Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
VP, Technology Risk ManagementOverviewThe Technology Risk and Controls Governance (TR&CG) organization is a business enabler and industry leader in technology and security risk management practices, supported by a multidisciplinary team of technology, security, and risk professionals. Our mission is to exceed stakeholder expectations by providing enhanced visibility into technology risks, strengthening governance practices, and promoting a secure and resilient operational environment.
Within TR&CG, the Technology Controls Governance (TCG) team is responsible for establishing and maturing technology controls, standards, risk management, and control testing practices across Mastercard's technology landscape. The TCG team is seeking a Vice President, Technology Risk Management to drive alignment across enterprise risk management, technology controls, standards, and testing functions within the first and second lines of defense. This individual will help shape and execute a unified multi-year strategy that enables consistent implementation and sustainable risk management practices across first-line technology organizations.
Responsibilities
- Lead the planning, execution, reporting, and continuous improvement of Mastercard's technology control testing methodology.
- Align strategic and tactical objectives across TR&CG to ensure Technology Risk and Controls Management capabilities can be effectively implemented by any Mastercard organization that manages technology assets.
- Develop and maintain risk-based testing methodologies, including testing frequencies, control inventories, testing priorities, and standardized approaches for integration entities such as mergers and acquisitions and directly regulated entities.
- Serve as a strategic partner to business owners and stakeholders by providing guidance on control design, remediation, testing prioritization, and technology integration within existing frameworks to reduce risk exposure and strengthen control effectiveness.
- Partner with Technology, Risk, Second Line of Defense, and Regulatory teams to continuously enhance testing processes through iterative feedback, align executive expectations, and drive complex cross-functional risk initiatives.
- Assist in the standardization of control management practices for integration entities, including mergers and acquisitions and directly regulated entities, while managing variances from business-as-usual processes.
- Establish and oversee the integration of controls into emerging technologies while streamlining testing procedures, evidence requirements, sampling methodologies, and scalable business processes.
- Drive standardization, automation, AI, analytics, and process optimization to enhance control effectiveness, compliance, auditability, and operational efficiency.
- Analyze federated testing priorities, identify opportunities for testing synergies, and develop executive reporting and presentations on program progress.
- Provide guidance to First and Second Line of Defense stakeholders to inform testing decisions, connect control testing results to emerging risk themes, and communicate key insights to leadership and governance forums.
- Develop and maintain consolidated reporting, metrics, and continuous maturity assessments to measure program effectiveness and support strategic decision-making.
- Support audits, regulatory examinations, and assurance activities through clear reporting, documentation, consolidated metrics, and presentations of progress and results for First and Second Line of Defense stakeholders.
- Manage collaborative relationships across the organization and influence the ongoing maturity of Mastercard's technology risk and control environment.
Requirements
- Degree in technology, information systems management, information security management, security policy or related program desired, but not required.
- IT certification(s) preferred such as CISSP/CISA/CRISC.
- Familiarity with industry frameworks such as NIST, ISO 27001, SOX, SOC 1/2, PCI, CRI, or UCF preferred.
- Strong knowledge of regulatory technology and security risk management expectations.
- Expertise in current and emerging technologies and their potential for exploitation.
- Bridge governance and execution by developing scalable operating models, processes, and stakeholder relationships that enable business units to effectively implement risk management, controls, and control testing requirements.
- Deep knowledge of business unit risk and control frameworks, including the oversight and governance of control testing activities to support compliance, risk management, and continuous improvement.
- Familiarity with laws, regulations, policies, and ethics as they relate to cybersecurity and IT management (GDPR, FBA, CBA, CROE, etc.).
- Project management expertise, including planning, prioritization, stakeholder management, risk mitigation, resource coordination, and delivery of complex initiatives.
- Experience collaborating cross-functionally, geographically to identify and implement best practice assurance/compliance processes.
- Systematic problem-solving approach, coupled with strong communication skills and a sense of ownership and drive.
•Proven success in navigating multi-national organizations and operating effectively within a diverse multicultural organization.Mastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact [email protected] and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Abide by Mastercard’s security policies and practices;
Ensure the confidentiality and integrity of the information being accessed;
Report any suspected information security violation or breach, and
Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.
Pay Ranges
O'Fallon, Missouri: $189,000 - $312,000 USD
