Title and SummarySenior Technology Risk Assurance Specialist, Services Technology Risk
Overview:
Services Technology Risk empowers Mastercard to provide regulators, auditors, customers, and leadership with confidence in the effectiveness of our technology risk management, security, resiliency, and control practices. Our mission is to enable Services to innovate and grow securely by embedding risk management into how technology products are designed, delivered, operated, and governed. We help Services build and operate secure, resilient, and trusted technology by partnering with Engineering, Product, Security and Business teams to proactively identify and manage risk, strengthen controls, and modernize assurance activities.
We are a multidisciplinary team of technology risk, controls, and assurance professionals focused on building and maintaining a strong technology control environment across the Services Business Unit. We provide risk intelligence, insights, and analysis while streamlining and scaling assurance activities through automation, analytics, reusability, and self-service capabilities that reduce manual effort and increase confidence in control effectiveness.
As Services continues to scale, increasing technology complexity, evolving regulatory expectations, fragmented processes, and growing customer assurance demands create new risks and challenges. Our role is to help teams navigate these challenges by building practical, scalable risk management practices that support innovation while maintaining secure, resilient, and well-controlled technology environments.
About the Role:
The Senior Technology Risk Analyst will serve as a key contributor within the Services Technology Risk team, helping drive assurance, control effectiveness, risk assessment, and continuous improvement activities across the Services technology landscape.
This role is ideal for someone who combines a strong foundation in technology risk and controls with hands-on assurance experience across frameworks such as PCI DSS, SOC 2, and ISO 27001. The successful candidate will be equally comfortable partnering with engineers to understand technical implementations, working with auditors and customers to demonstrate control effectiveness, and identifying opportunities to automate traditionally manual risk and assurance activities.
The ideal candidate is intellectually curious, collaborative, and passionate about leveraging data, analytics, AI, and automation to transform how risk management and assurance are performed. This individual will serve as a trusted advisor to stakeholders, helping teams understand risk, strengthen controls, and build secure, resilient technology solutions at scale. They view compliance and assurance not as a check-the-box exercise, but as an opportunity to strengthen engineering practices, improve control effectiveness, and enable the business to move faster with confidence.
The Senior Technology Risk Analyst, Services Technology Risk will:
oExecute technology control testing and assurance activities across Services programs, products, and platforms.
oSupport PCI DSS, SOC 1, SOC 2, ISO 27001, customer assurance engagements, and internal and external audit activities.
oPerform control design and operating effectiveness assessments across key technology domains including access management, change management, cloud security, resiliency, and data protection.
oConduct technology risk assessments to identify emerging risks, evaluate business impact, and support risk treatment and mitigation strategies.
oPartner with Engineering, Product, Security, Business Operations, and Architecture teams to identify control gaps and develop practical, risk-based remediation plans.
oSupport audit readiness efforts, including evidence management, stakeholder coordination, issue tracking, and validation of remediation activities.
oAnalyze risk, control, issue, and assurance data to identify trends, systemic weaknesses, and opportunities for process improvement.
oDrive improvements in risk and assurance processes through automation, analytics, AI-enabled solutions, and continuous monitoring capabilities.
oSupport the development and enhancement of technology control libraries, testing methodologies, and reusable assurance artifacts.
oTranslate regulatory, customer, and framework requirements into practical and scalable control solutions that engineering teams can effectively implement.
oMonitor and report on technology risk, compliance, and control health metrics, escalating issues and exceptions when appropriate.
oPromote a culture where risk management is viewed as a business enabler that supports innovation, resiliency, and customer trust.
All About You:
oExperience in technology risk management, technology audit, information security, compliance, internal controls, or related disciplines.
oStrong hands-on experience supporting or executing assurance activities across frameworks such as PCI DSS, SOC 1, SOC 2, ISO 27001, customer assurance programs, or regulatory examinations.
oSolid understanding of technology risk management principles and experience identifying, assessing, mitigating, monitoring, and reporting technology risks.
oExperience evaluating control design and operating effectiveness, performing control testing, documenting observations, and supporting remediation efforts.
oStrong knowledge of technology and security controls across areas such as identity and access management, change management, cloud security, software development lifecycle, encryption, logging and monitoring, vulnerability management, and operational resiliency.
oAbility to understand technical architectures and effectively discuss risks and controls with engineering, security, and operations teams.
oFamiliarity with technology risk and security frameworks such as PCI DSS, ISO 27001, NIST, COBIT, SOC, and related industry standards.
oDemonstrated passion for automation, AI, analytics, and continuous improvement, with experience leveraging technology to improve risk management and assurance outcomes.
oAbility to analyze large data sets, identify trends, uncover systemic issues, and translate findings into actionable insights.
oStrong problem-solving skills with a practical and risk-based approach to decision-making.
oComfortable navigating ambiguity and working independently while managing multiple priorities in a fast-paced environment.
oStrong verbal and written communication skills, with the ability to present complex technical and risk concepts to both technical and non-technical audiences.
oAbility to build trusted relationships and collaborate effectively across Engineering, Product, Security, Architecture, Operations, and business stakeholders.
oCurious, proactive, and self-motivated, with a strong sense of ownership and a desire to continuously learn and expand expertise.
oPassionate about helping teams build secure, resilient, well-controlled technology while enabling innovation and business growth.
Corporate Security ResponsibilityAll activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
- Abide by Mastercard's security policies and practices;
- Ensure the confidentiality and integrity of the information being accessed;
- Report any suspected information security violation or breach, and
- Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
In line with Mastercard's total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary and may be eligible for an annual bonus or commissions depending on the role. The base salary offered may vary depending on multiple factors, including but not limited to location, job-related knowledge, skills, and experience. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance); flexible spending account and health savings account; paid leaves (including 16 weeks of new parent leave and up to 20 days of bereavement leave); 80 hours of Paid Sick and Safe Time, 25 days of vacation time and 5 personal days, pro-rated based on date of hire; 10 annual paid U.S. observed holidays; 401k with a best-in-class company match; deferred compensation for eligible roles; fitness reimbursement or on-site fitness facilities; eligibility for tuition reimbursement; and many more. Mastercard benefits for interns generally include: 56 hours of Paid Sick and Safe Time; jury duty leave; and on-site fitness facilities in some locations.
Pay RangesNew York City, New York: $106,000 - $169,000 USD