Certification and Assurance - Senior Security/Technology Risk Analyst
Certification and Assurance - Senior Security/Technology Risk Analyst

Certification and Assurance - Senior Security/Technology Risk Analyst

Full-Time 60000 - 80000 £ / year (est.) No home office possible
CareerArc

At a Glance

  • Tasks: Support certification audits and ensure compliance with security standards.
  • Company: Join Mastercard, a global leader in digital payments and innovation.
  • Benefits: Competitive salary, professional development, and a chance to make an impact.
  • Why this job: Be part of a team that enhances security and empowers economies worldwide.
  • Qualifications: Experience in security audits and knowledge of security frameworks required.
  • Other info: Dynamic work environment with opportunities for growth and collaboration.

The predicted salary is between 60000 - 80000 £ per year.

Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.

Main purpose of the role: The Vocalink Control Office function is seeking a Senior Technology Risk Analyst with Information Security knowledge and experience to support the Certification and Assurance team within Vocalink Limited. The role will be responsible for supporting Certifications, Certification Audits, and Assurance activities to support the retention of Vocalink Limited’s certifications and the delivery of assurance requirements including conducting control testing. The role requires an understanding of security and technology controls and frameworks, including working with a variety of standards, e.g. ISO27001, ISO22301, PCI DSS, PCI PIN, Swift, ISAE3000, etc. The applicant must have experience with at least one security standard and a proven ability to analyse or implement information security controls to ensure their design, implementation and operating effectiveness meet the requirements of the standard.

Key Responsibilities

  • Support the preparation for annual certification audits.
  • Support the assessment and validation of controls and processes against a variety of security standards and obligations.
  • Assist in managing certifications (e.g., ISO27001, PCI DSS) and assurance activities (e.g., ISAE3000).
  • Evaluate compliance with internal policies, standards, regulatory requirements, and customer obligations.
  • Prepare clear and accurate control testing documentation, including test procedures, results, and supporting evidence.
  • Support periodic testing of controls in line with a Control Testing Methodology.
  • Timely collection of control testing evidence from relevant Control Owners to support scheduled testing activities.
  • Identify and document control deficiencies, ensuring timely escalation to the Manager and support remediation follow-up activities.

Team Leadership, Collaboration and Stakeholder Engagement

  • Support the team Director in delivering the Certification and Assurance plan.
  • Maintain close working relationships with Control and Process Owners and Operators to operate certificate maintenance and assurance activities efficiently and effectively.
  • Work closely with 1st Line teams to obtain evidence, clarify processes, and ensure accurate testing outcomes.
  • Liaise with 2nd Line Security partners and Internal Audit as directed, ensuring transparency and alignment with control testing activities.
  • Contribute to the preparation of management information, dashboards, and thematic analysis for governance forums.
  • Support control owners by providing observations on control effectiveness and contributing to discussions on remediation approaches.

Governance and Continuous Improvement

  • Support the development of certification management, assurance activities and control testing processes, standards, tools, and methodologies.
  • Adhere to established control testing standards, procedures, and documentation requirements.
  • Provide input on opportunities to streamline testing activities, improve efficiency, and enhance the consistency of outcomes.
  • Contribute to the maturity of the 3 Lines of Defence model and promote a culture of proactive risk management.
  • Stay informed on emerging risks, regulatory changes, certification changes and industry best practices with a focus on cybersecurity risks.

Knowledge, Skills and Expertise (technical / role specific)

  • Experience of conducting security related audits/reviews.
  • Knowledge and experience of all areas of security.
  • Experience in control testing or assurance within security in a regulated environment.
  • Experience operating good practice security audit management and assurance processes.
  • Good investigative and analytical experience (e.g. enquiry, scanning, analysis, interviewing, testing), problem-solving, and decision-making skills.
  • Experience of working with control frameworks and standards (e.g. ISO27001, NIST, CRI, or PCI-DSS).
  • Ability to assess control design and operating effectiveness in complex environments and to identify control gaps and improvement opportunities.
  • Good communication and stakeholder engagement skills.

