Description
Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Senior Technology Risk Analyst-2 Who is Mastercard?Mastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential.
Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all.
Mission First, People Always
As Corporate Security, we are responsible for keeping Mastercard safe and secure from cyber and physical threats, and it is our people on the frontlines who make this happen every day.
By taking care of our people, their wellbeing, and career development, we provide them the necessary tools and environment to ensure the success of our mission.
Overview
The Corporate Security Regulatory Risk Management team is looking for a Senior Technology Risk Analyst to help drive readiness and compliance on security aspects related to the evolving regulatory and statutory needs across global markets. The ideal candidate should be passionate about information security, cybersecurity, intellectually curious and analytical with preferred exposure to regulatory environment.
In this highly visible role, you will:
• Perform design and operating effectiveness testing of information security controls
• Execute periodic control testing across infrastructure, applications and cloud
• Develop and maintain control testing plans, test scripts, and evidence requirements
• Identify control gaps, assess risk impact, and recommend remediation actions
• Track remediation plans and closure of control deficiencies
• Prepare clear testing reports, executive summaries, and dashboards
• Communicate findings to senior management and risk committees
All About You
The ideal candidate for this position should have:
• Strong experience in security control assessment and testing
• Ability to assess both technical and process controls
• Strong documentation, reporting, and communication skills
• Strong understanding of information security controls and assurance models
• Hands-on experience with ISO 27001, NIST, SOC and PCI DSS
• Proven ability to work in cross-functional teams and manage complex projects
• Preferred security certification e.g. CISSP, CISM, CISA and PCI DSS (ISA / PCIP - preferred)
• Excellent written and verbal communication skills to interact with stakeholders
NICE Framework References
National Initiative for Cybersecurity Education (NICE) competency proficiency levels of advanced to expert in the following areas (recommended no more than 6):
• Risk Management & Control Assessment
• Security Control Validation and Assurance
• Cybersecurity Governance & Compliance
• Frameworks & Standards Management
• Technical Security Assessment
• Cyber Risk Reporting & Communication
Corporate Security Responsibility
Every person working for, or on behalf of, Mastercard is responsible for information security. All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and therefore, it is expected that the successful candidate for this position must:
• Abide by Mastercard's security policies and practices;
• Ensure the confidentiality and integrity of the information being accessed;
• Report any suspected information security violation or breach, and
• Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Abide by Mastercard's security policies and practices;
Ensure the confidentiality and integrity of the information being accessed;
Report any suspected information security violation or breach, and
Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
Apply on company website