Our Purpose
We work to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments and businesses realize their greatest potential. Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. We cultivate a culture of inclusion for all employees that respects their individual strengths, views, and experiences. We believe that our differences enable us to be a better team – one that makes better decisions, drives innovation and delivers better business results.
Title and Summary
Senior Technology Risk Analyst - Privacy
Overview
The Mastercard Technology Risk Team is looking for a Senior Technology Risk Analyst to support and lead an assurance and controls program supporting various privacy and security requirements to meet customer and regulatory obligations for Mastercard. Focus will be on providing compliance support, the implementation of design (up-to-date standard operating procedures) and operational (testing the validity of procedures periodically) effectiveness, monitoring, and reporting of the ongoing operating effectiveness of the internal control environment and working closely with application/product owners to document the flow of data at the application level. This role is a pivotal part of the Mastercard technology risk function and supports Mastercard's commitment to balancing innovation while protecting the internal control posture. The team assesses internal controls to proactively identify risks, define remediation actions and track remediation efforts. We are looking for someone to join our team and help us meet these compliance goals.
The ideal candidate will have the ability to think and act both strategically and tactically while ensuring that the corporation remains compliant with required security, technology, and financial standards, as well as industry best practices.
Responsibilities
• Supports assurance program, engages with internal partners to help build control frameworks to ensure needs and expectations over services are met for various certifications (e.g., SOC2)
• Engages with Mastercard Privacy team to ensure privacy principles are adequately addressed
• Engages with product and application owners to document data flows using Data Flow Diagrams
•Engages with the auditors to test the control framework to ensure objectives are met and risk is managed effectively
•Executes control assessments of various operational and business areas to assess potential risks or control gaps
• Takes actions to address risk issues according to established policies; monitors the implementation of action plans to reduce risk
• Tracks remediation internally and externally through to resolution to help improve design and operational effectiveness of controls
• Assists with the implementation of cross-functional initiatives to deliver on risk goals, policies and procedures
• Supports special projects as requested; provides ad-hoc support to management
• Reports formally on the results of assurance/certification objectives, controls, and risk assessments
• Helps develop and maintain reports, metrics and presentations of progress and results for meetings with customers and regulators
Experiences
• Demonstrated ability to operate with independence and autonomy
• Experience with control frameworks (e.g., SOC2, ISAE3402/3000, ISO27001 and GDPR)
• Bachelor’s degree or equivalent combination of education and experience/Bachelor’s degree in computer science, information technology or related field preferred
• Strong interpersonal, communication and presentation skills necessary for interaction with business leaders and teams across all levels of the organization
• Professional certification like CISSP/CISA/CRISC/CIPP or similar, a plus
• Contribute to work environment that encourages knowledge of, respect for, and the development of skills to engage with those of other cultures and backgrounds
• Familiarity with the financial services industry and payment processing industry, a plus
• Experience collaborating cross-functionally to identify and implement best practice risk processes
• Exposure to security, including network and internet systems security
• Demonstrates basic knowledge of Risk analysis; begins to develop relationships with risk managers, business and technology partners
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Abide by Mastercard’s security policies and practices;
Ensure the confidentiality and integrity of the information being accessed;
Report any suspected information security violation or breach, and
Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.