At a Glance
- Tasks: Lead assessments and manage compliance for Mastercard's technology risk environment.
- Company: Join Mastercard, a global leader in digital payments, empowering economies in over 200 countries.
- Benefits: Enjoy flexible work options, competitive pay, and opportunities for professional growth.
- Why this job: Be part of a team that balances innovation with security, making a real impact on the economy.
- Qualifications: Bachelor's degree in IT or related field; experience with control frameworks and audits is essential.
- Other info: Ideal for tech-savvy problem solvers who thrive in a collaborative, diverse environment.
The predicted salary is between 48000 - 72000 £ per year.
Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we are helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
The Mastercard Technology Risk Team is looking for an Assurance Manager to oversee the assurance program supporting requirements to meet customer and regulatory obligations for various regions. The focus of the position is on providing readiness and compliance support, monitoring, and reporting of the operating effectiveness of Mastercard's internal control environment. The role is a pivotal part of the Mastercard technology risk function. Mastercard is committed to balancing innovation while protecting the internal control posture. The team assesses internal controls to proactively identify risks, define remediation actions and track remediation efforts. We are looking for someone to join our team and help us meet these compliance goals. This person will be technically savvy and likes to solve issues and drive outcomes.
The ideal candidate will have the ability to think and act both strategically and tactically while ensuring that the organization remains compliant with required security, technology, and financial standards, as well as industry best practices.
Responsibilities:- Lead evaluations and assessments
- Develop, plan, and execute control assessments of various IT (security) and, to a lesser extent, business areas to assess potential risks or control gaps, beyond procedural aspects, and also including technical configurations.
- Understand the materiality of findings to live services.
- Report formally on the results of assurance/certification objectives, controls and risk assessments.
- Manage control inquiries from both internal and external stakeholders.
- Engage with customers to design control frameworks to ensure assurance needs and expectations are met for various certifications (e.g., ISAE, SOC).
- Engage with auditors to develop, mature and evaluate the control framework to ensure objectives are met and risk is managed effectively.
- Engage with internal stakeholders to make feasibility evaluations and cost/benefit analyses for control implementation.
- Establish and track remediation through to resolution whilst improving design and operating effectiveness of controls.
- Reduce error ratings and risk exposure as a result of gaps in control performance.
- Develop and maintain reports, metrics and presentations of progress and results for meetings with internal stakeholders, customers, and regulators.
- Provide data analysis and strategy execution across risk areas, leveraging an understanding of risk and regulations.
- You have proven experience in successfully implementing and evaluating control frameworks (e.g., ISAE 3402, ISAE 3000 and SOC 2) and/or managing and executing technology audits.
- You have a Bachelor’s degree in computer science, information technology, IT/technology audit or related field, or an equivalent combination of education and experience.
- You are comfortable with the Trust Services Criteria (TSC), the five principles (security, availability, processing integrity, confidentiality, and privacy) and how to achieve them across various platforms is essential.
- Professional certification like CISSP, CISA, CRISC or similar is highly valued.
- Familiarity with the financial services industry and payment processing industry is a plus.
- You have strong interpersonal, communication and presentation skills necessary for interaction with business leaders and teams across all levels of the organization.
- You will contribute to a work environment that encourages knowledge of, respect for and development of skills to engage with those of other cultures and backgrounds.
- You are comfortable to challenge strategy and approach, but also have the pragmatism to successfully negotiate and build consensus.
All activities involving access to Mastercard assets, information, and networks come with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
- Abide by Mastercard's security policies and practices;
- Ensure the confidentiality and integrity of the information being accessed;
- Report any suspected information security violation or breach, and
- Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
Lead Technology Risk Analyst employer: Hispanic Alliance for Career Enhancement
Contact Detail:
Hispanic Alliance for Career Enhancement Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Lead Technology Risk Analyst
✨Tip Number 1
Familiarise yourself with the specific control frameworks mentioned in the job description, such as ISAE 3402 and SOC 2. Understanding these frameworks will not only help you in interviews but also demonstrate your commitment to the role.
✨Tip Number 2
Network with professionals in the technology risk field, especially those who have experience with Mastercard or similar companies. Engaging in conversations can provide insights into the company culture and expectations, which can be invaluable during the interview process.
✨Tip Number 3
Prepare to discuss real-world examples of how you've implemented or evaluated control frameworks in past roles. Being able to articulate your hands-on experience will set you apart from other candidates.
✨Tip Number 4
Stay updated on the latest trends and regulations in the financial services and payment processing industries. Showing that you are knowledgeable about current events and changes in the industry can impress interviewers and highlight your proactive approach.
We think you need these skills to ace Lead Technology Risk Analyst
Some tips for your application 🫡
Understand the Role: Before applying, make sure you fully understand the responsibilities and requirements of the Lead Technology Risk Analyst position. Tailor your application to highlight relevant experiences that align with the job description.
Highlight Relevant Experience: In your CV and cover letter, emphasise your experience with control frameworks like ISAE 3402 or SOC 2, as well as any technology audits you've managed. Use specific examples to demonstrate your skills in risk assessment and compliance.
Showcase Technical Skills: Mention any technical certifications you hold, such as CISSP or CISA, and detail your familiarity with Trust Services Criteria. This will show that you have the necessary technical knowledge for the role.
Craft a Compelling Cover Letter: Write a cover letter that not only outlines your qualifications but also conveys your passion for technology risk management. Discuss how you can contribute to Mastercard's goals of balancing innovation with security.
How to prepare for a job interview at Hispanic Alliance for Career Enhancement
✨Understand the Role Thoroughly
Before your interview, make sure you have a solid grasp of the Lead Technology Risk Analyst role. Familiarise yourself with the key responsibilities, such as control assessments and compliance support, so you can discuss how your experience aligns with these tasks.
✨Showcase Your Technical Knowledge
Since the role requires a strong understanding of control frameworks like ISAE and SOC, be prepared to discuss your experience with these standards. Highlight any relevant certifications, such as CISSP or CISA, and provide examples of how you've implemented or evaluated control frameworks in past roles.
✨Prepare for Scenario-Based Questions
Expect questions that assess your problem-solving skills and ability to handle risk management scenarios. Think of specific examples from your previous work where you identified risks, designed remediation strategies, or improved control effectiveness, and be ready to share these during the interview.
✨Demonstrate Strong Communication Skills
As this role involves interaction with various stakeholders, it's crucial to showcase your interpersonal and communication skills. Practice articulating complex technical concepts in a clear and concise manner, and be prepared to discuss how you've successfully collaborated with teams across different levels in your previous positions.