At a Glance
- Tasks: Lead assessments and develop control frameworks to ensure compliance and manage risks.
- Company: Mastercard powers economies globally, making transactions secure and accessible for everyone.
- Benefits: Enjoy a dynamic work environment with opportunities for professional growth and innovation.
- Why this job: Join a team that balances innovation with security, making a real impact in the tech world.
- Qualifications: Bachelor's degree in IT or related field; experience with control frameworks and technology audits required.
- Other info: Professional certifications like CISSP or CISA are highly valued; strong communication skills essential.
The predicted salary is between 48000 - 72000 £ per year.
Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we are helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realise their greatest potential.
The Mastercard Technology Risk Team is looking for an Assurance Manager to oversee the assurance program supporting requirements to meet customer and regulatory obligations for various regions. The focus of the position is on providing readiness and compliance support, monitoring, and reporting of the operating effectiveness of Mastercard's internal control environment. The role is a pivotal part of the Mastercard technology risk function. Mastercard is committed to balancing innovation while protecting the internal control posture. The team assesses internal controls to proactively identify risks, define remediation actions and track remediation efforts. We are looking for someone to join our team and help us meet these compliance goals. This person will be technically savvy and likes to solve issues and drive outcomes.
The ideal candidate will have the ability to think and act both strategically and tactically while ensuring that the organisation remains compliant with required security, technology, and financial standards, as well as industry best practices.
Responsibilities:- Lead evaluations and assessments
- Develop, plan, and execute control assessments of various IT (security) and, to a lesser extent, business areas to assess potential risks or control gaps, beyond procedural aspects, and also including technical configurations
- Understand the materiality of findings to live services
- Report formally on the results of assurance/certification objectives, controls and risk assessments
- Manage control inquiries from both internal and external stakeholders
- Control framework and policy development
- Engage with customers to design control frameworks to ensure assurance needs and expectations are met for various certifications (e.g., ISAE, SOC...)
- Engage with auditors to develop, mature and evaluate the control framework to ensure objectives are met and risk is managed effectively
- Engage with internal stakeholders to make feasibility evaluations and cost/benefit analyses for control implementation
- Remediation design and tracking
- Establish and track remediation through to resolution whilst improving design and operating effectiveness of controls
- Reduce error ratings and risk exposure as a result of gaps in control performance
- Develop and maintain reports, metrics and presentations of progress and results for meetings with internal stakeholders, customers, and regulators
- Provide data analysis and strategy execution across risk areas, leveraging an understanding of risk and regulations
- You have proven experience in successfully implementing and evaluating control frameworks (e.g., ISAE 3402, ISAE 3000 and SOC 2) and/or managing and executing technology audits
- You have a Bachelor's degree in computer science, information technology, IT/technology audit or related field, or an equivalent combination of education and experience
- You are comfortable with the Trust Services Criteria (TSC), the five principles (security, availability, processing integrity, confidentiality, and privacy) and how to achieve them across various platforms is essential
- Professional certification like CISSP, CISA, CRISC or similar is highly valued
- Familiarity with the financial services industry and payment processing industry is a plus
- You have strong interpersonal, communication and presentation skills necessary for interaction with business leaders and teams across all levels of the organization
- You will contribute to a work environment that encourages knowledge of, respect for and development of skills to engage with those of other cultures and backgrounds
- You are comfortable to challenge strategy and approach, but also have the pragmatism to successfully negotiate and build consensus
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
- Abide by Mastercard's security policies and practices;
- Ensure the confidentiality and integrity of the information being accessed;
- Report any suspected information security violation or breach, and
- Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
Lead Technology Risk Analyst employer: Mastercard, Inc.
Contact Detail:
Mastercard, Inc. Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Lead Technology Risk Analyst
✨Tip Number 1
Familiarise yourself with the specific control frameworks mentioned in the job description, such as ISAE 3402 and SOC 2. Understanding these frameworks will not only help you in interviews but also demonstrate your commitment to the role.
✨Tip Number 2
Network with professionals in the technology risk and compliance fields. Attend industry events or webinars where you can meet people who work at Mastercard or similar companies. This can provide valuable insights and potentially lead to referrals.
✨Tip Number 3
Brush up on your knowledge of the Trust Services Criteria (TSC) and how they apply across various platforms. Being able to discuss these principles confidently will set you apart during discussions with hiring managers.
✨Tip Number 4
Prepare to showcase your problem-solving skills by thinking of examples from your past experience where you've successfully identified and remediated risks. Be ready to discuss these scenarios in detail during your interview.
We think you need these skills to ace Lead Technology Risk Analyst
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in technology risk management and control frameworks. Use keywords from the job description, such as 'control assessments', 'risk exposure', and 'compliance goals' to demonstrate your fit for the role.
Craft a Compelling Cover Letter: In your cover letter, express your passion for technology risk and compliance. Mention specific experiences where you've successfully implemented control frameworks or managed audits, and how these relate to Mastercard's mission of empowering economies.
Showcase Relevant Certifications: If you hold any professional certifications like CISSP, CISA, or CRISC, make sure to highlight them prominently in your application. These credentials are highly valued and can set you apart from other candidates.
Prepare for Technical Questions: Be ready to discuss your understanding of the Trust Services Criteria and how you have applied them in previous roles. Prepare examples that showcase your ability to assess risks and develop remediation strategies effectively.
How to prepare for a job interview at Mastercard, Inc.
✨Understand the Role Thoroughly
Before the interview, make sure you have a solid grasp of what the Lead Technology Risk Analyst position entails. Familiarise yourself with the key responsibilities, such as control assessments and compliance support, so you can speak confidently about how your experience aligns with these tasks.
✨Showcase Your Technical Savvy
Given the technical nature of this role, be prepared to discuss your experience with control frameworks like ISAE and SOC. Highlight specific examples where you've successfully implemented or evaluated these frameworks, demonstrating your ability to manage technology audits effectively.
✨Prepare for Scenario-Based Questions
Expect questions that assess your problem-solving skills in real-world scenarios. Think of situations where you've identified risks or gaps in controls and how you addressed them. This will showcase your strategic and tactical thinking abilities.
✨Emphasise Communication Skills
As this role involves interaction with various stakeholders, it's crucial to demonstrate your strong interpersonal and communication skills. Be ready to provide examples of how you've effectively communicated complex information to different audiences, ensuring clarity and understanding.