Description
Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Vice President, Information Security Engineering - Business Security Officer Who is Mastercard?Mastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential.
Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all.
Mission First, People Always
As Corporate Security, we are responsible for keeping Mastercard safe and secure from cyber and physical threats, and it is our people on the frontlines who make this happen every day.
By taking care of our people, their wellbeing, and career development, we provide them with the necessary tools and environment to ensure the success of our mission.
Overview
The Business Security Enablement (BSE) team is looking for a Business Security Officer (BSO). The BSO is a senior level contributor that will drive partnerships with technology, engineering, and business teams. This BSO role will function as the primary security advocate and advisor for one of our recent acquisitions. In this role, you will:
• Provide information security risk advice and consultation to the newly acquired organization through a strong understanding of the organization and applications.
• Enable the acquired entity to proactively manage, control, mitigate and/or remediate security risk within the organizations risk appetite.
• Provide guidance to the acquired organization on Corporate Security topics, policies, standards, and controls.
• Partner with application development teams to improve the security of the application code and architecture.
• Drive risk culture and promote security awareness activities within the Product and Technology organization.
• Lead a team of security engineers dedicated to the acquired organization.
• Partner and collaborate with other BSOs to continuously improve security engineering processes.
All About You
The ideal candidate for this position should have:
• Demonstrated effectiveness working in a global environment and leading a global team of security engineers.
• Demonstrated experience building organizational relationships, partnering with, and influencing executive leadership while commanding the respect of the individuals with varying technical expertise across the organization.
• Strong understanding of information security, risk and data privacy within the domain of digital commerce including relevant practical experience, integration of different security technologies, and designing secure multi-domain solutions.
• Demonstrate a broad awareness of security operations concepts and practices across all phases of the development and delivery lifecycle.
• Experience and proficiency with cloud technologies, API design, and distributed systems operations.
• Knowledge and technical security experience in cryptography, including several of the following: encryption, hashing, key management, digital certificates, TLS.
• Knowledge of relevant industry standards and guidelines such as ISO27001, PCI-DSS, NIST SP800-53, COBIT.
• Experience of continuous delivery/continuous integration processes and procedures including critical security considerations in automated workflows
• Experience and understanding of architecture and technologies used in payments and e-commerce.
• Experience with mergers and acquisitions specifically cybersecurity domains.
NICE Framework references All About You
• National Initiative for Cybersecurity Education (NICE) competency proficiency levels of limited in leadership, limited to developing in operational and professional, and developing to proficient in technical.
• This Mastercard role shares KSAs with related NICE work roles
o OV-SPP-002, OPM751, Cyber Policy and Strategy Planner
o OV-EXL-001, OPM901, Executive Cyber Leadership
o OV-MGT-001, OPM722, Information Systems Security Manager
Corporate Security Responsibility
Every person working for, or on behalf of, Mastercard is responsible for information security. All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and therefore, it is expected that the successful candidate for this position must:
• Abide by Mastercard's security policies and practices.
• Ensure the confidentiality and integrity of the information being accessed.
• Report any suspected information security violation or breach, and
• Complete all periodic mandatory security training in accordance with Mastercard's guidelines.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Abide by Mastercard's security policies and practices;
Ensure the confidentiality and integrity of the information being accessed;
Report any suspected information security violation or breach, and
Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
Apply on company website