Back to Search Results
Get alerts for jobs like this Get jobs like this tweeted to you
Company: Mastercard
Location: Pune, MH, India
Career Level: Director
Industries: Banking, Insurance, Financial Services

Description

Our Purpose

Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.

Title and Summary

Director, Technology Risk Management Who is Mastercard?
Mastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential.
Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all.
Mission First, People Always
As Corporate Security, we are responsible for keeping Mastercard safe and secure from cyber and physical threats, and it is our people on the frontlines who make this happen every day.
By taking care of our people, their wellbeing, and career development, we provide them the necessary tools and environment to ensure the success of our mission.
Overview
The Corporate Security Regulatory Risk team is looking for a Director, Technology Risk Management, to drive Information Security Management System for Regulated markets mandating ISMS implementation and ensuring compliance on security aspects related to the evolving regulatory and statutory obligations with a focus on India region. The ideal candidate should be passionate about information security, cybersecurity, intellectually curious and analytical with strong exposure to business and regulatory environment.
In this highly visible role, you will:
• Establish and maintain a global ISMS strategy and framework for meeting market specific regulatory obligations for ISMS implementation.
• Partner with 1st line Tech Risk and Regulatory Execution teams to drive Risk Assessments, oversee implementation of Risk Treatment plans, manage Cyber Risk Assessments of new products.
• Establish governance and management reporting on compliance to ISMS components for the specific market implementation.
• Serve as the primary point of contact regarding ISMS matters, reporting to leadership and risk committees on ISMS implementation and related security risks, drive ISMS awareness across the organization.
• Actively engage with cross functional teams within 1st LOD, Technology, Risk, Regulatory Counsels, Business teams etc. to drive compliance to security requirements from regulatory and statutory obligations.
• Manage and oversee security aspects of regulatory audits and assessments including readiness and remediation, responding to regulatory notifications and related actions for regulatory compliance.

All About You
The ideal candidate for this position should have:
• Knowledge of information and cyber security domains and controls, understanding of secure system design and defense-in-depth strategies, governance and risk management framework and practices.
• Strong understanding of ISO/IEC 27001, 27002, and related security standards, with experience leading ISMS implementation and certifications.
• Experience managing compliance programs, audit readiness, handling security audits, conducting assessments.
• Proven ability to lead cross-functional teams and manage complex projects, senior stakeholder management, regulatory enquiries
• Strategic thinking, executive communication and strong analytical and problem-solving abilities
• Preferred security certification e.g. CISSP, CISM, CISA, CRISC or equivalent. ISO/IEC 27001 Lead Implementer or Lead Auditor.
• Be seen as a trusted advisor with understanding of business processes and able to provide security consultation and advisory on regulatory matters.
NICE Framework References
National Initiative for Cybersecurity Education (NICE) competency proficiency levels of advanced to expert in the following areas:
• Client Relationship Management
• Risk Management
• Interpersonal Skills
• Information Systems/Network Security
• Information Assurance
• Project Management
Corporate Security Responsibility
Every person working for, or on behalf of, Mastercard is responsible for information security. All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and therefore, it is expected that the successful candidate for this position must:
• Abide by Mastercard's security policies and practices;
• Ensure the confidentiality and integrity of the information being accessed;
• Report any suspected information security violation or breach, and
• Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.

Corporate Security Responsibility


All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:

  • Abide by Mastercard's security policies and practices;

  • Ensure the confidentiality and integrity of the information being accessed;

  • Report any suspected information security violation or breach, and

  • Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.




 Apply on company website