Description
Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Director Risk Management OVERVIEW:The ONE (“The Operations, Network, and Employee Digital Experience teams focus on the underpinning platforms that power our Network and the employees that serve it”) Risk and Control team is a newly formed group focused upon establishing both foundational and transformational risk management practice at Mastercard Technology. Responsibilities include, but are not limited to, leading efforts in support of Technology partners with identifying control gaps, designing key control activities, monitoring such activities, and driving risk remediation with TeamONE platform and program owners.
This is an exciting opportunity to be in a leadership role taking part in solving complex problems and working with great Mastercard technology leaders in operations and platforms. This highly visible role will be focusing upon proactively identifying, monitoring, and managing technology risks to protect Mastercard Technology and our customers.
In this role you will combine your technical, risk, control, and leadership expertise with your keen eye for detail to create and implement robust control activities that fortify TeamONE against threats and potential issues. If you are ready to be at the forefront of technological risk management, we invite you to bring your risk management and leadership skills to our innovative and collaborative environment.
ROLE:
• Lead the assessments of IT controls and processes to identify deficiencies, deviations, and compliance gaps.
• Lead and perform IT and operational control walkthroughs to determine existing process controls and adherence to control framework for the following key control areas: Patch Management, End-of-Life/End-of-Support, Access Management, Configuration Management, Disaster Recovery, Asset Tagging and Inventory Accuracy and Completeness, Logging and Monitoring, and Change Management.
• Within each assigned project, understand specific risks (e.g., strategic, operational, financial, legal, regulatory, technology, other) and business requirements. Lead the development of control activity documentation in qualitative and timely manner. Evaluate compliance with relevant policies, procedures, and requirements, assess controls design adequacy and operating effectiveness, and identify controls gaps and improvement opportunities. Lead the development of draft reportable issues for validation with management and understand related risk, impact, and root cause. Partner with management to develop action plans that remediate gaps identified in a sustainable manner. Track, monitor, and validate the completion of action plans by management.
• Lead efforts to support the development and updating of control and process documentation, and relevant standards.
• Based on criticality and urgency, support remediation activities and link such activities back to monitor risk rating
• Partner with first and second-line risk management teams for all risk related functions to ensure alignment on risk management methodology, practices, terminology, etc.
ALL ABOUT YOU:
• Technical Proficiency:
o Demonstrate abilities in leading technology risk and control assessment and implementation activities.
o Knowledge of IT general controls and related operations.
o Experience in Mainframe, Oracle, SQL, Unix/Linux, HP Nonstop and/or Windows environments.
o Knowledge of cybersecurity principles, best practices, and threat landscape.
o Ability to both lead and assess technology controls, vulnerabilities, and potential risks.
o General understanding of technology infrastructure.
o o Background in technology audit, risk management, technology operations, information systems management, information security management, regulatory engagement, etc.
• Risk Management Expertise:
o Strong knowledge of the risk management lifecycle and processes (e.g., methods for identifying, assessing treating and monitoring risk)
o Leadership experience with developing, implementing, and delivering technology risk assessment and mitigation approaches.
o Leadership experience in developing and implementing technology risk management frameworks and strategies.
o Strong understanding of industry standards and regulatory requirements related to technology risk management (e.g., SOC 1, SOC 2, ISO 27001, PCI-DSS, COBIT, NIST Cybersecurity Framework).
• Regulatory and Compliance Knowledge:
o Experience with regulatory technology and security risk management expectations.
o Leadership experience in developing, performing, and evaluating IT internal controls and testing.
o Demonstrate ability to align the organization's technology practices with legal and regulatory standards.
• Execution and Communication:
o Demonstrate strong leadership and execution skills, consistently meeting and exceeding team project deadlines, and goals.
o Demonstrate ability to work as a leader, independently and in a team environment, ensuring tasks are completely thoroughly and accurately.
o Exceptional attention to detail with keen ability to identify errors or discrepancies in processes or documentation.
o Strong analytical skills to identify potential risks, assess their potential impact, and devise effective mitigation strategies.
o Excellent communication skills to effectively convey technical concepts to both technical and non-technical stakeholders, including executive management.
o Ability to lead and collaborate with cross-functional teams, including other technology, security, compliance, application / product teams, and business / regional teams.
• Qualifications (preferred but not required)
o Bachelor's degree in Information Technology, Computer Science, or a related field.
o Experience in leading evaluations assessing compliance with legal, regulatory, operational and IT requirements.
o Professional Certification or Designation (e.g., CISA, CIA, CISSP, or equivalent).
o Experience in payment eco systems.
o Ability to travel up to 10%.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Abide by Mastercard's security policies and practices;
Ensure the confidentiality and integrity of the information being accessed;
Report any suspected information security violation or breach, and
Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
Apply on company website