Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Senior Information Security Engineer
Overview
The Senior Information Security Engineer candidate will have a high degree of responsibility and will work closely with Network and Security Engineering, Cloud Security, and Enterprise Application teams to design, build and deliver technology solutions and drive alignment to Mastercard policies and standards. This person will research areas of risk and influence changes to polices and technical standards as well as technology requirements for future security services.
The role requires the ability to influence and collaborate across a diverse group of internal stakeholders, effectively managing multiple priorities, demands, and possess a deep understanding of networks and systems in both on-premises and cloud environments.
In this role, the Senior Information Security Engineer will:
Manage diverse security consulting engagements that include the development and analysis of solution designs, software business cases, implementation plans, and network changes.
Analyze new and existing technologies and provide recommendations for areas of security risk and alignment to Mastercard’s policies and technical standards.
Build and sustain strong working relationships with internal stakeholders to collaboratively design, develop, and implement secure technology solutions.
Participate in defining secure network and system designs and configurations.
Perform security and threat assessments to identify inherent risks, exposures, and mitigating controls.
Provide support for the development of technical security requirements ensuring appropriate stakeholders are engaged, requirements are updated, prepared for Governance reviews, and published.
Analyze the security posture of commercial and opensource applications to ensure the use cases align with Mastercard’s security policies standards.
Collaborate with other corporate security teams to evaluate new technologies, defining security requirements, performing proof of concept testing, and engaging with vendors.
All About You
The qualified candidate must have:
A high desire to develop technical and security expertise and have a passion to learn about new technologies, and progressively takes initiative to develop that expertise
Working knowledge and application of NIST Security Publications, PCI-DSS, and industry standards for hardening systems and software
Experience operating an enterprise network including building servers in an on-premises or cloud environment
Experience performing security assessments or system configuration audits in an enterprise environment to identify weaknesses and policy non-compliance
Solution design and engineering experience in one or more security domains including Identity & Access Management, Network Security, Application Security, Cryptography, Security Assessment and Testing, Security Operations, and Secure Software Development
Working experience with firewalls and access control lists
Experience developing assessment reports, analyses of alternatives, or comprehensive IT solution designs
It would be a bonus if you have:
Experience with software defined networking concepts and continuous integration and delivery solutions
A degree in Computer Science or Engineering.
Security industry certifications such as CISSP, GCIH, or OSCP
Previous experience as a PCI QSA
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Abide by Mastercard’s security policies and practices;
Ensure the confidentiality and integrity of the information being accessed;
Report any suspected information security violation or breach, and
Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.