Our Purpose
We work to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments and businesses realize their greatest potential. Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. We cultivate a culture of inclusion for all employees that respects their individual strengths, views, and experiences. We believe that our differences enable us to be a better team – one that makes better decisions, drives innovation and delivers better business results.
Title and Summary
VP, Technology Risk Management - NAM Assurance Overview:
The Technology Risk Management (TRM) organization is a business enabler and industry leader of technology and security risk management practices, supported by a multi-disciplinary team of top security, technology, and risk professionals. Our mission is to exceed our stakeholder expectations by providing enhanced visibility and proactive management of technology risks and ensuring strong security and sound operational environment.
The Controls Solutions & Monitoring team is responsible for the global strategy and oversight of providing enhanced assurance to Mastercard's internal/external stakeholders by proactively assessing technology and security controls and continuous process improvement. This role will develop the strategic direction of the assurance team to proactively identify control gaps and risks of meeting Mastercard standards/stakeholder contractual obligations. The role will also partner and provide assurance support across various Mastercard business units that deliver global services, such as Core Card Services, Open Banking, Loyalty, etc.
Responsibilities:
- Oversee development, maintenance, and execution of assurance program, engaging with customers to build compliance/control frameworks to ensure needs and expectations over services are met for Mastercard policies and various certifications (e.g., SOC1/SOC2, ISAEs).
- Oversee development of assessment plans to validate/test controls aligned to regulatory and customer expectations for business, technology, and security controls identifying potential risks and control gaps.
- Oversee integration of new technologies and businesses into assurances program while standardizing, leveraging synergies, or process improvements to drive scalability across the program.
- Serve as strategic partner providing advice to business owners regarding controls design, remediation, and technology integration with existing frameworks to minimize risk exposure/control failure.
- Drive oversight and awareness of compliance/assurance outcomes (e.g., controls gaps, opportunities for improvement).
- Develop and maintain consolidated reports, metrics and presentations of progress and results for meetings with customers and regulators.
- Oversee third party reporting, to mature control frameworks ensuring objectives are met and risks are managed effectively.
- Proactively assist in identifying technology and security risks and compliance trends and potential red flags, including exception and escalation awareness.
- Manage a diverse team of Assurance Leads, providing oversight and SME support, along with driving consistency across assurance program models.
- Manage collaborative working relationships with stakeholders across the organization.
Experience:
- Degree in technology, information systems management, information security management, security policy or related program desired, but not required.
- IT certification(s) preferred such as CISSP/CISA/CRISC.
- Knowledge of Control Framework standards such as ISAEs, SOC1, SOC2s.
- Knowledge of regulatory technology and security risk management expectations.
- Knowledge of current and emerging technologies and potential for exploitation.
- Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and IT management (e.g., GDPR, FBA, CBA, etc.).
- Experience collaborating cross-functionally, geographically to identify and implement best practice assurance/compliance processes.
- Systematic problem-solving approach, coupled with strong communication skills and a sense of ownership and drive.
- Proven success in navigating multi-national organizations and operating effectively within a diverse multicultural organization.
- Project Management Skills.
Mastercard is an inclusive equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law.
If you require accommodations or assistance to complete the online application process or during the recruitment process, please contact reasonable_accommodation@mastercard.com and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
- Abide by Mastercard's security policies and practices.
- Ensure the confidentiality and integrity of the information being accessed.
- Report any suspected information security violation or breach.
- Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
In line with Mastercard's total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary based on location, experience and other qualifications for the role and may be eligible for an annual bonus or commissions depending on the role. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance), flexible spending account and health savings account, paid leaves (including 16 weeks new parent leave, up to 20 paid days bereavement leave), 10 annual paid sick days, 10 or more annual paid vacation days based on level, 5 personal days, 10 annual paid U.S. observed holidays, 401k with a best-in-class company match, deferred compensation for eligible roles, fitness reimbursement or on-site fitness facilities, eligibility for tuition reimbursement, gender-inclusive benefits and many more.
#J-18808-Ljbffr