We work to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments and businesses realize their greatest potential. Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. We cultivate a culture of inclusion (https://www.mastercard.us/en-us/vision/who-we-are/diversity-inclusion.html) for all employees that respects their individual strengths, views, and experiences. We believe that our differences enable us to be a better team – one that makes better decisions, drives innovation and delivers better business results.
Lead Information Security Engineer
The Business Security Enablement (BSE) team is looking for a Lead Security Engineer to join us focused on supporting and critically securing our SaaS technology and deployments. The Business Security Enablement guild is a worldwide team of information security experts focused on helping Mastercard achieve its goals by ensuring security is a first though in design in everything we do. Mastercard is researching and developing the next generation of products, services, and solutions at scale to enable consumers to conduct transactions securely, efficiently, and intelligently far beyond traditional payment cards that you may know us for.
• Can you demonstrate a high level of expertise in information security and secure engineering disciplines?
• Can you demonstrate an advanced working level in application technology and security best practices?
• Can you advise product and operational teams on how to securely adopt and deploy SaaS following industry best practices and enhance existing security?
• Can you analyze a solution to reduce the security risk to an acceptable level while still providing beneficial functionality for the end user?
• Apply knowledge of security principles, theories and concepts to business and development life cycle.
• Take a Lead Security Position in larger, more complex initiatives for our CX&D program (e.g., global initiatives, cross functional/cross geographies).
• Provide strategic leadership regarding organization-wide risks, standards, technologies, and methodologies.
• Work closely with program engineers to evaluate business requests to determine feasibility.
• Provide and recommend optimal solutions to meet security and regulatory requirements in the design of new/enhanced systems.
• Ensure established security policies and standards are observed on projects.
• Provide technical support for business owners to ensure adherence to requirements and document problem areas with resolutions.
• Document enhancements to security standards and procedures.
• Prepare and present business/technical presentations.
• Investigate/Research MasterCard or industry business/technical security processes.
All About You
• Adaptive communication skills to influence cross-functionally without direct authority, comfort speaking with customers and business partners at all levels.
• Motivated self-starter with agility and ability to manage ambiguity, and deal with and anticipate change while still meeting business objectives.
• Passion for great product design, security, and usability.
• Experience with application threat modeling or other risk identification techniques.
• Experienced in mobile security architecture concepts, design, and implementation for Android and iOS is a plus.
• Current knowledge of security best practices, common exploits, and threat landscape.
• Strong understanding of Information Security, Authentication, and Data Privacy within the domain of Digital Commerce including relevant practical experience.
• Demonstrated experience designing secure multi-domain internet-facing applications.
• Knowledge of the security architecture of web-based network environments and secure communication between environments
• Knowledge and technical security experience in Cryptography, including several of the following: PKI, Digital Certificates, SSL, Hashing, Encryption techniques, and so on.
• Good understanding of Software Development especially related to secure coding best practices. Prior experience programming in Java is a plus.
• Understanding of Agile methodologies
We value the safety of each member of our community because we know we’re all in this together. In many locations, which may change over time, we’ve implemented a virtual hiring process and continue to interview candidates by video or phone. In addition, in some locations, only individuals who have been fully vaccinated will be permitted inside Mastercard offices until further notice.
In the US, Mastercard is a government contractor, which may legally require most Mastercard employees to be vaccinated unless a verified approved medical or religious exemption is granted. Further, we are currently making every effort towards having employees return to work in the office 2 days per week, if that makes sense for their team. Everyone must be vaccinated to enter Mastercard offices at this time. Therefore, we expect all candidates to be vaccinated or to be approved for a medical or religious accommodation prior to commencing work at Mastercard.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Abide by Mastercard’s security policies and practices;
Ensure the confidentiality and integrity of the information being accessed;
Report any suspected information security violation or breach, and
Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.
Requisition ID: R-167071