Lead Risk Control Analyst
MastercardAbout the role
Our Purpose
We work to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments and businesses realize their greatest potential. Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. We cultivate a culture of inclusion for all employees that respects their individual strengths, views, and experiences. We believe that our differences enable us to be a better team – one that makes better decisions, drives innovation and delivers better business results.
Title and Summary
Lead Risk Control AnalystOverviewWho is Mastercard?
Mastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible. Using secure data and networks, partnerships, and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all.
Mission First, People Always
Corporate Security is responsible for keeping Mastercard safe and secure from cyber and physical threats. We are a highly effective team protecting a major component of global payments infrastructure. Our new Security Risk and Control Operations team is at the forefront of this effort in the “1st Line of Defense,” coordinating efforts across Corporate Security, enterprise risk management, and market-facing product teams to assess risks, implement controls to mitigate them, and provide assurance to regulators and stakeholders of Mastercard’s best-in-class performance in information security.
We are seeking a Lead Risk Control Analyst to power the governance of security controls and report on their effectiveness. Working directly with the owners of security control domains such as identity and access management, vulnerability management, and network security, you will play a central role in applying a standard governance template to these control areas, assessing the maturity of control management, consolidating metrics, and generating executive-level products on control performance. Your work will drive decisions by senior managers on adjustments in the control environment required to keep risk within appetite.
In this position, you will:
- Spearhead the development and implementation of governance processes for information security controls
- Assess the effectiveness of control domain management within Corporate Security
- Curate a portfolio of metrics on the performance and effectiveness of various control domains and use that data to provide visualizations, identify insights, patterns and trends, and drive escalations
- Oversee synchronization between security control design and the company’s overall control framework that drives testing, evidencing, issue generation, and assurance
- Develop and deliver executive-level updates on the status of control design and implementation
- Ensure the security control environment is properly reflected in risk assessments
- Coordinate with colleagues managing controls in other domains to share lessons learned and standardize approaches when appropriate
- Compose responses to regulators and auditors on queries regarding security controls
- Maintain documentation of control domain governance procedures
The ideal candidate for this position should be:
- Knowledgeable of risk management processes and the design and implementation of information security controls
- Experienced in coordinating and executing control testing
- Adept at recognizing how control strengths and weaknesses effect the risk posture of a complex organization
- Familiar with RSA Archer or similar governance, risk, and compliance (GRC) tools
- Literate in one or more cyber security frameworks, such as NIST CSF, ISO 27001, or the Cyber Risk Institute profile
- Effective at working with and communicating to a wide range of stakeholders across technology and business functions, including senior executives, technology standard owners, auditors, and information security engineers
- Able to influence and drive results cross-functionally
- Professionally certified in information security or a related field
This position aligns with National Initiative for Cybers
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s