Vice President, Information Security Engineering

MasterCard

Arlington (VA)

On-site

USD 244,000 - 390,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Comprehensive benefits package
Paid time off and leave
401k with company match

Job summary

Mastercard, Arlington, VA, is seeking a Vice President for Information Security Engineering focused on Employee Access Management Governance. You will lead governance, policy alignment, onboarding, and audit readiness across workforce, privileged, and machine identities, partnering with product, engineering, and risk teams.

Responsibilities include defining standards, enforcing controls, and driving improvements across enterprise access management.

Qualifications

  • Significant experience leading identity and access management, governance, compliance, audit, risk management, or related security functions.
  • Defined, implemented, and enforced governance frameworks, operational standards, controls, policies, and process management routines.
  • Strong understanding of access management disciplines including identity lifecycle, provisioning, privileged access, reviews, and audit support.

Responsibilities

  • Lead the EAM Governance organization responsible for access management governance, standards, controls, compliance, audit support, policy alignment, onboarding governance, and operational process enforcement.
  • Define, maintain, and enforce enterprise access management standards, procedures, operating models, and control expectations across EAM capabilities.
  • Own day-to-day governance and operational management of EAM processes, ensuring teams follow standards, controls, and compliance requirements.
  • Provide governance over audit readiness, control execution, evidence management, remediation tracking, and regulatory response activities.
  • Partner with audit, risk, compliance, and product/engineering teams to integrate governance into roadmaps and transformations.
  • Establish onboarding governance for applications and emerging AI-based identities.
  • Oversee operational access management processes, including BAU activities, access hygiene, and testing.
  • Drive continuous improvement using metrics and risk indicators.
  • Lead remediation efforts for audit findings and control gaps.

Skills

Identity & access management
Governance & controls
Audit & compliance
Stakeholder management
Security operations

Job description

Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.

Title and Summary Vice President, Information Security Engineering Overview

The Vice President, Employee Access Management Governance is responsible for leading the governance, standards, controls, onboarding, compliance, audit, and operational management functions across Employee Access Management. This role ensures that access management processes are consistently defined, enforced, measured, and improved across the enterprise, while balancing security, operational effectiveness, user experience, and regulatory expectations. The VP will establish and maintain the governance model for access management capabilities across workforce, privileged, application, machine, and emerging AI-based identities. This includes ownership of access management standards, process controls, operational routines, audit readiness, compliance support, policy alignment, onboarding governance, issue remediation, and continuous improvement across the EAM environment. This leader will partner closely with product, engineering, cyber risk, technology, compliance, audit, application owners, service teams, and business stakeholders to ensure access management practices are scalable, well-controlled, operationally effective, and aligned to enterprise security objectives.

Responsibilities

Lead the EAM Governance organization responsible for access management governance, standards, controls, compliance, audit support, policy alignment, onboarding governance, and operational process enforcement.

Define, maintain, and enforce enterprise access management standards, procedures, operating models, and control expectations across EAM capabilities.

Own the day-to-day governance and operational management of EAM processes, ensuring teams follow defined standards, controls, service expectations, and compliance requirements.

Provide leadership over access management compliance, audit readiness, control execution, evidence management, remediation tracking, and regulatory response activities.

Partner with internal audit, compliance, risk, and control teams to ensure access management controls are clearly defined, effectively executed, continuously monitored, and supported with appropriate evidence.

Lead governance over application onboarding into EAM capabilities, ensuring consistent intake, prioritization, readiness assessment, control alignment, documentation, and operational handoff.

Establish standards and governance for onboarding emerging access use cases, including AI-enabled applications, AI agents, machine identities, service accounts, privileged access patterns, and non-human identities.

Oversee operational access management processes, including recurring business-as-usual activities, work order resolution, service channels, access hygiene, segregation of duties support, user acceptance testing, quality assurance, and process optimization.

Drive continuous improvement across EAM governance and operations by using metrics, process performance data, issue trends, customer feedback, risk indicators, and control outcomes.

Lead remediation efforts related to audit findings, control gaps, policy exceptions, operational issues, and access management process deficiencies.

Partner with EAM Product and Engineering teams to ensure governance, compliance, onboarding, and operational requirements are incorporated into product roadmaps, platform migrations, and modernization efforts.

Provide governance oversight for major EAM initiatives, migrations, and transformation activities, including EAM tool controls migration, EAM tool transition activities, governance-related processes, and other access management modernization programs.

Define and maintain clear accountability models across product, governance, operations, control owners, application teams, and business stakeholders.

Develop and sustain metrics, dashboards, and reporting that demonstrate control effectiveness, operational performance, onboarding progress, remediation status, audit readiness, and risk reduction.

Ensure EAM processes comply with applicable regulatory, operational, security, and enterprise policy requirements.

Serve as a senior authority on access governance decisions, control expectations, operational risk, policy interpretation, audit response, and process design.

Experiences

Significant experience leading identity and access management, access governance, compliance, audit, risk management, security operations, or related enterprise security functions.

Demonstrated experience defining, implementing, and enforcing governance frameworks, operational standards, controls, policies, and process management routines.

