Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title And Summary
Information Security Engineer II
Overview
Who is Mastercard?
Mastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible. Using secure data and networks, partnerships, and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all.
Mission First, People Always
Corporate Security is responsible for keeping Mastercard safe and secure from cyber and physical threats. We are a highly effective team protecting a major component of global payments infrastructure. Our Security Risk and Control Operations team is at the forefront of this effort in the “1st Line of Defense,” coordinating efforts across Corporate Security, enterprise risk management, and market-facing product teams to assess risks, implement controls to mitigate them, and provide assurance to regulators and stakeholders of Mastercard’s best-in-class performance in information security.
Overview
We are seeking an Information Security Engineer II to support the identification, assessment, and management of security issues across Mastercard’s technology environment.
This role is primarily focused on Issue Management System operations, including issue intake validation, action plan review, evidence assessment, and ongoing risk tracking. The ideal candidate will partner closely with technology teams, risk owners, and standard owners to ensure that security gaps are clearly articulated, properly tracked, and remediated or risk accepted in accordance with Mastercard’s standards.
Role
This Role Will Also Provide Support For Control Assessment Activities, Including Validation Of Control Gaps And Alignment To Applicable Policies And Standards. In This Position, You Will:
- Support end-to-end issue management lifecycle, including issue triage, validation, and workflow progression in Archer
- Review and challenge issue descriptions, risk statements, and impacted control mappings to ensure clarity, accuracy, and alignment to standards
- Evaluate and provide feedback on action plans, including remediation strategies and risk acceptance proposals
- Assess compensating controls and supporting evidence to ensure audit defensible submissions and compliance with Corporate Security expectations
- Partner with issue owners, remediation owners, and standard owners to drive timely resolution of security gaps and prevent delinquency
- Perform structured review of control deficiencies identified through assessments, audits, or self identified issues, ensuring proper documentation within TIMS
- Support light control assessment activities, including validation of control gaps against industry standard, internal standards, and regulatory requirements
- Contribute to issue reporting, trend analysis, and governance insights to support risk discussions and leadership visibility
- Build strong relationships with cross-functional stakeholders across engineering, risk, and governance teams
All About You
The ideal candidate for this position has:
- Experience in a payment, fintech, bank, or other highly regulated environment.
- Strong understanding across core security control domains.
- Hands-on experience with issue management or GRC platforms
- Ability to evaluate risk statements, control gaps, remediation plans, and evidence with a high degree of rigor and attention to detail
- Strong written and verbal communication skills, with the ability to produce clear, concise, and audit-defensible documentation
- Experience working with cross-functional stakeholders and managing risk conversations across multiple teams
- Analytical mindset with the ability to challenge assumptions and identify gaps in controls or remediation strategies
- Bachelor’s degree (or equivalent practical experience) in Information Security, Information Systems, Computer Science, or related field.
- Relevant certifications such as CISSP, CISA, Security+, PCI ISA, etc.
NICE Framework references
Mastercard Corporate Security Roles Have Been Aligned With The NICE Framework (National Initiative For Cybersecurity Education). For This Role The NICE Work Roles Most Closely Aligned Are:
- Security Control Assessment (OG-WRL-012): Responsible for conducting independent comprehensive assessments of management, operational, and technical security controls and control enhancements employed within or inherited by a system to determine their overall effectiveness.
- Systems Testing and Evaluation (DD-WRL-007): Responsible for planning, preparing, and executing system tests, evaluating test results against specifications, and reporting findings.
- Vulnerability Assessment Analyst (PR-VAM-001): Responsible for identifying, analyzing, and reporting vulnerabilities and control gaps, including deviations from secure configurations, enterprise standards, and regulatory requirements, and supporting remediation or risk treatment decisions.
- Cybersecurity Architect (DD-WRL-001): Responsible for ensuring that security requirements are adequately addressed in all aspects of enterprise architecture, including reference models, segment and solution architectures, and the resulting systems that protect and support organizational mission and business processes.
- Systems Security Analyst (OM-ANA-001): Helps ensure secure configuration and operational security requirements are implemented and verifiable in production environments.
Corporate Security Responsibility
Every Person Working For, Or On Behalf Of, Mastercard Is Responsible For Information Security. All Activities Involving Access To Mastercard Assets, Information, And Networks Comes With An Inherent Risk To The Organization And Therefore, It Is Expected That The Successful Candidate For This Position Must:
- Abide by Mastercard’s security policies and practices;
- Ensure the confidentiality and integrity of the information being accessed;
- Report any suspected information security violation or breach; and
- Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.
Accountabilities/Tasks Performed:
- Strong security and technical skills to uncover security gaps within implemented technologies
- Communicate security gaps found to platform and compliance teams for tracking to remediation
Desired Skills/Abilities:
- Computer Science or Pen testing background
- Strong communication and writing skills
- Relationship building skills: outgoing and able to build a strong rapport with fellow team members and platform owners
- Positive and go getter attitude
- Strong commitment levels from a results delivery perspective
Corporate Security Responsibility
All Activities Involving Access To Mastercard Assets, Information, And Networks Comes With An Inherent Risk To The Organization And, Therefore, It Is Expected That Every Person Working For, Or On Behalf Of, Mastercard Is Responsible For Information Security And Must:
- Abide by Mastercard’s security policies and practices;
- Ensure the confidentiality and integrity of the information being accessed;
- Report any suspected information security violation or breach, and
- Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.