- Location
- Pune, India
- Workplace
- Hybrid
- Type
- Full-time
- Department
- IT
- Seniority
- Director
- Education
- Bachelor
- Closing date
- Today
- Source
- Workday
Description
Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Director, Technology Risk ManagementDirector, Technology Risk ManagementLead technology risk oversight and help advance the broader MTS Risk Management Framework.
LOCATION: Pune (hybrid)
BUSINESS UNIT: Mastercard Services
FUNCTION: Second Line Risk Management
SHAPE THE FUTURE OF RISK MANAGEMENT AT MASTERCARD
Mastercard Transaction Services (MTS) enables secure, innovative and regulated money movement services globally. As the business grows and evolves, we are seeking an experienced Director, Technology Risk Management to strengthen independent technology risk oversight across our regulated entities and help advance the wider MTS Risk Management Framework.
This is a highly visible leadership role within the second line of defence. Technology risk is the primary focus, spanning technology, cyber, operational resilience, outsourcing and third-party risk. The successful candidate will also contribute across broader risk disciplines, including risk appetite, risk assessments, issue and risk event management, governance, reporting, policy and framework development.
Working with senior leaders across Technology, Engineering, Product, Cyber Security, Compliance, Regulatory Affairs and Legal Entity Management, you will provide credible challenge, translate complex risk matters into clear business insight, and support sound decision-making within a fast-moving global payments environment.
WHAT WILL YOU BE ACCOUNTABLE FOR
Strategic technology risk oversight
-Lead independent second line oversight and challenge of technology, cyber and operational resilience risks across MTS regulated entities.
-Evaluate material technology initiatives, transformation programmes and strategic investments from a risk perspective.
-Provide credible, evidence-based challenge of technology risk assessments, control environments, risk acceptances, control weaknesses and remediation plans.
-Monitor emerging technology and cyber risks, assess their relevance to MTS, and advise senior stakeholders on potential business and regulatory impacts.
-Oversee second line challenge of outsourcing, critical third-party arrangements, technology dependencies and concentration risks.
Broader Risk Management Framework leadership
-Play a leading role in the continued development, implementation and embedding of the MTS Risk Management Framework beyond the technology risk domain.
-Drive enhancements to risk governance, risk appetite, risk assessment, issue management, risk event management, risk acceptance and reporting processes.
-Contribute to the development and maintenance of risk policies, standards, methodologies, procedures and guidance.
-Lead or facilitate enterprise and legal entity risk assessments and support consistent application of the framework across regulated entities.
-Provide oversight and challenge of material non-technology risks, issues, events and remediation activities where required by the broader Risk team agenda.
-Partner with first line stakeholders to improve risk identification, assessment, escalation and management practices while preserving second line independence.
Governance, regulatory and Board engagement
-Prepare and present clear risk insights to executive leadership, governance committees and Boards.
-Lead or support regulatory examinations, supervisory engagements, independent reviews, audits and associated remediation programmes.
-Provide subject matter expertise on regulatory expectations relating to technology, operational resilience and broader risk governance.
-Contribute to strategic risk reporting, risk appetite oversight and escalation of material risk matters.
Leadership and influence
-Build trusted relationships across Technology, Engineering, Product and control functions and influence decisions through clear, practical risk advice.
-Promote a strong risk culture and constructive challenge across MTS.
-Mentor and develop risk professionals and contribute to capability building across the wider Risk Management function.
-Operate effectively across multiple legal entities, jurisdictions and risk domains in a complex global organisation.
WHAT ARE WE LOOKING FOR
Essential experience
-Significant experience in technology risk, cyber risk, operational risk, information security governance, technology controls, IT audit or a related discipline.
-Experience operating at senior level within financial services, payments, banking, fintech or another highly regulated sector.
-Demonstrated ability to provide independent oversight and credible challenge across complex technology environments and change programmes.
-Experience engaging senior executives, governance committees, Boards, regulators, auditors or independent reviewers.
-Proven ability to assess complex risks, identify material themes and translate them into clear, pragmatic recommendations.
-Strong executive communication, stakeholder management and influencing skills.
Desirable experience and knowledge
-Experience designing, implementing, enhancing or embedding an enterprise or legal entity Risk Management Framework.
-Practical experience across broader risk disciplines such as risk appetite, enterprise risk assessments, issue management, risk event management, risk acceptance, policy development and governance reporting.
-Experience working across technology and non-technology risk domains rather than within a single specialist discipline.
-Knowledge of payment systems, money movement platforms, e-money institutions or regulated payment service providers.
-Experience supporting regulatory examinations, supervisory engagements, remediation programmes or regulatory change initiatives.
-Knowledge of operational resilience, business continuity, outsourcing and third-party risk management.
-Experience working across multiple regulated entities or jurisdictions.
Qualifications
-A bachelor's degree in technology, information security, computer science, risk management or a related discipline is preferred. Relevant professional experience will also be considered.
-Professional certifications such as CRISC, CISSP, CISM, CISA, COBIT or ITIL are desirable.
The leadership profile
-Credible technology risk leader with the breadth to contribute to the full Risk Management Framework.
-Independent and appropriately challenging, with a collaborative and solutions-oriented style.
-Comfortable moving between strategic governance, regulatory priorities and detailed risk matters.
-Able to create clarity from complexity and focus stakeholders on material risks and outcomes.
-Committed to high standards of integrity, judgement and second line independence.
WHY JOIN MASTERCARD
-Influence technology risk management across a global, regulated money movement business.
-Help shape the evolution of the broader MTS Risk Management Framework.
-Engage directly with senior leaders, governance forums and regulatory stakeholders.
-Work on complex challenges spanning technology, cyber security, operational resilience, governance and enterprise risk.
-Make a meaningful contribution to the safety, resilience and responsible growth of Mastercard Transaction Services.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Abide by Mastercard’s security policies and practices;
Ensure the confidentiality and integrity of the information being accessed;
Report any suspected information security violation or breach, and
Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.