MasterCard Lead Information Security Engineer in Pune, India
We work to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments and businesses realize their greatest potential. Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. We cultivate a culture of inclusion (https://www.mastercard.us/en-us/vision/who-we-are/diversity-inclusion.html) for all employees that respects their individual strengths, views, and experiences. We believe that our differences enable us to be a better team – one that makes better decisions, drives innovation and delivers better business results.
Lead Information Security Engineer
Who is Mastercard?
Mastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible. Using secure data and networks, partnerships, and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential.
Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all.
• MasterCard is seeking a demonstrated security engineering expert to join our Business Security Enablement Guild within the Corporate Security team. The Business Security Enablement Guild is a powerful team of information security and DevSecOps experts focused on helping Mastercard achieve its goals by ensuring security is at the heart of everything we do. Mastercard is researching and developing the next generation of products, services, and solutions at scale to enable consumers to securely, efficiently, and intelligently conduct transactions regardless of channel.
• Whether through traditional retail, mobile, or e-commerce, MasterCard innovation is leading the digital convergence of traditional and emerging payments technologies across a wide variety of new devices and services for billions of users worldwide.
• Are you passionate about security? Do you like to tinker with things in order to figure out how to build them better, stronger, and more resilient? Are you a people person who values partnership, teamwork, and building solutions with cross-functional disciplines and teams? Are you curious? Do you follow trends, research, and best practices as part of your insatiable desire to learn and teach others? Do you want to have a true impact on the security of how the world transacts? This may be the role for you.
• As the Guild Security Engineer, you will be relied upon to serve as a technical security expert supporting the development and sustainability of secure products and practices. You will be the subject matter expert in application security delivering tactical mentorship and strategic consulting in terms of building a security-focused culture, secure development best practices, and application security awareness as well as contextualizing the threat landscape and associated risks for the Program.
• You will be an active and critical participant in the design and implementation of the various processes and initiatives of the Business Security Enablement Guild.
• You will proactively work to find solutions that align with business needs while operating within Mastercard’s risk tolerance that is scalable and can be applied across multiple programs and platforms. This requires the ability to collaborate with cross-functional teams and regularly articulate and communicate to diverse audiences and properly translate security and risk management terminology into business terms and recommend alternative solutions to these stakeholders.
• As the Guild Security Engineer, you will also assist the Business Security Enablement Guild in assessing the current threat landscape and business needs of different programs. This includes examining systems and applications to understand their current security posture and advocating for security best practices to engineering teams.
All About You
• Adaptive communication skills to influence cross-functionally without direct authority, comfort speaking with customers and business partners at all levels.
• Motivated self-starter with agility and ability to manage ambiguity, and deal with and anticipate change while still meeting business objectives.
• Passion for great product design, security, and usability.
• Experience with application threat modeling or other risk identification techniques.
• Experienced in mobile security architecture concepts, design, and implementation for Android and iOS is a plus.
• Current knowledge of security best practices, common exploits, and threat landscape.
• Strong understanding of Information Security, Authentication, and Data Privacy within the domain of Digital Commerce including relevant practical experience.
• Demonstrated experience designing secure multi-domain internet-facing applications.
• Knowledge of the security architecture of web-based network environments and secure communication between environments
• Knowledge and technical security experience in Cryptography, including several of the following: PKI, Digital Certificates, SSL, Hashing, Encryption techniques, and so on.
• Good understanding of Software Development especially related to secure coding best practices. Prior experience programming in Java is a plus.
• Understanding of Agile methodologies
• Ability to build secure DevOps architecture patterns and provide guidance on how to develop secure applications and infrastructures
We value the safety of each member of our community because we know we’re all in this together. In many locations, which may change over time, we’ve implemented a virtual hiring process and continue to interview candidates by video or phone. In addition, in some locations, only individuals who have been fully vaccinated will be permitted inside Mastercard offices until further notice.
In the US, Mastercard is a government contractor, which may legally require most Mastercard employees to be vaccinated unless a verified approved medical or religious exemption is granted. Further, we are currently making every effort towards having employees return to work in the office 2 days per week, if that makes sense for their team. Everyone must be vaccinated to enter Mastercard offices at this time. Therefore, we expect all candidates to be vaccinated or to be approved for a medical or religious accommodation prior to commencing work at Mastercard.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Abide by Mastercard’s security policies and practices;
Ensure the confidentiality and integrity of the information being accessed;
Report any suspected information security violation or breach, and
Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.
Requisition ID: R-142147