Director, Technology Risk

Mastercard

Bray (OK)

On-site

USD 160,000 - 210,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Mastercard is seeking a Director, Technology Risk to lead second-line oversight across markets with emphasis on Europe, ensuring alignment with IT policies, standards, and regulatory expectations.

The role drives development of risk reporting, supports ERM and ORC frameworks, and collaborates with global teams to strengthen technology risk governance and controls.

Qualifications

  • Second line of defense roles across multiple jurisdictions.
  • Strong communication with senior management and governance forums.
  • Familiarity with ISO, NIST CSF or equivalent standards.

Responsibilities

  • Provide independent second-line oversight and review of market technology risks.
  • Ensure documentation and ongoing monitoring of risk and control effectiveness.
  • Develop clear risk reporting for governance forums and regulatory bodies.

Skills

Second line of defense
Risk governance
Regulatory compliance
Stakeholder mgmt

Job description

Our Purpose

Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.

Title and Summary

Director, Technology Risk
Director, Second Line of Defense - Technology Risk

Overview
  • Provide independent second-line oversight, review, and validation of technology risks across markets, with a focus on Europe, ensuring alignment with IT policies, standards, controls, and regulatory expectations.
  • Support maintenance of a technology risk management framework aligned with regulatory requirements and Mastercard's Enterprise Risk Management and Operational Risk and Control frameworks.
  • Support development of a control framework aligned with approved risk appetite, regulatory obligations, and technology risk exposure.
  • Review risk and technology-related regulatory requirements and assess the adequacy of management responses to supervisory inspections and feedback.
  • Lead the development of clear, decision-useful risk reporting for market and Group governance forums, supporting effective escalation and transparency.
Role
Technology Risk Oversight in Market
  • Provide independent second line oversight and constructive review of market (Europe) relevant risks and risk assessment activities focusing on Operational Resilience and Security risks, this includes risk assessments related to material product and technology changes.
  • Provide second line oversight across key control areas focusing on technology (such as change management, system availability, security, access, and data), reviewing control design, assessing operational effectiveness, and examining control testing results and assurance outcomes. Identifies, highlights and escalates material control deficiencies and remediation delays.
  • Ensure documentation and ongoing monitoring of market relevant risks focused on technology risks, controls, and issues, including security testing results, through remediation to closure in approved GRC tools.
  • Support and review security and resilience frameworks and strategies, ensuring they address threats and vulnerabilities specific to market's specific processes, products and services.
  • Ensures technology teams develop policies and standards specific to the local market, reducing risk exposure and promoting the implementation of robust IT and security controls.
  • Oversee the development of relevant metrics focused on technology and security risk metrics, ensuring they are risk meaningful and outcomes focused, and aligned with approved risk appetite and tolerance thresholds.
Risk Management Framework
  • Maintain and support the adoption of the Technology Risk Standard in markets and technology and contribute to the design and delivery of supporting processes and tools that meet local regulatory requirements.
  • Support the execution of the Enterprise Risk Management (ERM) and Operational Risk and Controls (ORC) Framework in market and technology groups.
  • Develop and manages local risk processes, ensuring best practices are followed and that all procedures are documented, reviewed, and refreshed regularly.
  • Support maintaining a control framework in coordination with Group First line of defense Technology and Security Risk teams.
Technology Risk Governance
  • Act as the 2LOD Risk representative at governance forums, risk committees, and senior management discussions, providing clear, evidence-based insights to support effective decision making.
  • Review the effectiveness of risk reporting (focusing on technology risk) to management and governance committees and promotes alignment with Group standards
  • Oversee the reporting of key risk indicators to governance bodies, ensuring timely remediation actions are taken when breaches occur.
Regulatory Engagement
  • Support regulatory examinations in Europe and across markets on matters related to risk matters and technology and security risk and controls.
  • Review and supports risk and technology related submissions to regulatory authorities.
  • Evaluates and supports the preparation of technology risk and assurance reports.
All About You
  • Proven experience collaborating with cross functional and global teams, managing multiple stakeholders and navigating various regulatory environments.
  • Ability to manage multiple priorities, deliverables, and initiatives simultaneously in a fast paced environment.
  • Background in formal second line of defense roles, providing independent oversight rather than direct operational responsibility.
  • Proactive and curious mindset, with the ability to engage broadly across the business while maintaining focus on core responsibilities.
  • Experience advocating for policy and procedure enhancements when necessary.
  • Strong ability to identify opportunities for improvement and driving continuous enhancement.
  • Familiarity with enterprise risk and control frameworks such as ISO, NIST CSF, or other equivalent international standards.
  • Experience working with, and presenting to, senior management and governance forums.
  • Excellent verbal and written communication abilities.
Corporate Security Responsibility
  • Abide by Mastercard's security policies and practices;
  • Ensure the confidentiality and integrity of the information being accessed;
  • Report any suspected information security violation or breach, and
  • Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director of Risk Management
Director of Risk Management

Mastercard • New York (NY)

On-site
USD 180,000 - 280,000
Director - Consumer Credit Analytics - Global Product Manager
Director - Consumer Credit Analytics - Global Product Manager

Mastercard • Bray (OK)

On-site
USD 180,000 - 230,000
Unified Checkout Services Product Development Director
Unified Checkout Services Product Development Director

Mastercard • Bray (OK)

On-site
USD 180,000 - 280,000
Director - Segment Sales Enablement - Enterprise & Credit Risk
Director - Segment Sales Enablement - Enterprise & Credit Risk

Mastercard • Bray (OK)

On-site
USD 180,000 - 300,000
Lead Program Security Engineer
Lead Program Security Engineer

Mastercard • Bray (OK)

On-site
USD 180,000 - 240,000
Vice President, Technology Risk Managment
Vice President, Technology Risk Managment

Mastercard • O’Fallon (MO)

On-site
USD 189,000 - 312,000
Senior Information Security Engineer
Senior Information Security Engineer

Mastercard • Bray (OK)

On-site
USD 120,000 - 160,000
IT Operational Risk Manager
IT Operational Risk Manager

Selby Jennings • Town of Florida (NY)

On-site
USD 90,000 - 140,000
Director, Software Engineering
Director, Software Engineering

Mastercard • Bray (OK)

On-site
USD 209,000 - 279,000
Principal Software Engineer - Architecture
Principal Software Engineer - Architecture

Mastercard • Bray (OK)

On-site
USD 160,000 - 230,000