Strong understanding of access management disciplines, including identity lifecycle, access provisioning, application onboarding, privileged access, access reviews, segregation of duties, control monitoring, remediation, and audit support.

Experience leading audit, regulatory, compliance, and control-related activities, including evidence collection, issue management, remediation tracking, and stakeholder response.

Proven ability to operate across large, complex, global environments with multiple stakeholders, competing priorities, and significant operational and regulatory expectations.

Experience partnering with product, engineering, architecture, cyber risk, compliance, audit, operations, application owners, and business teams to deliver secure and scalable access management outcomes.

Strong operational leadership experience, including service management, process execution, metrics, work intake, issue prioritization, quality assurance, process improvement, and performance reporting.

Experience with application onboarding, access management intake processes, platform migration support, and operational readiness activities.

Understanding of emerging access governance needs related to AI-enabled applications, autonomous agents, machine identities, service accounts, APIs, and other non-human identity patterns.

Ability to translate control requirements, policy obligations, audit findings, and operational risks into practical execution plans and measurable outcomes.

Demonstrated ability to build collaborative working relationships with senior stakeholders across global, regional, and local teams.

Strong communication skills with the ability to present complex governance, risk, control, and operational topics clearly to executive, technical, audit, and business audiences.

Experience developing and using metrics to measure process effectiveness, control health, operational performance, remediation progress, and risk reduction.

Proven ability to lead organizational change, improve operating models, simplify processes, and drive disciplined execution across teams.

Experience engaging vendors, consultants, and third-party partners where needed to support governance, compliance, onboarding, automation, or operational improvement objectives.

Corporate Security Responsibility

All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must: Abide by Mastercard’s security policies and practices; Ensure the confidentiality and integrity of the information being accessed; Report any suspected information security violation or breach, and Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.

In line with Mastercard’s total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary and may be eligible for an annual bonus or commissions depending on the role. The base salary offered may vary depending on multiple factors, including but not limited to location, job-related knowledge, skills, and experience.

Mastercard benefits for full time (and certain part time) employees generally include:

insurance (including medical, prescription drug, dental, vision, disability, life insurance); flexible spending account and health savings account; paid leaves (including 16 weeks of new parent leave and up to 20 days of bereavement leave); 80 hours of Paid Sick and Safe Time, 25 days of vacation time and 5 personal days, pro-rated based on date of hire; 10 annual paid U.S. observed holidays; 401k with a best-in-class company match; deferred compensation for eligible roles; fitness reimbursement or on-site fitness facilities; eligibility for tuition reimbursement; and many more.

Mastercard benefits for interns generally include:

56 hours of Paid Sick and Safe Time; jury duty leave; and on-site fitness facilities in some locations.

Pay Ranges

Arlington, Virginia: $244,000 - $390,000 USD

Everyone wants easier ways to pay; we invent them. Checkout lines are slow; we speed them along. Merchants want more sales; we give them data and insights. People need financial access; we connect them. Corporate purchasing is complicated; we make it simple. Commuters are busy; we speed them on their way. Governments need greater efficiencies; we help create them. Small businesses are virtual; we give them access to a world of buyers. Retailers want to fight fraud; we provide the tools.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vice President, Information Security Engineering
Vice President, Information Security Engineering

Socket.dev • Arlington (VA)

On-site
USD 244,000 - 390,000
Vice President, AI Vulnerability Operations
Vice President, AI Vulnerability Operations

MasterCard • O’Fallon (MO)

On-site
USD 212,000 - 339,000
Insurance
401k with company match
Paid time off
Manager, Network Economics & Value Optimization
Manager, Network Economics & Value Optimization

MasterCard • Purchase (NY)

On-site
USD 137,000 - 218,000
Insurance benefits
FSAs/HSA
Paid leave
+5
Manager, Site Reliability Engineering
Manager, Site Reliability Engineering

MasterCard • O’Fallon (MO)

On-site
USD 122,000 - 207,000
Senior Site Reliability Engineer
Senior Site Reliability Engineer

MasterCard • O’Fallon (MO)

On-site
USD 96,000 - 163,000
Health insurance
401k with company match
Paid time off
+1
Vice President, Product Management, Data and Analytics
Vice President, Product Management, Data and Analytics

Mastercard • Arlington (VA)

On-site
USD 235,000 - 375,000
Competitive base salary
Annual bonus or commissions
401k with company match
+2
Vice President, Product Management, Data and Analytics
Vice President, Product Management, Data and Analytics

Mastercard • Missouri

On-site
USD 204,000 - 326,000
Principal Software Development Engineer
Principal Software Development Engineer

Mastercard • Missouri

On-site
USD 170,000 - 281,000
401k with match
Tuition reimbursement
On-site fitness facilities
Director, Risk Management
Director, Risk Management

Mastercard • Purchase (NY)

On-site
USD 163,000 - 269,000
Consultant, Advisors & Consulting Services, Marketing
Consultant, Advisors & Consulting Services, Marketing

MasterCard • Purchase (NY)

On-site
USD 97,000 - 139,000
Health insurance
401(k) with company match
Paid time off