The Manager of Risk Management in Cyber Security oversees independent risk management, supports policies, and promotes strong risk culture across Cyber Security functions at Mastercard.
Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Manager, Risk Management Cyber Security
Role Profile/Job Description
Who is Mastercard:
Mastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential.
Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all.
Role Overview:
This role sits within the Second Line of Defence (2LOD) Risk function and provides independent oversight and challenge of Cyber Security risk across Vocalink Mastercard. You will act as a functional risk partner to the First Line of Defence Cyber Security function, ensuring robust risk management practices are embedded and aligned with regulatory expectations and industry best practice.
The role supports the delivery of a secure and resilient service to millions of citizens and businesses, safeguarding critical payment infrastructure and data assets. You will champion cyber security and resilience risk internally and at senior management level, helping to maintain trust in the UK financial system.
This role will report into the Vice President of Risk Management (Cyber Security).
The Role Holder Will:• Provide second line expertise and challenge around all aspects of Cyber Security related risks• Support the Vocalink risk management approach and implemented policies and procedures to minimize Cyber Security risk exposure and drive robust controls.• Support the implementation and embedding of the Enterprise Risk Management Framework for Cyber Security risk, ensuring completeness and accuracy of risk assessments, control standards, residual risk evaluations, and issue management.• Partner with first line Cyber Security teams to promote balanced risk-taking and a strong risk culture.• Represent Cyber Security risk at relevant committees and forums, deputising for the VP Risk Management when required.• Provide clear and concise risk briefings to senior stakeholders, including the CRO ensuring timely escalation of material risks and appetite breaches.• Liaise with and support the risk and control owners to resolve any questions, queries and challenges relating to cyber security relevant certification and or customer requirements for example, during an audit as well as in the pre and post audit stages.
All About You (Knowledge, Skill, and Experience):• Professional cyber security certifications (e.g., CRISC, CISA, CISM, CISSP, ISO 27001 Lead Auditor) preferred.• Knowledge of key cyber security relevant control domains, frameworks and standards (e.g., NIST, ISO27001, CSF, CRI, MITRE, etc.).• Strong understanding of risk management principles and the Three Lines of Defence model.• Enthusiastic about cyber security including tracking industry trends and emerging risks• Experience of applying operational risk frameworks and understanding of risk assessment methodologies• Proven experience in Cyber Security risk and controls oversight within a financial institution or critical infrastructure environment.• Ability to analyse complex data with attention to detail and articulate risk insights clearly to technical and non-technical audiences.• Skilled in building trusted relationships with stakeholders at all levels.• Highly organised, adaptable, and able to work independently with minimal supervision and as part of a team.• Excellent written and verbal communication skills.
Desirable:• Experience within Critical National Infrastructure responsible organisations• Financial Services experience particularly in payments and relevant infrastructure• Experience working with regulators (Bank of England supervision)
Corporate Security Responsibility:
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:• Abide by Mastercard's security policies and practices;• Ensure the confidentiality and integrity of the information being accessed;• Report any suspected information security violation or breach, and• Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Manager, Risk Management Cyber Security
Role Profile/Job Description
Who is Mastercard:
Mastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential.
Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all.
Role Overview:
This role sits within the Second Line of Defence (2LOD) Risk function and provides independent oversight and challenge of Cyber Security risk across Vocalink Mastercard. You will act as a functional risk partner to the First Line of Defence Cyber Security function, ensuring robust risk management practices are embedded and aligned with regulatory expectations and industry best practice.
The role supports the delivery of a secure and resilient service to millions of citizens and businesses, safeguarding critical payment infrastructure and data assets. You will champion cyber security and resilience risk internally and at senior management level, helping to maintain trust in the UK financial system.
This role will report into the Vice President of Risk Management (Cyber Security).
The Role Holder Will:• Provide second line expertise and challenge around all aspects of Cyber Security related risks• Support the Vocalink risk management approach and implemented policies and procedures to minimize Cyber Security risk exposure and drive robust controls.• Support the implementation and embedding of the Enterprise Risk Management Framework for Cyber Security risk, ensuring completeness and accuracy of risk assessments, control standards, residual risk evaluations, and issue management.• Partner with first line Cyber Security teams to promote balanced risk-taking and a strong risk culture.• Represent Cyber Security risk at relevant committees and forums, deputising for the VP Risk Management when required.• Provide clear and concise risk briefings to senior stakeholders, including the CRO ensuring timely escalation of material risks and appetite breaches.• Liaise with and support the risk and control owners to resolve any questions, queries and challenges relating to cyber security relevant certification and or customer requirements for example, during an audit as well as in the pre and post audit stages.
All About You (Knowledge, Skill, and Experience):• Professional cyber security certifications (e.g., CRISC, CISA, CISM, CISSP, ISO 27001 Lead Auditor) preferred.• Knowledge of key cyber security relevant control domains, frameworks and standards (e.g., NIST, ISO27001, CSF, CRI, MITRE, etc.).• Strong understanding of risk management principles and the Three Lines of Defence model.• Enthusiastic about cyber security including tracking industry trends and emerging risks• Experience of applying operational risk frameworks and understanding of risk assessment methodologies• Proven experience in Cyber Security risk and controls oversight within a financial institution or critical infrastructure environment.• Ability to analyse complex data with attention to detail and articulate risk insights clearly to technical and non-technical audiences.• Skilled in building trusted relationships with stakeholders at all levels.• Highly organised, adaptable, and able to work independently with minimal supervision and as part of a team.• Excellent written and verbal communication skills.
Desirable:• Experience within Critical National Infrastructure responsible organisations• Financial Services experience particularly in payments and relevant infrastructure• Experience working with regulators (Bank of England supervision)
Corporate Security Responsibility:
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:• Abide by Mastercard's security policies and practices;• Ensure the confidentiality and integrity of the information being accessed;• Report any suspected information security violation or breach, and• Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
- Abide by Mastercard's security policies and practices;
- Ensure the confidentiality and integrity of the information being accessed;
- Report any suspected information security violation or breach, and
- Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
Top Skills
Cisa
Cism
Cissp
Cri
Crisc
Csf
Iso 27001
Iso27001
Mitre
Nist
Similar Jobs at Mastercard
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
The role is part of a graduate program aimed at developing skills in business development, with a focus on security responsibilities and information integrity.
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
The Director of Product Management will lead strategies for Payment Performance data products, ensuring alignment with market needs and driving go-to-market execution across teams.
Top Skills:
AnalyticsData ProductsInsightsPayment Consulting
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
The Manager of Channel Partnership Sales oversees partner lifecycle management, aiming to meet regional revenue targets through effective partner recruitment, onboarding, and activation, while managing C-level relationships.
What you need to know about the Edinburgh Tech Scene
From traditional pubs and centuries-old universities to sleek shopping malls and glass-paneled office buildings, Edinburgh's architecture reflects its unique blend of history and modernity. But the fusion of past and future isn't just visible in its buildings; it's also shaping the city's economy. Named the United Kingdom's leading technology ecosystem outside of London, Edinburgh plays host to major global companies like Apple and Adobe, as well as a growing number of innovative startups in fields like cybersecurity, finance and healthcare.

