Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Vice President, Software Supply Chain Security
Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Vice President, Software Supply Chain Security
Who is Mastercard?
Mastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential.
Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all.
Mission First, People Always
As Corporate Security, we are responsible for keeping Mastercard safe and secure from cyber and physical threats, and it is our people on the frontlines who make this happen every day.
By taking care of our people, their wellbeing, and career development, we provide them with the necessary tools and environment to ensure the success of our mission.
Overview
The Network Engineering Services team is looking for a Vice President of Software Supply Chain Security. The VP is senior leader responsible for protecting the integrity, provenance, and trustworthiness of all software that powers the company’s global payments ecosystem. This role ensures end-to-end security across internal development, third-party software, CI/CD pipelines, cloud workloads, vendor integrations, and payment processing platforms that require the highest levels of reliability, compliance, and resiliency.
Role
Define the Software Supply Chain Security Strategy aligned to the company’s global payments mission, regulatory obligations, and risk appetite.
Build and lead high performing global DevSecOps, platform engineering, and security automation teams.
Architect security for CI/CD pipelines, infrastructure-as-code frameworks, and automation platforms
Embed security controls into development workflows, including SAST/DAST, SBOM, dependency scanning, secrets management, to eliminate preventable exposure
Establish governance for software bill of materials (SBOM), artifact integrity, code provenance, and policy-as-code guardrails
Promote a secure-by-default engineering culture with paved roads for secure component consumption, signing, building, and deployment.
Parter with Vulnerability Management on strategy and outcomes for end-to-end detection, triage, risk acceptance, remediation, validation and overall exposure management
Partner with DevOps on cloud strategy and operations (AWS, Azure, GCP, or hybrid), ensuring resilient, scalable, and secure infrastructure.
Partner with Legal, Third-Party Risk Management (TPRM), and Procurement to enforce contractual obligations for secure development, reporting, incident notification, and replace/patch SLAs.
All About You
Demonstrated effectiveness leading Security, Platform/DevOps, or Software Engineering teams
Proven track record of implementing software supply chain controls across complex, multicloud and hybrid environments.
Demonstrated ability to balance regulatory, security, and developer experience requirements at enterprise scale.
Deep expertise in CI/CD, artifact registries, Kubernetes/container security, cryptographic signing, and OSS governance.
Strong knowledge of SLSA, NIST SSDF, OWASP SCVS/SCVST, ISO 27001/27036, and regulatory frameworks
Hands-on familiarity with SAST/DAST/IAST/SCA, secrets and dependency management, API security, and runtime protections
Strong stakeholder management and executive communication skills; proven record influencing Product and Engineering leaders.
NICE Framework references
• National Initiative for Cybersecurity Education (NICE) competency proficiency levels of limited in leadership, limited to developing in operational and professional, and developing to proficient in technical.
• This Mastercard role shares KSAs with related NICE work roles
o OV-SPP-002, OPM751, Cyber Policy and Strategy Planner
o OV-EXL-001, OPM901, Executive Cyber Leadership
o OV-MGT-001, OPM722, Information Systems Security Manager
Mastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact reasonable_accommodation@mastercard.com and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Abide by Mastercard’s security policies and practices;
Ensure the confidentiality and integrity of the information being accessed;
Report any suspected information security violation or breach, and
Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.
In line with Mastercard’s total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary and may be eligible for an annual bonus or commissions depending on the role. The base salary offered may vary depending on multiple factors, including but not limited to location, job-related knowledge, skills, and experience. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance); flexible spending account and health savings account; paid leaves (including 16 weeks of new parent leave and up to 20 days of bereavement leave); 80 hours of Paid Sick and Safe Time, 25 days of vacation time and 5 personal days, pro-rated based on date of hire; 10 annual paid U.S. observed holidays; 401k with a best-in-class company match; deferred compensation for eligible roles; fitness reimbursement or on-site fitness facilities; eligibility for tuition reimbursement; and many more. Mastercard benefits for interns generally include: 56 hours of Paid Sick and Safe Time; jury duty leave; and on-site fitness facilities in some locations.
Pay Ranges
O'Fallon, Missouri: $212,000 - $339,000 USD