Mastercard Jobs

Job Information

MasterCard Head of Security Operations in Toronto, Canada

Our Purpose

We work to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments and businesses realize their greatest potential. Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. We cultivate a culture of inclusion (https://www.mastercard.us/en-us/vision/who-we-are/diversity-inclusion.html) for all employees that respects their individual strengths, views, and experiences. We believe that our differences enable us to be a better team – one that makes better decisions, drives innovation and delivers better business results.

Job Title

Head of Security Operations

Job Description

To support our continued growth and success, we are seeking a Senior Security Operations Manager to assist in all operational aspects of our security program. The ideal candidate will have solid experience in information security technologies including; incident, vulnerability and threat management as well as excellent communication and technical abilities. If you are looking for a challenge that will allow you to collaborate within dynamic teams and work in a fast-paced environment, this position is for you.

Responsibilities:

• Manage a team of Information Security Operations professionals

• Invite collaboration with both technical and business stakeholders advising on our security standards, policies and industry trends to help the business and customers succeed.

• Develop relationships to share knowledge and influence security objectives while being inclusive to all stake holders.

• Improve and maintain security services, focused on review efficiency, standards definition, and change management correctness.

• Maintain operational security posture through incident management, vulnerability management, key management, identity and access management, etc.

• Respond to security incidents, manage the process and escalate as required.

• Perform various security service functions including internal vulnerability scans, user access review, configuration and hardening validation and automation of many of these tasks within our SIEM.

• Document risk and mitigation controls, including policy/procedure updates.

• Participate in audits and assessments and provide support, as appropriate.

• Analyze established operational security controls and procedures and recommend improvements.

• Evaluate appropriate tools for supporting the security operations function.

• Participate in security on-call rotation.

Preference will be given to candidates with working experience in the following:

• Extensive Linux administration and troubleshooting experience.

• Extensive Network technology administration and troubleshooting experience.

• Low level PKI management and troubleshooting.

• Cyber Ark PIM.

• HSM for example Luna 7 or related appliances.

• KeySecure NAE,KMIP and related services.

• Splunk and Rsyslog filtering.

• Hashicorp Vault as it pertains to secret and PKI management.

• SIEMs like Qradar/Splunk ES/LogRhythm or related technologies

What you bring:

• Bachelor's Degree or equivalent experience/certification

• Windows and Linux/UNIX administration experience

• Solid understanding and troubleshooting is the ISO layer protocols.

• Working understanding of cryptography.

• Excellent verbal and written communication skills.

• Experience working in a PCI DSS, SOC or HIPPA environment

• Knowledge of all security domains including hardware security modules, single-sign on, and identity management.

• Preference will be given to candidates with the following certifications: CISSP, CCSP, CSSLP, OSCP, CISM etc.

COVID-19 Considerations

We value the safety of each member of our community because we know we’re all in this together. In many locations, which may change over time, we’ve implemented a virtual hiring process and continue to interview candidates by video or phone. In addition, in some locations, only individuals who have been fully vaccinated will be permitted inside Mastercard offices until further notice.

In the US, Mastercard is a government contractor, which may legally require most Mastercard employees to be vaccinated unless a verified approved medical or religious exemption is granted. Further, we are currently making every effort towards having employees return to work in the office 2 days per week, if that makes sense for their team. Everyone must be vaccinated to enter Mastercard offices at this time. Therefore, we expect all candidates to be vaccinated or to be approved for a medical or religious accommodation prior to commencing work at Mastercard.

Corporate Security Responsibility

All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:

  • Abide by Mastercard’s security policies and practices;

  • Ensure the confidentiality and integrity of the information being accessed;

  • Report any suspected information security violation or breach, and

  • Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.

Requisition ID: R-162647

DirectEmployers