Vice President, Software Supply Chain Security

Mastercard

O’Fallon (MO)

On-site

USD 212,000 - 339,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Mastercard in O'Fallon, Missouri, is seeking a Vice President of Software Supply Chain Security to lead efforts in safeguarding the company's software ecosystem. This senior leader will establish a robust strategy for software security within the global payments framework.

The ideal candidate has a strong background in security leadership, CI/CD practices, and robust stakeholder management capabilities. Join Mastercard to make a meaningful impact in software integrity and security.

Qualifications

  • Demonstrated effectiveness leading Security or Software Engineering teams.
  • Proven track record of implementing software supply chain controls.
  • Deep expertise in CI/CD, artifact registries, and cryptographic signing.

Responsibilities

  • Define the Software Supply Chain Security strategy.
  • Build and lead global DevSecOps teams.
  • Architect security for CI/CD pipelines and automation platforms.

Skills

Leadership
DevSecOps
CI/CD
Kubernetes/container security
Stakeholder management
Cryptographic signing
API security

Education

Relevant degree in Computer Science or related field

Job description

Our Purpose

Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.

Title and Summary

Vice President, Software Supply Chain Security

Overview

The Network Engineering Services team is looking for a Vice President of Software Supply Chain Security. The VP is a senior leader responsible for protecting the integrity, provenance, and trustworthiness of all software that powers the company’s global payments ecosystem. This role ensures end‑to‑end security across internal development, third‑party software, CI/CD pipelines, cloud workloads, vendor integrations and payment processing platforms that require the highest levels of reliability, compliance and resiliency.

Role
  • Define the Software Supply Chain Security strategy aligned to the company’s global payments mission, regulatory obligations and risk appetite.
  • Build and lead high‑performing global DevSecOps, platform engineering and security automation teams.
  • Architect security for CI/CD pipelines, infrastructure‑as‑code frameworks and automation platforms.
  • Embed security controls into development workflows, including SAST/DAST, SBOM, dependency scanning and secrets management to eliminate preventable exposure.
  • Establish governance for software bill of materials (SBOM), artifact integrity, code provenance and policy‑as‑code guardrails.
  • Promote a secure‑by‑default engineering culture with paved roads for secure component consumption, signing, building and deployment.
  • Partner with Vulnerability Management on strategy and outcomes for end‑to‑end detection, triage, risk acceptance, remediation, validation and overall exposure management.
  • Partner with DevOps on cloud strategy and operations (AWS, Azure, GCP or hybrid), ensuring resilient, scalable and secure infrastructure.
  • Partner with Legal, Third‑Party Risk Management (TPRM) and Procurement to enforce contractual obligations for secure development, reporting, incident notification and replace/patch SLAs.
All About You
  • Demonstrated effectiveness leading Security, Platform/DevOps or Software Engineering teams.
  • Proven track record of implementing software supply chain controls across complex, multicloud and hybrid environments.
  • Demonstrated ability to balance regulatory, security and developer experience requirements at enterprise scale.
  • Deep expertise in CI/CD, artifact registries, Kubernetes/container security, cryptographic signing and OSS governance.
  • Strong knowledge of SLSA, NIST SSDF, OWASP SCVS/SCVST, ISO 27001/27036 and other regulatory frameworks.
  • Hands‑on familiarity with SAST/DAST/IAST/SCA, secrets and dependency management, API security and runtime protections.
  • Strong stakeholder management and executive communication skills; proven record influencing Product and Engineering leaders.
NICE Framework references
  • National Initiative for Cybersecurity Education (NICE) competency proficiency levels of limited in leadership, limited to developing in operational and professional, and developing to proficient in technical.
  • This Mastercard role shares KSAs with related NICE work roles
    • OV‑SPP‑002, OPM751, Cyber Policy and Strategy Planner
    • OV‑EXL‑001, OPM901, Executive Cyber Leadership
    • OV‑MGT‑001, OPM722, Information Systems Security Manager

Mastercard is a merit‑based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disability or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact reasonable_accommodation@mastercard.com and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.

Corporate Security Responsibility
  • Abide by Mastercard's security policies and practices.
  • Ensure the confidentiality and integrity of the information being accessed.
  • Report any suspected information security violation or breach, and
  • Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
Pay Ranges

O'Fallon, Missouri: $212,000 - $339,000 USD

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vice President, Software Supply Chain Security
Vice President, Software Supply Chain Security

Mastercard • O’Fallon (MO)

On-site
USD 212,000 - 339,000
Vice President Platform Engineering
Vice President Platform Engineering

Socket.dev • O’Fallon (MO)

On-site
USD 200,000 - 330,000
Manager, Software Engineering
Manager, Software Engineering

Mastercard • O’Fallon (MO)

On-site
USD 140,000 - 231,000
Vice President, AI Vulnerability Operations
Vice President, AI Vulnerability Operations

Socket.dev • O’Fallon (MO)

On-site
USD 212,000 - 339,000
Health insurance
401k with company match
Paid time off
+1
Director, Software Engineering
Director, Software Engineering

Mastercard • O’Fallon (MO)

On-site
USD 170,000 - 281,000
Medical insurance
401k with company match
Paid time off
Vice President Platform Engineering
Vice President Platform Engineering

Mastercard • O’Fallon (MO)

On-site
USD 200,000 - 330,000
Health insurance
401(k) match
Paid time off
Vice President, Information Security Engineering
Vice President, Information Security Engineering

Socket.dev • Arlington (VA)

On-site
USD 244,000 - 390,000
Vice President, GBSC Strategy & Innovation
Vice President, GBSC Strategy & Innovation

Mastercard • O’Fallon (MO)

On-site
USD 189,000 - 312,000
Medical insurance
401k with match
Generous vacation and leave policies
Manager, Software Engineering
Manager, Software Engineering

Mastercard • O’Fallon (MO)

On-site
USD 140,000 - 231,000
Vice President, AI Vulnerability Operations
Vice President, AI Vulnerability Operations

MasterCard • O’Fallon (MO)

On-site
USD 212,000 - 339,000
Insurance
401k with company match
Paid time off