SecurityBackend
PCI DSS
Also written as PCI, Payment Card Industry Data Security Standard
The card industry's security standard for anyone handling payment card data — prescriptive, audited, and a strong reason most companies avoid touching card numbers at all.
Think of it like
The rules for handling cash in a bank vault: specific, inspected, and not open to interpretation.
Junior or senior?
Senior sounds like
Often explains how they REDUCED scope — tokenising or outsourcing card handling so most of their systems fell outside the standard. That's the sophisticated answer.
Ask them
“How did your architecture limit which systems were in PCI scope?”