Mastercard
Payments
SeniorInformationSecurityEngineer
Neural analysis suggests this role is
optimal for Senior candidates.
“Senior Information Security Engineer at Mastercard. Skills: Shadow IT blocking strategy, governance processes, escalation framework, data security, risk assessment. Contribute to the execution of the Shadow IT and Data Protection roadmap. Develop and maintain a Shadow IT blocking strategy framework for unapproved applications”
What You'll Achieve.
Define and operate a clear, defensible blocking and escalation framework that protects Mastercard data while enabling informed business decisions; Provide transparency, consistency, and defensibility across the enterprise
Industry & Context.
balance security risk, business impact, and policy alignment in high visibility decisions; Evaluate risk and determine outcomes; identify risk patterns, repeat offenders, policy gaps, and opportunities for control improvement; assess risk
Abide by Mastercard’s security policies, Ensure the confidentiality and integrity of the information being, Report any suspected information security violation or breach, Complete all periodic mandatory security trainings
What They're Looking For.
Must Have
Experience operating or designing security governance or enforcement programs in large, complex environments, understanding of information security, data protection, and risk management, particularly as applied to SaaS and third party technologies, Demonstrated ability to make and defend risk based decisions that balance security, policy, and business impact, Experience working cross functionally with Legal, Privacy, Compliance, and Technology teams, Ability to clearly document decisions and articulate technical and business impact to diverse audiences, verbal and written communication skills, including executive ready summaries, Demonstrated technical competency in security engineering through hands on experience or relevant qualifications, Data security and governance (in depth knowledge), Information security engineering, Risk assessment and decision frameworks, Policy interpretation and enforcement, Cross functional coordination and escalation management
Nice to Have
Experience with SaaS security posture management (SSPM), CASB, or DSPM, Familiarity with enterprise intake, exception, or risk acceptance processes, Cloud security experience, Automation or data analytics experience, Alteryx (or equivalent ETL), PowerBI (or equivalent visualization), PowerAutomate, etc experience is a plus, Application development experience is preferred, including the ability to develop scripts, work with APIs, and leverage AI capabilities in support of Shadow IT initiatives.
What You'll Do.
Contribute to the execution of the Shadow IT and Data Protection roadmap
Develop and maintain a Shadow IT blocking strategy framework for unapproved applications
Document all blocking decisions
Establish and maintain communication protocols to notify stakeholders of application blocks
Manage unblock requests and escalations and exception processing
Partner with application
and business teams to define paths to compliance
Track and report Shadow IT metrics
Build and operationalize a next generation Shadow IT governance model
Develop a way to automatically tag approved apps
Work with stakeholders to ensure all browser types experience is consistent
Work with stakeholders to ensure browser notifications
Perform completeness and quality assessments to validate Shadow IT enforcement coverage and identify governance gaps or process breakdowns
Analyze and interpret complex datasets to identify risk patterns
and opportunities for control improvement
How You'll Work.
Team & Collaboration
Work side by side with other team members to build and mature the Shadow IT governance process; Cross functional coordination; Coordinate with Security Operations and business stakeholders; Partner with application, platform, and business teams; Work with stakeholders
Communication Scope
articulate technical and business impact to diverse audiences; verbal and written communication skills; executive ready summaries
Full Job Description
**Our Purpose** _Mastercard powers economies and empowers people in 200 + countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential._ **Title and Summary** ### Senior Information Security Engineer ### Who is Mastercard? Mastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential. Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all Mission First, People Always As Corporate Security, we are responsible for keeping Mastercard safe and secure from cyber and physical threats, and it is our people on the frontlines who make this happen every day. By taking care of our people, their wellbeing, and career development, we provide them the necessary tools and environment to ensure the success of our mission. Overview Mastercard is seeking candidates to join the Data Protection team with a focus on ShadowIT risk management, governance, and enforcement. As Mastercard accelerates innovation through SaaS, cloud services, and automation platforms, unapproved technology usage presents material data security, privacy, and compliance risks. This role is critical
Applying for this Senior Information Security Engineer role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Workday
- Workday has a multi-step form — save your progress after every section.
- "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
- Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
- Job requisition numbers are useful when following up with HR by email.
ANONYMOUS · UNFILTERED
What do employees actually say about Mastercard?
Real rants from real employees. Read before you apply.