As an Information Security Engineer, you will integrate security in product design, conduct risk assessments, and recommend security technologies while collaborating with various teams.
Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Information Security Engineer
We areThe Identity Solutions team is seeking a skilled and experienced Security Engineer. You will play a crucial role to ensure products integrate security requirements during design and throughout the product's lifecycle. You will work closely with various security teams to provide product engineers with security capabilities and recommendations. You'll mentor and guide technology, product and software development teams, ensuring high-quality outcomes, and play a vital role in shaping our technology and security landscape.
What You'll Do:
• Collaborate with software developers, system engineers, and other stakeholders to integrate security controls into the development lifecycle• Provide input to designs and architectures that include business and regulatory requirements• Provide guidance on best practices for secure designs• Guide developers through proper application development during various design phases• Conduct risk assessments and perform threat modeling to identify potential security vulnerabilities and design weaknesses• Identify security controls that will address security gaps• Evaluate and recommend security technologies, tools, and services• Perform security reviews and audits of system designs and implementations• Stay updated on industry trends, emerging threats, and best practices in security designs
What you bring:
• Strong communication skills with the ability to collaborate with technical and non-technical stakeholders• Experience as a Security Design Engineer or in a similar role• Experience with secure software development methodologies (e.g. OWASP Top 10, CWE/SANS Tops 25, etc.)• Knowledge of encryption algorithms, authentication protocols, and secure communication protocols• Strong understanding of network security best practices, security principles and standards, and frameworks (e.g., ISO 27001, NIST Cybersecurity Framework, etc.)• Understanding of network protocols, architecture, and topology for cloud and on-premises implementations• Familiarity with cloud security principles and best practices (AWS, GCP, Azure)• Ability to perform risk assessments and threat modeling to identify security risks and mitigations• Effective communication and interpersonal skills, with the ability to work collaboratively in a team environment
Additional nice to have:
• Technical experience with scripting/programming languages• CISSP, CCSP or industry-recognized / vendor-specific security certification(s)• Previous experience in an audited environment complying with common regulation standards• Experience with DevSecOps
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Information Security Engineer
We areThe Identity Solutions team is seeking a skilled and experienced Security Engineer. You will play a crucial role to ensure products integrate security requirements during design and throughout the product's lifecycle. You will work closely with various security teams to provide product engineers with security capabilities and recommendations. You'll mentor and guide technology, product and software development teams, ensuring high-quality outcomes, and play a vital role in shaping our technology and security landscape.
What You'll Do:
• Collaborate with software developers, system engineers, and other stakeholders to integrate security controls into the development lifecycle• Provide input to designs and architectures that include business and regulatory requirements• Provide guidance on best practices for secure designs• Guide developers through proper application development during various design phases• Conduct risk assessments and perform threat modeling to identify potential security vulnerabilities and design weaknesses• Identify security controls that will address security gaps• Evaluate and recommend security technologies, tools, and services• Perform security reviews and audits of system designs and implementations• Stay updated on industry trends, emerging threats, and best practices in security designs
What you bring:
• Strong communication skills with the ability to collaborate with technical and non-technical stakeholders• Experience as a Security Design Engineer or in a similar role• Experience with secure software development methodologies (e.g. OWASP Top 10, CWE/SANS Tops 25, etc.)• Knowledge of encryption algorithms, authentication protocols, and secure communication protocols• Strong understanding of network security best practices, security principles and standards, and frameworks (e.g., ISO 27001, NIST Cybersecurity Framework, etc.)• Understanding of network protocols, architecture, and topology for cloud and on-premises implementations• Familiarity with cloud security principles and best practices (AWS, GCP, Azure)• Ability to perform risk assessments and threat modeling to identify security risks and mitigations• Effective communication and interpersonal skills, with the ability to work collaboratively in a team environment
Additional nice to have:
• Technical experience with scripting/programming languages• CISSP, CCSP or industry-recognized / vendor-specific security certification(s)• Previous experience in an audited environment complying with common regulation standards• Experience with DevSecOps
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
- Abide by Mastercard's security policies and practices;
- Ensure the confidentiality and integrity of the information being accessed;
- Report any suspected information security violation or breach, and
- Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
Top Skills
Authentication Protocols
AWS
Azure
Cwe/Sans Top 25
Encryption Algorithms
GCP
Iso 27001
Nist Cybersecurity Framework
Owasp Top 10
Secure Communication Protocols
Similar Jobs at Mastercard
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Manage consulting deliverables and workstreams across various industries, develop strategies leveraging data and technology, and mentor junior consultants.
Top Skills:
ExcelPowerPointWord
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
As an Associate Consultant, you will solve strategic problems for clients, work with data and technology, and receive mentorship. You'll collaborate on various projects across industries, developing consulting skills while helping businesses improve performance.
Top Skills:
ExcelPythonSASSQLTableau
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
As an Associate Consultant Intern, you will assist clients with strategic business challenges, gain mentorship, and collaborate on projects while participating in networking and team-building activities.
Top Skills:
Business Intelligence PlatformsExcelPythonSASSQLTableau
What you need to know about the Edinburgh Tech Scene
From traditional pubs and centuries-old universities to sleek shopping malls and glass-paneled office buildings, Edinburgh's architecture reflects its unique blend of history and modernity. But the fusion of past and future isn't just visible in its buildings; it's also shaping the city's economy. Named the United Kingdom's leading technology ecosystem outside of London, Edinburgh plays host to major global companies like Apple and Adobe, as well as a growing number of innovative startups in fields like cybersecurity, finance and healthcare.

