- Provide independent second-line oversight, review, and validation of technology risks across markets, with a focus on Europe, ensuring alignment with IT policies, standards, controls, and regulatory expectations
- Support maintenance of a technology risk management framework aligned with regulatory requirements and Mastercard’s Enterprise Risk Management and Operational Risk and Control frameworks
- Support development of a control framework aligned with approved risk appetite, regulatory obligations, and technology risk exposure
- Review risk and technology-related regulatory requirements and assess the adequacy of management responses to supervisory inspections and feedback
- Lead the development of clear, decision-useful risk reporting for market and Group governance forums, supporting effective escalation and transparency
- Provide independent second line oversight and constructive review of market (Europe) relevant risks and risk assessment activities focusing on Operational Resilience and Security risks, this includes risk assessments related to material product and technology changes
- Provide second line oversight across key control areas focusing on technology (such as change management, system availability, security, access, and data), reviewing control design, assessing operational effectiveness, and examining control testing results and assurance outcomes. Identifies, highlights and escalates material control deficiencies and remediation delays
- Ensure documentation and ongoing monitoring of market relevant risks focused on technology risks, controls, and issues, including security testing results, through remediation to closure in approved GRC tools
- Support and review security and resilience frameworks and strategies, ensuring they address threats and vulnerabilities specific to market’s specific processes, products and services
- Ensures technology teams develop policies and standards specific to the local market, reducing risk exposure and promoting the implementation of robust IT and security controls
- Oversee the development of relevant metrics focused on technology and security risk metrics, ensuring they are risk meaningful and outcomes focused, and aligned with approved risk appetite and tolerance thresholds.
Risk Management Framework:
- Maintain and support the adoption of the Technology Risk Standard in markets and technology and contribute to the design and delivery of supporting processes and tools that meet local regulatory requirements
- Support the execution of the Enterprise Risk Management (ERM) and Operational Risk and Controls (ORC) Framework in market and technology groups
- Develop and manages local risk processes, ensuring best practices are followed and that all procedures are documented, reviewed, and refreshed regularly
Technology Risk Governance:
- Act as the 2LOD Risk representative at governance forums, risk committees, and senior management discussions, providing clear, evidence-based insights to support effective decision making
- Review the effectiveness of risk reporting (focusing on technology risk) to management and governance committees and promotes alignment with Group standards
- Oversee the reporting of key risk indicators to governance bodies, ensuring timely remediation actions are taken when breaches occur.
Regulatory Engagement:
- Support regulatory examinations in Europe and across markets on matters related to risk matters and technology and security risk and controls
- Review and supports risk and technology related submissions to regulatory authorities
- Evaluates and supports the preparation of technology risk and assurance reports
Proactive and curious mindset, with the ability to engage broadly across the business while maintaining focus on core responsibilitiesExperience working with, and presenting to, senior management and governance forumsAbility to manage multiple priorities, deliverables, and initiatives simultaneously in a fast paced environmentProven experience collaborating with cross functional and global teams, managing multiple stakeholders and navigating various regulatory environmentsStrong ability to identify opportunities for improvement and driving continuous enhancementExcellent verbal and written communication abilitiesFamiliarity with enterprise risk and control frameworks such as ISO, NIST CSF, or other equivalent international standardsBackground in formal second line of defense roles, providing independent oversight rather than direct operational responsibilityExperience advocating for policy and procedure enhancements when necessary