Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Manager Security Engineer & Enablement
Manager Security Engineer & Enablement
To support our continued growth and success, we are actively recruiting for an Information Security Compliance Professional to assist in and support all aspects of our program. The ideal candidate will have solid experience in developing and/or maintaining information security policies and procedures, as well as familiarity with security frameworks and standards including CSA CCM, PCI-DSS, SOC2, ISO27001, etc. Excellent communication skills, both verbal and written, are essential. If you are looking for a challenge that will allow you to collaborate within dynamic teams and work in a fast-paced environment, this position is for you.
Job Duties & Responsibilities
Internal Compliance & Control Management
- Provide leadership in identifying control gaps, compliance risks, and process improvement opportunities across operational, regulatory, legal, and technology domains.
- Establish and maintain effective governance over the organization's control framework, ensuring controls remain current, relevant, and aligned with business objectives.
- Drive accountability for remediation activities by overseeing management action plans and ensuring timely and sustainable resolution of identified control weaknesses.
- Act as a trusted advisor to leadership and business stakeholders, championing a strong risk management culture and promoting adherence to governance standards across the organization.
- Partner with control functions and business leaders to strengthen the effectiveness of the Three Lines of Defense model and enhance overall risk and control practices.
- Provide independent challenge and oversight of complex technology and business processes, leveraging risk-based analysis to assess control effectiveness and identify emerging risks.
Audit & Compliance Program Leadership
- Lead the successful execution of internal, external, client, and regulatory audits, ensuring organizational readiness and effective stakeholder engagement throughout the audit lifecycle.
- Own and govern information security compliance programs, including PCI DSS, SOX and SOC 2, delivering strategic oversight, program direction, and continuous improvement.
- Influence and coordinate cross-functional stakeholders to ensure alignment on audit objectives, evidence collection, remediation activities, and regulatory expectations.
- Communicate audit outcomes, key risks, and remediation progress to senior leadership, enabling informed decision-making and effective risk management.
- Challenge and evaluate management responses to audit findings, ensuring remediation plans appropriately address root causes and reduce organizational risk.
- Serve as a subject matter expert and trusted advisor, providing guidance on compliance obligations, regulatory requirements, and audit readiness initiatives.
Client Assurance & Due Diligence Management
- Lead the governance and execution of client security and due diligence assessment programs, ensuring accurate, consistent, and timely responses that reflect organizational capabilities and controls.
- Oversee the assessment of client requirements, contractual obligations, and associated risks, ensuring appropriate stakeholder engagement and risk mitigation strategies.
- Strengthen client trust and support business growth by providing strategic direction on security assurance responses and compliance-related inquiries.
- Drive continuous improvement of the due diligence response process through knowledge management, content governance, and operational efficiencies.
- Maintain and enhance the organization's assurance knowledge repository, ensuring responses remain current, consistent, and aligned with evolving regulatory and client expectations.
- Partner with business, technology, legal, and compliance stakeholders to address complex client concerns while balancing risk, compliance, and commercial objectives.
Skills required
Must have a positive attitude, excellent critical thinking and problem-solving skills to support the business working with cross-functional teams on projects and initiatives. Liaise with internal and external stakeholders on an ongoing basis during the audit, relative to plans, objectives, evidence collection and results documenting, presenting and tracking findings and remediation actions.
- Preferably 5 - 7 years' experience with/in:
- IT security controls
- IT Audit, and/or
- Compliance management, and/or
- Project management/ coordination (document collections, coordination, tracking, customer partnership), and/or
- Information management
- Understanding of risk management and Information Security frameworks
- Certified Professional designation (CSA CCM, CISSP, CISA, CRISC) or willingness to work towards one or more of these certifications
- Experience with GDPR and/or PIPEDA and/or similar Data Privacy frameworks
- Experience with information management/ RFP platforms (e.g., Loopio, RFPIO, RFP360, etc.)
- Experience working with auditors and other stakeholders, managing audits, collecting evidence and tracking findings to a resolution
- Intellectually curious, self-motivated, passionate works well both independently and as part of a team
- Ability to influence change through effective communication and interpersonal skills
- Ability to work and partner with others in different levels of the organization
- Ability to multi-task, be organized and take initiative audit management.
- Managing the PCI, SOC-2 and other compliance programs end-to-end
- Evaluating internal stakeholders' response to audits and reporting to management on appropriateness
- Acting in a consultative capacity, providing advice and clarity to teams on compliance requirements and audits
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Abide by Mastercard’s security policies and practices;
Ensure the confidentiality and integrity of the information being accessed;
Report any suspected information security violation or breach, and
Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.