Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Manager, Risk Management Cyber Security
Role Profile/Job Description
Who is Mastercard:
Mastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential.
Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all.
Role Overview:
This role sits within the Second Line of Defence (2LOD) Risk function and provides independent oversight and challenge of Cyber Security risk across Vocalink Mastercard. You will act as a functional risk partner to the First Line of Defence Cyber Security function, ensuring robust risk management practices are embedded and aligned with regulatory expectations and industry best practice.
The role supports the delivery of a secure and resilient service to millions of citizens and businesses, safeguarding critical payment infrastructure and data assets. You will champion cyber security and resilience risk internally and at senior management level, helping to maintain trust in the UK financial system.
This role will report into the Vice President of Risk Management (Cyber Security).
The Role Holder Will:
• Provide second line expertise and challenge around all aspects of Cyber Security related risks
• Support the Vocalink risk management approach and implemented policies and procedures to minimize Cyber Security risk exposure and drive robust controls.
• Support the implementation and embedding of the Enterprise Risk Management Framework for Cyber Security risk, ensuring completeness and accuracy of risk assessments, control standards, residual risk evaluations, and issue management.
• Partner with first line Cyber Security teams to promote balanced risk-taking and a strong risk culture.
• Represent Cyber Security risk at relevant committees and forums, deputising for the VP Risk Management when required.
• Provide clear and concise risk briefings to senior stakeholders, including the CRO ensuring timely escalation of material risks and appetite breaches.
• Liaise with and support the risk and control owners to resolve any questions, queries and challenges relating to cyber security relevant certification and or customer requirements for example, during an audit as well as in the pre and post audit stages.
All About You (Knowledge, Skill, and Experience):
• Professional cyber security certifications (e.g., CRISC, CISA, CISM, CISSP, ISO 27001 Lead Auditor) preferred.
• Knowledge of key cyber security relevant control domains, frameworks and standards (e.g., NIST, ISO27001, CSF, CRI, MITRE, etc.).
• Strong understanding of risk management principles and the Three Lines of Defence model.
• Enthusiastic about cyber security including tracking industry trends and emerging risks
• Experience of applying operational risk frameworks and understanding of risk assessment methodologies
• Proven experience in Cyber Security risk and controls oversight within a financial institution or critical infrastructure environment.
• Ability to analyse complex data with attention to detail and articulate risk insights clearly to technical and non-technical audiences.
• Skilled in building trusted relationships with stakeholders at all levels.
• Highly organised, adaptable, and able to work independently with minimal supervision and as part of a team.
• Excellent written and verbal communication skills.
Desirable:
• Experience within Critical National Infrastructure responsible organisations
• Financial Services experience particularly in payments and relevant infrastructure
• Experience working with regulators (Bank of England supervision)
Corporate Security Responsibility:
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
• Abide by Mastercard’s security policies and practices;
• Ensure the confidentiality and integrity of the information being accessed;
• Report any suspected information security violation or breach, and
• Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Abide by Mastercard’s security policies and practices;
Ensure the confidentiality and integrity of the information being accessed;
Report any suspected information security violation or breach, and
Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.