Our Purpose
We work to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments and businesses realize their greatest potential. Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. We cultivate a culture of inclusion for all employees that respects their individual strengths, views, and experiences. We believe that our differences enable us to be a better team – one that makes better decisions, drives innovation and delivers better business results.
Title and Summary
Lead Information Security Engineer
Who is Mastercard?
Mastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential.
Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all.
Mission First, People Always
As Corporate Security, we are responsible for keeping Mastercard safe and secure from cyber and physical threats, and it is our people on the frontlines who make this happen every day.
By taking care of our people, their wellbeing, and career development, we provide them the necessary tools and environment to ensure the success of our mission.
Overview
The Lead Security Architect candidate will have a high degree of responsibility and will work closely with Network and Security Engineering, Cloud Security, and Enterprise Application teams to design, build and deliver technology solutions and drive alignment to Mastercard policies and standards. This person will research areas of risk and influence changes to policies and technical standards as well as technology requirements for future security services.
The role requires the ability to influence and collaborate across a diverse group of internal stakeholders, effectively managing multiple priorities, demands, and possess a deep understanding of networks and systems in both on-premises and cloud environments.
In this role, the Lead Information Security Engineer will:
Manage diverse security consulting engagements that include the development and analysis of solution designs, software business cases, implementation plans, and network changes.
Analyze new and existing technologies and provide recommendations for areas of security risk and alignment to Mastercard’s policies and technical standards.
Solid understanding and working knowledge of system design processes with experience developing designs, defining technical requirements, developing analyses of alternatives, and system architectures.
Provide guidance for technical teams in defining secure network and system designs and configurations.
Perform security and threat assessments by identifying inherent risks, exposures, and mitigating controls.
Lead the development of technical security requirements ensuring appropriate stakeholders are engaged, requirements are updated, prepared for Governance reviews, and published.
Analyze the security posture of commercial and open source applications to ensure the use cases align with Mastercard’s security policies standards.
Collaborate with other corporate security teams to evaluate new technologies, defining security requirements, performing proof of concept testing, and engaging with vendors.
Hands-on experience developing concepts of operations and formal procedures for managing systems, developing security use cases, standardizing engineering processes, and developing processes for security operations. Must be able to develop process flow diagrams and narratives with experience in implementing processes in a workflow management solution.
All About You
The qualified candidate must have:
Experience performing security risk assessments and system configuration audits in an enterprise environment to identify weaknesses and policy non-compliance
Experience operating an enterprise network including managing security infrastructure in an on-premises or cloud environment
A high desire to develop technical and security expertise and have a passion to learn about new technologies, and progressively takes initiative to develop that expertise
Working knowledge and application of NIST Security Publications, PCI-DSS, and industry standards for hardening systems and software
Solution design and engineering experience in one or more security domains including Identity & Access Management, Network Security, Application Security, Cryptography, Security Assessment and Testing, Security Operations, and Secure Software Development
Working experience with firewalls and access control lists
Experience developing assessment reports, analyses of alternatives, or comprehensive IT solution designs
It would be a bonus if you have:
Experience with software defined networking concepts and continuous integration and delivery solutions
A degree in Computer Science or Engineering.
Security industry certifications such as CISSP, GCIH, or OSCP
Previous experience as a PCI QSA
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Abide by Mastercard’s security policies and practices;
Ensure the confidentiality and integrity of the information being accessed;
Report any suspected information security violation or breach, and
Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.