At a Glance
- Tasks: Lead and manage control testing and certification audits for security standards.
- Company: Join Vocalink Limited, a leader in innovative financial technology.
- Benefits: Competitive salary, career growth, and a dynamic work environment.
- Why this job: Make a real impact in cybersecurity and compliance at a director level.
- Qualifications: Extensive experience with security frameworks and strong leadership skills.
- Other info: Collaborative culture with opportunities to mentor junior team members.
The predicted salary is between 72000 - 108000 £ per year.
The newly created 1st Line Control Office function within Vocalink Limited (VLL) is seeking a Principal Analyst (Director-level equivalent), to join the Control Testing, Certification and Assurance team. This senior technical role is for an experienced technical subject matter expert who will be responsible for leading and managing Certifications, Certification Audits, and other Assurance activities including conducting control testing to drive the retention of VLL’s certifications across multiple frameworks and the delivery of assurance obligations to its customers and Regulators.
This position requires a deep and broad understanding of security and technology control frameworks, with hands-on experience across standards such as: ISO 27001, ISO 22301, PCI DSS, PCI PIN, SWIFT CSP, ISAE 3000 etc. The successful candidate must have proven expertise in analysing and assessing control design, implementation and operating effectiveness against these standards, ensuring compliance and identifying gaps. The role also involves end-to-end management of external audits, requiring strong coordination skills and experience in audit readiness and stakeholder engagement.
The role has a significant emphasis on PCI DSS, so the successful candidate must have extensive experience in understanding and testing against PCI DSS requirements, and managing all aspects of the PCI DSS external audit process.
Key Responsibilities- Lead and manage external audits for technical standards, e.g. PCI DSS and PCI PIN.
- Support the Vice President and Director of Certification and Assurance in the development and maintenance of the annual Control Testing, Certification and Assurance plan.
- Provide strategic input into the evolution and continuous improvement of Certification and Assurance team processes and procedures.
- Maintain certification related documentation.
- Prepare and lead the organisation for annual certification audits.
- Lead the assessment and validation of controls and processes against a variety of security standards and obligations.
- Conduct periodic testing of key and non-key controls in line with the Control Testing Methodology.
- Evaluate compliance with internal policies, standards, regulatory requirements, and customer obligations.
- Prepare and review control testing documentation, including test procedures, results, and identified gaps.
- Ensure timely escalation of control deficiencies and support remediation tracking.
- Create and quality assure reports and team outputs.
- Supervise and mentor junior team members (Senior Analysts and Managers), providing guidance on certification requirements, assurance requirements, testing execution and quality assurance.
- Maintain close working relationships with Control and Process Owners and Operators to operate certificate maintenance and assurance activities efficiently and effectively.
- Contribute to reporting for governance forums, including dashboards, thematic reviews, and trend analysis.
- Support the development and refinement of certification management, Assurance activities and control testing processes, standards, tools, and methodologies.
- Stay informed on emerging risks, regulatory changes, certification changes and industry best practices with a focus on cybersecurity risks.
- Strong understanding and experience of working with control frameworks and standards (e.g. ISO27001, NIST, CRI, or PCI DSS).
- Strong understanding and experience of conducting security related audits/reviews and managing/coordinating external audits including certification audits.
- Experience of resolving varied and complex certification and assurance issues.
- Proven experience in control testing or assurance within security in a regulated environment.
- Excellent communication and stakeholder engagement skills.
- Strong organisational skills with the ability to prioritise and manage multiple tasks.
- Certifications such as ISO27001, CISA, CISM, CISSP, PCI SSC ISA, CRISC, or equivalent is desirable.
- Bachelor’s degree in Computer Science, Cyber Security, Information Technology, or a related field.
- Experience engaging with senior leadership at the Executive level and above.
- Proficiency in data analytics and Microsoft Office Suite (MS Word, MS Excel, MS Access and MS PowerPoint).
- Self-starter with a continuous improvement mindset and a collaborative approach.
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must abide by Mastercard’s security policies and practices.
Principal Analyst, Control Testing, Certification and Assurance (Director Level) in Harrogate employer: MasterCard
Contact Detail:
MasterCard Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Principal Analyst, Control Testing, Certification and Assurance (Director Level) in Harrogate
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the industry. Attend events, webinars, or even local meetups. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching the company and its culture. Understand their values and how they align with your own. This will help you tailor your responses and show that you're genuinely interested in being part of their team.
✨Tip Number 3
Practice makes perfect! Conduct mock interviews with friends or mentors to get comfortable with common questions. This will help you articulate your experience and skills confidently when it counts.
✨Tip Number 4
Don’t forget to follow up after interviews! A simple thank-you email can go a long way in leaving a positive impression. Plus, it shows your enthusiasm for the role and keeps you on their radar.
We think you need these skills to ace Principal Analyst, Control Testing, Certification and Assurance (Director Level) in Harrogate
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to highlight your experience with control frameworks and standards like PCI DSS and ISO27001. We want to see how your skills align with the role, so don’t hold back on showcasing your relevant achievements!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you’re the perfect fit for the Principal Analyst role. Share specific examples of your past experiences that relate to the responsibilities outlined in the job description.
Showcase Your Leadership Skills: Since this is a director-level position, we’re keen to see your leadership experience. Highlight any instances where you’ve led teams or managed projects, especially in relation to certification audits and assurance activities.
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands. Plus, it shows us you’re serious about joining our team at StudySmarter!
How to prepare for a job interview at MasterCard
✨Know Your Standards Inside Out
Make sure you have a solid grasp of the key control frameworks mentioned in the job description, especially PCI DSS. Brush up on the requirements and be ready to discuss how you've applied them in your previous roles.
✨Showcase Your Audit Experience
Prepare specific examples of your experience managing external audits. Highlight your role in coordinating these processes and any challenges you overcame. This will demonstrate your hands-on expertise and leadership skills.
✨Engage with Stakeholders
Think about how you've collaborated with various stakeholders in past roles. Be ready to share examples of how you maintained relationships and communicated effectively, as this is crucial for the role.
✨Demonstrate Continuous Improvement Mindset
Be prepared to discuss how you've contributed to process improvements in your previous positions. Share specific instances where your initiatives led to better compliance or efficiency, showing that you're proactive and forward-thinking.