Description
Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Lead Information Security Engineer OverviewThe Lead Security Architect candidate will have a high degree of responsibility and will work closely with Network and Security Engineering, Cloud Security, and Enterprise Application teams to design, build and deliver technology solutions and drive alignment to Mastercard policies and standards. This person will research areas of risk and influence changes to policies and technical standards as well as technology requirements for future security services.
The role requires the ability to influence and collaborate across a diverse group of internal stakeholders, effectively managing multiple priorities, demands, and possess a deep understanding of networks and systems in both on-premises and cloud environments.
In this role, the Lead Security Architect will:
- Manage diverse security consulting engagements that include the development and analysis of solution designs, software business cases, implementation plans, and network changes.
- Analyze new and existing technologies and provide recommendations for areas of security risk and alignment to Mastercard's policies and technical standards.
- Solid understanding and working knowledge of system design processes with experience developing designs, defining technical requirements, developing analyses of alternatives, and system architectures.
- Provide guidance for technical teams in defining secure network and system designs and configurations.
- Perform security and threat assessments by identifying inherent risks, exposures, and mitigating controls.
- Lead the development of technical security requirements ensuring appropriate stakeholders are engaged, requirements are updated, prepared for Governance reviews, and published.
- Analyze the security posture of commercial and open source applications to ensure the use cases align with Mastercard's security policies standards.
- Collaborate with other corporate security teams to evaluate new technologies, defining security requirements, performing proof of concept testing, and engaging with vendors.
- Hands-on experience developing concepts of operations and formal procedures for managing systems, developing security use cases, standardizing engineering processes, and developing processes for security operations. Must be able to develop process flow diagrams and narratives with experience in implementing processes in a workflow management solution.
All About You
The qualified candidate must have:
- Experience performing security risk assessments and system configuration audits in an enterprise environment to identify weaknesses and policy non-compliance
- Experience operating an enterprise network including building servers in an on-premises or cloud environment
- A high desire to develop technical and security expertise and have a passion to learn about new technologies, and progressively takes initiative to develop that expertise
- Working knowledge and application of NIST Security Publications, PCI-DSS, and industry standards for hardening systems and software
- Solution design and engineering experience in one or more security domains including Identity & Access Management, Network Security, Application Security, Cryptography, Security Assessment and Testing, Security Operations, and Secure Software Development
- Working experience with firewalls and access control lists
- Experience developing assessment reports, analyses of alternatives, or comprehensive IT solution designs
It would be a bonus if you have:
- Experience with software defined networking concepts and continuous integration and delivery solutions
- A degree in Computer Science or Engineering.
- Security industry certifications such as CISSP, GCIH, or OSCP
- Previous experience as a PCI QSA Mastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact reasonable_accommodation@mastercard.com and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Abide by Mastercard's security policies and practices;
Ensure the confidentiality and integrity of the information being accessed;
Report any suspected information security violation or breach, and
Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
Pay Ranges
O'Fallon, Missouri: $140,000 - $231,000 USDApply on company website