27001) • Policy, Control & Risk Register Design • Vendor Due‑Diligence Workflows • Certification • Evidence Collection & Audit Support • Projectized Packages:  – SOC 2 Scoping + Gap Package (4–6 weeks)  – ISO 27001 Internal Audit Readiness (3–4 weeks)  – HIPAA Compliance Framework Setup Why Partner With Me: • Reduced compliance timelines by 30–50% • Secured enterprise and funding reputational wins • CPA on-staff • Deep experience in high‑growth, funded startups & Cloud 100 teams Let’s talk if you: Want to pass your audit first try Need to scale securely under investor or enterprise pressure Value a proactive compliance leader—not just a vendor Click “Invite to Job” to schedule a free 15‑minute discovery call or ask for a fixed‑price proposal.

  • Compliance
  • Sarbanes-Oxley Act
  • Risk Assessment
  • IT Compliance Audit
  • Compliance Consultation
  • HIPAA
  • SOC 1 Report
  • SaaS
  • GDPR Compliance Review
  • Policy Writing
  • Information Security Governance
  • Regulatory Compliance
  • Security Infrastructure
  • Information Security Audit
  • Business Continuity Plan
Sam W.

Setauket-East Setauket, New York

$175/hr
4.7
46 jobs

Turn Security Into Your Fastest Path to Revenue Enterprise clients won't sign until you can prove security, privacy, and compliance. I get you there — fast, audit-ready, and without grinding your roadmap to a halt. I'm Dr. Sam Wertheim, an Upwork Expert-Vetted (Top 1%) fractional CISO with 17+ years across DoD (Defense Innovation Unit), Fortune-scale enterprises, and federal agencies. I currently serve as fractional CISO to a NYDFS-regulated insurtech and as sitting CISO for an identity-governance platform. My doctoral research focuses on AI-driven social engineering — bringing both battle-tested compliance execution and a forward view on where threats are heading. WHERE I CREATE VALUE - Close enterprise deals — SOC 2, ISO 27001, PCI DSS, HIPAA, NYDFS §500, done right and audit-ready - Secure cloud & AI products — AWS, Azure, GCP, SaaS platforms, and the new risk surface AI introduces - Strengthen risk posture — without slowing the business down WHY CLIENTS KEEP ME ON RETAINER - Executive security leadership at a fraction of a full-time CISO's cost - A practitioner, not just an advisor — I've run the pen tests, built the SIEM, filed the regulatory certifications - Deep regulatory specialization (NYDFS §500, SOC 2, ISO 27001) most generalists can't match WHAT CLIENTS SAY - "The SOC 2 work let us close a Fortune 100 contract we'd been stuck on for months." — SaaS founder - "ISO 27001 certified faster than we thought possible. It opened doors immediately." — Series-stage CTO - "Compliance finally stopped being the thing that slowed our sales cycle." — B2B SaaS CEO SOUND FAMILIAR? - Drowning in security questionnaires and vendor risk reviews? - Need to be audit-ready before your next enterprise deal closes? - Running Vanta, Drata, or Sprinto but unsure what comes next? - Shipping AI-driven products and unsure how to govern the risk? - Want ongoing CISO leadership without a full-time hire? CORE SERVICES - Fractional / virtual CISO (vCISO) — ongoing security leadership - Compliance & audit readiness — SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, NYDFS §500 - Penetration testing & security assessments - Security questionnaires & vendor risk — pass enterprise reviews quickly - AI security & governance — for teams building AI-driven products EXPERTISE - Frameworks: SOC 2, ISO 27001, PCI DSS, NIST 800-53, NYDFS §500, GDPR, HIPAA, CMMC, HITRUST - Cloud & security: AWS, Azure, GCP, SIEM, IAM, Zero Trust, endpoint security - GRC tooling: OneTrust, Whistic, CyberGRX, Panorays, Graphite Connect, Vanta / Drata / Sprinto Let's talk. Message me or click Invite for a free consultation — bring your toughest compliance roadblock and I'll tell you straight how I'd solve it. Dr. Sam Wertheim · Fractional CISO · Upwork Expert-Vetted Top 1% Cybersecurity Expert | Threat Intelligence | AI Security | Governance, Risk, and Compliance

  • Compliance
  • Cybersecurity Management
  • Business
  • Cyber Threat Intelligence
  • Cloud Engineering
  • Cybersecurity Monitoring
  • NIST Cybersecurity Framework
  • Python
  • Project Management
  • Cybersecurity Tool
  • Rust
  • NIST SP 800-53
  • Security Management
Michael C.

