Dominic. A WAJA

Security Advisor Consultant - Compliance Specialist , Data Security & Risk Management | PCI DSS -SME & Privacy -SME | Global Data Protection & Payment Card Security

United States

About

I operate at the intersection of security, risk, and data protection, helping organizations protect sensitive data while meeting complex regulatory demands. With 7 years of experience across PCI DSS, enterprise risk management, and compliance frameworks, I’ve worked with organizations in healthcare, financial services, and retail to identify control gaps, reduce risk exposure, and strengthen audit readiness. My work goes beyond traditional compliance by integrating privacy principles into security and risk programs, ensuring that both cardholder data (CHD) and personal data (PII/PHI) are protected across their lifecycle. I specialize in: • PCI DSS v4.0 assessments and payment environment security • Enterprise risk assessments and control gap analysis • Third-party risk management and vendor governance • Data protection and privacy risk (HIPAA, GDPR, CCPA) • Cross-border data transfer risk and third-party exposure In my recent work, I’ve led integrated assessments that combine PCI DSS and privacy requirements, identifying risks in data flows, contractor access, and offshore processing. I’ve conducted privacy impact assessments (PIAs), evaluated vendor data handling practices, and helped organizations implement practical controls around access management, data minimization, and monitoring. What differentiates my approach is the ability to translate regulatory requirements into operational controls that align with business objectives. I don’t just assess compliance, I focus on how data moves, where risk exists, and how to build scalable, defensible control environments. I’m particularly interested in roles where I can contribute to: • Building or maturing data protection and privacy programs • Strengthening third-party risk and data governance • Supporting organizations operating in highly regulated environments If your organization is looking to strengthen its data protection posture across PCI, privacy, and enterprise risk, let’s connect. Key Strengths: ✔ PCI DSS v4.0, ISO 27001, SOC 2, HITRUST, FinCEN Regulatory Expectations ✔ Governance, Risk & Compliance (GRC) ✔ Audit Readiness & External Auditor Engagement ✔ Third-Party Vendor Risk Management ✔ Data Governance & Minimization Principles ✔ Data Mapping & Classification (PII, PHI, CHD)

Experience

  • Security Advisor Consultant at GMI - Global Market Innovators
    Jul 2026 - Present · 1 mo

  • Policy Advisor - Unpaid at Alliance for American Leadership
    Apr 2025 - Jun 2026 · 1 yr 3 mos

  • Import/Export Operation Compliance at Lufthansa
    Aug 2025 - Apr 2026 · 9 mos

    As an Office Agent – Import/Export Operations Compliance with Lufthansa Cargo Airlines, I assist full adherence to international trade compliance with customs, aviation security & regulations while supporting governance, risk, and compliance (GRC) objectives across operations. I collaborate with various units and compliance teams to manage security & regulatory risks. Conduct documentation reviews, processing and maintain audit readiness. My role strengthens data integrity, export control compliance, documentation and process transparency—aligning operational activities.

  • Risk Management Specialist at Privaxi
    Jul 2024 - Jul 2025 · 1 yr 1 mo

  • PCI DSS Security Compliance Analyst at Baxter Clewis Consulting
    Jan 2020 - May 2025 · 5 yrs 5 mos

    As a PCI DSS Compliance Consultant, I’ve had the privilege of helping organizations achieve and sustain PCI DSS certification by building resilient, audit-ready security programs that align business operations with global payment security standards. Beyond meeting regulatory requirements, I view PCI DSS as a strategic framework that fosters trust, accountability, and operational resilience. Working closely with IT, cybersecurity, and business stakeholders, I’ve learned that the key to lasting compliance lies in preparation, collaboration, and continuous improvement—not firefighting during audits. As a consultant, my goal remains clear: to empower organizations to integrate security and compliance into their core business processes, creating a foundation for long-term success and customer confidence.