Description
Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Senior Technology Risk Analyst OverviewThe Mastercard Technology Risk Management Team is seeking a Lead Technology Risk Analyst to drive an assurance and controls program across SOC 1, SOC 2, PCI DSS, ISO 27001, ISO 27701, and other global compliance frameworks. This role helps ensure Mastercard meets customer, regulatory, and certification requirements by partnering with first-line risk teams and technology stakeholders to design, implement, and monitor effective controls across Mastercard's global programs.
The Lead Analyst will support control framework design, provide compliance oversight, and monitor ongoing operating effectiveness across multiple assurance domains. This role is central to maintaining Mastercard's strong internal control posture while enabling the organization to innovate responsibly. The team proactively assesses controls, identifies risks, defines remediation actions, and tracks remediation through closure.
We are seeking someone who can think strategically while executing tactically—bringing strong control, compliance, and assurance expertise across multi-framework environments.
Responsibilities
Partner with first-line risk teams and internal stakeholders to design and implement control frameworks supporting SOC 1, SOC 2, PCI DSS, ISO 27001/27701, and other certification programs.
Support and lead assurance activities with internal and external auditors to evaluate control design and operating effectiveness.
Execute control assessments across technology and operational areas to identify risks, gaps, or control design weaknesses.
Track remediation actions through resolution to strengthen control design maturity and operating effectiveness.
Produce formal reporting on certification progress, assurance outcomes, test results, and control performance.
Develop and maintain dashboards, metrics, and executive-ready reporting for internal leadership, customers, regulators, and audit partners.
Collaborate closely with Mastercard's assurance and compliance programs — including SOC 1, SOC 2, ISAE 3402, ISAE 3000, ISO 27001/27701, SOX, and PCI DSS — to ensure alignment across the Technology Risk Management function.
About You
Demonstrated ability to operate independently and with sound judgment.
Experience with technology, security, or compliance frameworks such as SOC 1, SOC 2, PCI DSS, ISO 27001/27701, ISAE 3402/3000, and/or FedRAMP.
Bachelor's degree or equivalent experience; degrees in computer science, information technology, cybersecurity, or related fields preferred.
Strong interpersonal, communication, and presentation skills for partnering with leaders and teams across all organizational levels.
Professional certifications such as CISSP, CISA, CRISC, CPA, or similar are a plus.
Cloud certifications (Azure, AWS, GCP) are a plus.
Commitment to fostering an inclusive, culturally aware, and globally collaborative work environment.
Familiarity with the financial services, payments, or technology industries is a plus. Mastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact reasonable_accommodation@mastercard.com and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Abide by Mastercard's security policies and practices;
Ensure the confidentiality and integrity of the information being accessed;
Report any suspected information security violation or breach, and
Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
Pay Ranges
O'Fallon, Missouri: $88,000 - $141,000 USDApply on company website