Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart, and accessible. Our technology and innovation, partnerships, and networks combine to deliver a unique set of products and services that help people, businesses, and governments realize their greatest potential.
Title and Summary
Director Risk Management
OVERVIEW:
The ONE (“The Operations, Network, and Employee Digital Experience teams focus on the underpinning platforms that power our Network and the employees that serve it”) Risk and Control team is a newly formed group focused upon establishing both foundational and transformational risk management practice at Mastercard Technology. Responsibilities include, but are not limited to, leading efforts in support of Technology partners with identifying control gaps, designing key control activities, monitoring such activities, and driving risk remediation with TeamONE platform and program owners.
This is an exciting opportunity to be in a leadership role taking part in solving complex problems and working with great Mastercard technology leaders in operations and platforms. This highly visible role will be focusing upon proactively identifying, monitoring, and managing technology risks to protect Mastercard Technology and our customers.
ROLE:
- Lead the assessments of IT controls and processes to identify deficiencies, deviations, and compliance gaps.
- Lead and perform IT and operational control walkthroughs to determine existing process controls and adherence to control framework for key control areas.
- Within each assigned project, understand specific risks and business requirements. Lead the development of control activity documentation in a qualitative and timely manner.
- Evaluate compliance with relevant policies, procedures, and requirements, assess controls design adequacy and operating effectiveness, and identify controls gaps and improvement opportunities.
- Lead the development of draft reportable issues for validation with management and understand related risk, impact, and root cause.
- Partner with management to develop action plans that remediate gaps identified in a sustainable manner.
- Track, monitor, and validate the completion of action plans by management.
- Lead efforts to support the development and updating of control and process documentation, and relevant standards.
- Support remediation activities and link such activities back to monitor risk rating.
- Partner with first and second-line risk management teams for all risk-related functions to ensure alignment on risk management methodology, practices, terminology, etc.
ALL ABOUT YOU:
- Technical Proficiency:
- Demonstrate abilities in leading technology risk and control assessment and implementation activities.
- Knowledge of IT general controls and related operations.
- Experience in Mainframe, Oracle, SQL, Unix/Linux, HP Nonstop and/or Windows environments.
- Knowledge of cybersecurity principles, best practices, and threat landscape.
- Ability to both lead and assess technology controls, vulnerabilities, and potential risks.
- General understanding of technology infrastructure.
- Background in technology audit, risk management, technology operations, information systems management, information security management, regulatory engagement, etc.
- Risk Management Expertise:
- Strong knowledge of the risk management lifecycle and processes.
- Leadership experience with developing, implementing, and delivering technology risk assessment and mitigation approaches.
- Leadership experience in developing and implementing technology risk management frameworks and strategies.
- Strong understanding of industry standards and regulatory requirements related to technology risk management.
- Regulatory and Compliance Knowledge:
- Experience with regulatory technology and security risk management expectations.
- Leadership experience in developing, performing, and evaluating IT internal controls and testing.
- Demonstrate ability to align the organization's technology practices with legal and regulatory standards.
- Execution and Communication:
- Demonstrate strong leadership and execution skills.
- Demonstrate ability to work as a leader, independently and in a team environment.
- Exceptional attention to detail with keen ability to identify errors or discrepancies.
- Strong analytical skills to identify potential risks, assess their potential impact, and devise effective mitigation strategies.
- Excellent communication skills to effectively convey technical concepts to both technical and non-technical stakeholders.
- Ability to lead and collaborate with cross-functional teams.
- Qualifications (preferred but not required):
- Bachelor's degree in Information Technology, Computer Science, or a related field.
- Experience in leading evaluations assessing compliance with legal, regulatory, operational, and IT requirements.
- Professional Certification or Designation (e.g., CISA, CIA, CISSP, or equivalent).
- Experience in payment ecosystems.
- Ability to travel up to 10%.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks come with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
- Abide by Mastercard’s security policies and practices;
- Ensure the confidentiality and integrity of the information being accessed;
- Report any suspected information security violation or breach;
- Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.