Qualifications

  • Professional certifications such as CISA, CISM, CISSP, PCI SSC ISA, CRISC, or equivalent is desirable.

Preferred Skills & Attributes

  • Bachelor’s degree in Computer Science, Cyber Security, Information Technology, or a related field.
  • Good Knowledge of security controls and IT general controls across a variety of platforms and environments.
  • Knowledge of security related control frameworks and standards.
  • Proficiency in Microsoft Office Suite (MS Word, MS Excel, MS Access and MS PowerPoint).
  • Strong organisational skills with the ability to prioritise and manage multiple tasks.
  • Self-starter with a continuous improvement mindset and a collaborative approach.

Corporate Security Responsibility

  • Abide by Mastercard’s security policies and practices.
  • Ensure the confidentiality and integrity of the information being accessed.
  • Report any suspected information security violation or breach.
  • Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.

Certification and Assurance - Senior Security/Technology Risk Analyst employer: CareerArc

Mastercard is an exceptional employer that fosters a culture of innovation and collaboration, empowering employees to thrive in their careers. With a commitment to professional development and a focus on sustainability, Mastercard offers a dynamic work environment where team members can engage in meaningful projects that impact economies worldwide. Located in a vibrant area, employees benefit from a diverse workplace, competitive compensation, and opportunities for growth within a global leader in digital payments.
CareerArc

Contact Detail:

CareerArc Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Certification and Assurance - Senior Security/Technology Risk Analyst

✨Tip Number 1

Network like a pro! Get out there and connect with folks in the industry. Attend events, join online forums, or even hit up LinkedIn. The more people you know, the better your chances of landing that dream job.

✨Tip Number 2

Prepare for interviews by researching the company and its culture. Understand their values and how they align with your skills. This will help you tailor your responses and show them you're the perfect fit for the role.

✨Tip Number 3

Practice makes perfect! Do mock interviews with friends or use online resources to get comfortable with common questions. The more you practice, the more confident you'll feel when it’s time to shine.

✨Tip Number 4

Don’t forget to follow up after your interview! A quick thank-you email can go a long way in showing your enthusiasm for the position. Plus, it keeps you on their radar as they make their decision.

We think you need these skills to ace Certification and Assurance - Senior Security/Technology Risk Analyst

Information Security Knowledge
ISO27001
PCI DSS
Control Testing
Security Audits
Analytical Skills
Problem-Solving Skills
Stakeholder Engagement
Communication Skills
Control Frameworks
Regulatory Compliance
Continuous Improvement Mindset
Microsoft Office Suite Proficiency
Organisational Skills
Team Collaboration

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the role of Senior Security/Technology Risk Analyst. Highlight your experience with security standards like ISO27001 or PCI DSS, and showcase any relevant certifications you have. We want to see how your skills align with what we're looking for!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how your background makes you a great fit for our Certification and Assurance team. Keep it concise but impactful – we love a good story!

Showcase Your Analytical Skills: In your application, be sure to highlight your analytical and problem-solving skills. Mention specific examples where you've assessed control effectiveness or identified gaps in security processes. We’re keen on candidates who can think critically and improve our systems.

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, you’ll find all the details you need about the role and our company culture there!

How to prepare for a job interview at CareerArc

✨Know Your Standards

Familiarise yourself with the key security standards mentioned in the job description, like ISO27001 and PCI DSS. Be ready to discuss your experience with these frameworks and how you've applied them in past roles.

✨Showcase Your Analytical Skills

Prepare examples that highlight your investigative and analytical abilities. Think of situations where you identified control gaps or improved processes, as this will demonstrate your problem-solving skills effectively.

✨Engage with Stakeholders

Since the role involves collaboration with various teams, be prepared to discuss how you've successfully engaged with stakeholders in previous positions. Share specific instances where your communication skills made a difference.

✨Continuous Improvement Mindset

Express your commitment to continuous improvement by discussing any initiatives you've led or participated in. Highlight how you stay updated on emerging risks and best practices in cybersecurity to show your proactive approach.

Certification and Assurance - Senior Security/Technology Risk Analyst
CareerArc

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>