Canyon, Texas

$150/hr
5.0
3 jobs

I help organizations build, strengthen, and mature cybersecurity governance, risk, and compliance (GRC) programs that stand up to real-world operational and audit scrutiny. As an Information Security professional with experience supporting defense contractors, manufacturers, federal environments, and commercial organizations, I specialize in translating complex security and compliance requirements into practical, sustainable business processes. Whether your organization is pursuing SOC 2, ISO/IEC 27001, NIST Cybersecurity Framework (CSF), NIST SP 800-53, NIST SP 800-171, or CMMC assessment readiness, my focus is helping you reduce risk while building programs that remain effective long after an assessment is complete. My expertise includes: • Governance, Risk, and Compliance (GRC) program development and maturation • SOC 2 and ISO/IEC 27001 readiness assessments • NIST Cybersecurity Framework (CSF) implementation • NIST SP 800-53 and NIST SP 800-171 compliance • CMMC Level 1 and Level 2 assessment readiness • Risk assessments and security gap analyses • Security policies, standards, procedures, SSPs, and POA&Ms • Control mapping and evidence development • Virtual CISO (vCISO) advisory services • Microsoft 365 Commercial and GCC High security governance Throughout my career, I've worked as a Business Information Security Officer (BISO), cybersecurity consultant, and assessor, partnering with executive leadership to improve security maturity, prepare organizations for external assessments, and implement governance processes aligned with business objectives. My approach is practical, execution-focused, and rooted in real-world operational experience. I don't recommend unnecessary complexity or expensive rebuilds when existing programs can be strengthened through sound governance, risk management, and well-designed security controls. I work collaboratively with leadership, IT, compliance, and operational teams to create solutions that are technically sound, operationally achievable, and auditor defensible. If your organization needs help with: • Preparing for a SOC 2, ISO 27001, NIST, or CMMC assessment • Performing a cybersecurity risk or gap assessment • Developing security documentation and governance processes • Building or improving an Information Security Program • Establishing a practical GRC roadmap • Aligning security controls with regulatory or contractual requirements • Executive cybersecurity strategy and vCISO guidance I'd welcome the opportunity to discuss your objectives and help you build a security and compliance program that delivers measurable business value.

  • Compliance
  • Information Security
  • Risk Management
  • Risk Assessment
  • Cybersecurity Management
  • NIST Cybersecurity Framework
  • NIST SP 800-53
  • CMMC
  • SOC 2
  • ISO 27001
  • Security Policies & Procedures Documentation
  • Internal Auditing
  • Microsoft Intune
  • Microsoft Endpoint Manager

How it works

Post a job for freePost a job

Tell us what you need. Create your own job post or generate one with AI then filter talent matches.

Hire top talent fast

Consult, interview, and hire quickly, so you can meet the freelancers you're excited about.

Collaborate easily

Use Upwork to chat or video call, share files, and track project progress right from the app.

Payment simplified

Manage payments in one place with flexible billing options. Only pay for approved work, hourly or by milestone.

Don't just take our word for it

How do I hire a PCI Compliance Specialist in the United States on Upwork?

You can hire a PCI Compliance Specialist in the United States on Upwork in four simple steps:

  • Create a job post tailored to your PCI Compliance Specialist project scope. We'll walk you through the process step by step.
  • Browse top PCI Compliance Specialist talent on Upwork and invite them to your project.
  • Once the proposals start flowing in, create a shortlist of top PCI Compliance Specialist profiles and interview.
  • Hire the right PCI Compliance Specialist for your project from Upwork, the world's largest work marketplace.

At Upwork, we believe talent staffing should be easy.

How much does it cost to hire a PCI Compliance Specialist?

Rates charged by PCI Compliance Specialists on Upwork can vary with a number of factors including experience, location, and market conditions. See hourly rates for in-demand skills on Upwork.

Why hire a PCI Compliance Specialist in the United States on Upwork?

As the world's work marketplace, we connect highly-skilled freelance PCI Compliance Specialists and businesses and help them build trusted, long-term relationships so they can achieve more together. Let us help you build the dream PCI Compliance Specialist team you need to succeed.

Can I hire a PCI Compliance Specialist in the United States within 24 hours on Upwork?

Depending on availability and the quality of your job post, it's entirely possible to sign up for Upwork and receive PCI Compliance Specialist proposals within 24 hours of posting a job description.