A focused course, tailored for you
The Security Analyst's PCI and Merchant Risk Triage Playbook
Move a flagged merchant, a third-party SaaS review, and a PCI scope question through the queue without bouncing them to the lead.
The detection queue, a chargeback-flagged merchant, a SaaS review request, and a PCI scope question are all open before the morning standup. The analyst who can close each on their own, in writing, with notes that hold up later, becomes the one the team relies on.
Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.
Why this course
A Security Analyst at a payments-heavy e-commerce platform does not have a single job. The role is a queue. Detection alerts from the SIEM. Merchant accounts flagged for chargeback velocity or suspicious login patterns. Third-party SaaS reviews that product managers want answered today. PCI scope questions that arrive in a Slack thread and never get a clean answer. Privileged-access exception requests from engineering. Data subject requests routed in from legal. None of these alone are hard. The hard part is moving each one to a defensible close without escalating to the senior analyst every time, and writing the close in a way that the auditor, the legal team, or the next analyst can read six months later and trust. Most analyst notes are too short for that. The result is rework, escalations, and the slow feeling that the queue is winning. This course teaches the artefact for each queue type. The triage note. The merchant-risk decision. The SaaS risk review. The PCI scope question response. The privileged-access exception. The data subject request. Each is a written template with a worked example. The implementation playbook is tuned to the specific queue mix at the analyst's employer.
What you walk away with
- Close a detection-queue alert with a written triage note the next reader can rely on.
- Make a merchant chargeback-velocity or account-takeover decision with a defensible written record.
- Run a third-party SaaS risk review and return a yes, no, or yes-with-conditions answer in one document.
- Answer a PCI scope question in writing without expanding scope by accident.
- Process a privileged-access exception or a data subject request without bouncing it to the lead.
The 12 modules
How this addresses your situation
Specific modules that map to what you said you are dealing with.
What you get with this course
- Twelve written modules with the template the analyst writes from and a worked example per module.
- Downloadable templates for the triage note, merchant-risk decision, SaaS risk review, PCI scope response, privileged-access exception, data subject request, detection-tuning ticket, and incident handoff.
- The hand-built implementation playbook tuned to the specific queue mix at the analyst's employer.
- Access to the Art of Service learning environment with the course materials available for revisit.
- Thirty-day money-back if the materials do not match the role described above.
What you will have in hand by Day 1, Week 1, Month 1
Within one day: learning environment account provisioned, course materials available, hand-built implementation playbook delivered alongside course access.
Week one to two: work through the alert triage note, the merchant-risk decision, the SaaS review, and the PCI scope response modules in order; apply each to a live queue item.
Week three to four: work through the privileged-access, data subject request, detection-tuning, and incident-handoff modules; apply to live queue items.
Week five onward: the queue review, QSA and audit response, and role-progression modules become part of the regular weekly rhythm.
Before and after
The analyst closes alerts in two-line notes that the next reader cannot rely on, escalates merchant decisions to the lead, and answers PCI scope questions in Slack threads that disappear into history. Rework, escalation, and a slow feeling that the queue is winning.
Each queue item closes with a written artefact the next reader, the senior analyst, and the auditor can each rely on. The merchant, SaaS, and PCI decisions are made and recorded by the analyst on their own. The role-progression conversation has a folder of written artefacts behind it.
What happens if you do not address this
The analyst stays in the role for another year writing two-line notes, escalating routine merchant and SaaS decisions, and leaving PCI scope questions to die in Slack. The auditor opens last quarter's queue and the close notes do not hold up. The role-progression conversation has nothing on paper to point at.
Who it is for
Security Analyst (Tier 2 or senior Tier 1) at a large e-commerce, payments, or fintech platform. Owns or contributes to detection triage, merchant or customer risk decisions, third-party SaaS reviews, PCI scope questions, and privileged-access reviews. Reports to a Security Lead or Manager. Is the one who actually writes the notes that legal and the auditor read later.
How it arrives
Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.
Time investment. Around two to three hours per module. Twelve modules total. Designed to be worked through alongside the live queue rather than as a separate study block.
Why $199 is the right number
Free blog posts on SIEM triage and PCI scope exist and are useful for the first month of the role. SANS and ISC2 courses cover the broad analyst body of knowledge well but are not desk-level templates for the merchant-risk, SaaS-review, and queue-management work this course is built around. This course is the written desk-level artefact set, not a body-of-knowledge survey.
FAQ
30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.