1 hour ago

Senior Technology Risk Assurance Specialist, Services Technology Risk

Mastercard

$106,000 - $169,000 Yearly

New York City, New YorkUnited States

📍 On-site

Category: SecuritySubcategory: Compliance & RiskType: Full-time


Our Purpose

Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.

Title and Summary

Senior Technology Risk Assurance Specialist, Services Technology Risk

Overview:
Services Technology Risk empowers Mastercard to provide regulators, auditors, customers, and leadership with confidence in the effectiveness of our technology risk management, security, resiliency, and control practices. Our mission is to enable Services to innovate and grow securely by embedding risk management into how technology products are designed, delivered, operated, and governed. We help Services build and operate secure, resilient, and trusted technology by partnering with Engineering, Product, Security and Business teams to proactively identify and manage risk, strengthen controls, and modernize assurance activities.
We are a multidisciplinary team of technology risk, controls, and assurance professionals focused on building and maintaining a strong technology control environment across the Services Business Unit. We provide risk intelligence, insights, and analysis while streamlining and scaling assurance activities through automation, analytics, reusability, and self-service capabilities that reduce manual effort and increase confidence in control effectiveness.
As Services continues to scale, increasing technology complexity, evolving regulatory expectations, fragmented processes, and growing customer assurance demands create new risks and challenges. Our role is to help teams navigate these challenges by building practical, scalable risk management practices that support innovation while maintaining secure, resilient, and well-controlled technology environments.

About the Role:
The Senior Technology Risk Analyst will serve as a key contributor within the Services Technology Risk team, helping drive assurance, control effectiveness, risk assessment, and continuous improvement activities across the Services technology landscape.
This role is ideal for someone who combines a strong foundation in technology risk and controls with hands-on assurance experience across frameworks such as PCI DSS, SOC 2, and ISO 27001. The successful candidate will be equally comfortable partnering with engineers to understand technical implementations, working with auditors and customers to demonstrate control effectiveness, and identifying opportunities to automate traditionally manual risk and assurance activities.
The ideal candidate is intellectually curious, collaborative, and passionate about leveraging data, analytics, AI, and automation to transform how risk management and assurance are performed. This individual will serve as a trusted advisor to stakeholders, helping teams understand risk, strengthen controls, and build secure, resilient technology solutions at scale. They view compliance and assurance not as a check-the-box exercise, but as an opportunity to strengthen engineering practices, improve control effectiveness, and enable the business to move faster with confidence.

The Senior Technology Risk Analyst, Services Technology Risk will:
o Execute technology control testing and assurance activities across Services programs, products, and platforms.
o Support PCI DSS, SOC 1, SOC 2, ISO 27001, customer assurance engagements, and internal and external audit activities.
o Perform control design and operating effectiveness assessments across key technology domains including access management, change management, cloud security, resiliency, and data protection.
o Conduct technology risk assessments to identify emerging risks, evaluate business impact, and support risk treatment and mitigation strategies.
o Partner with Engineering, Product, Security, Business Operations, and Architecture teams to identify control gaps and develop practical, risk-based remediation plans.
o Support audit readiness efforts, including evidence management, stakeholder coordination, issue tracking, and validation of remediation activities.
o Analyze risk, control, issue, and assurance data to identify trends, systemic weaknesses, and opportunities for process improvement.
o Drive improvements in risk and assurance processes through automation, analytics, AI-enabled solutions, and continuous monitoring capabilities.
o Support the development and enhancement of technology control libraries, testing methodologies, and reusable assurance artifacts.
o Translate regulatory, customer, and framework requirements into practical and scalable control solutions that engineering teams can effectively implement.
o Monitor and report on technology risk, compliance, and control health metrics, escalating issues and exceptions when appropriate.
o Promote a culture where risk management is viewed as a business enabler that supports innovation, resiliency, and customer trust.

All About You:
o Experience in technology risk management, technology audit, information security, compliance, internal controls, or related disciplines.
o Strong hands-on experience supporting or executing assurance activities across frameworks such as PCI DSS, SOC 1, SOC 2, ISO 27001, customer assurance programs, or regulatory examinations.
o Solid understanding of technology risk management principles and experience identifying, assessing, mitigating, monitoring, and reporting technology risks.
o Experience evaluating control design and operating effectiveness, performing control testing, documenting observations, and supporting remediation efforts.
o Strong knowledge of technology and security controls across areas such as identity and access management, change management, cloud security, software development lifecycle, encryption, logging and monitoring, vulnerability management, and operational resiliency.
o Ability to understand technical architectures and effectively discuss risks and controls with engineering, security, and operations teams.
o Familiarity with technology risk and security frameworks such as PCI DSS, ISO 27001, NIST, COBIT, SOC, and related industry standards.
o Demonstrated passion for automation, AI, analytics, and continuous improvement, with experience leveraging technology to improve risk management and assurance outcomes.
o Ability to analyze large data sets, identify trends, uncover systemic issues, and translate findings into actionable insights.
o Strong problem-solving skills with a practical and risk-based approach to decision-making.
o Comfortable navigating ambiguity and working independently while managing multiple priorities in a fast-paced environment.
o Strong verbal and written communication skills, with the ability to present complex technical and risk concepts to both technical and non-technical audiences.
o Ability to build trusted relationships and collaborate effectively across Engineering, Product, Security, Architecture, Operations, and business stakeholders.
o Curious, proactive, and self-motivated, with a strong sense of ownership and a desire to continuously learn and expand expertise.
o Passionate about helping teams build secure, resilient, well-controlled technology while enabling innovation and business growth.

Mastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact reasonable_accommodation@mastercard.com and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.

Corporate Security Responsibility

All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:

  • Abide by Mastercard’s security policies and practices;

  • Ensure the confidentiality and integrity of the information being accessed;

  • Report any suspected information security violation or breach, and

  • Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.

In line with Mastercard’s total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary and may be eligible for an annual bonus or commissions depending on the role. The base salary offered may vary depending on multiple factors, including but not limited to location, job-related knowledge, skills, and experience. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance); flexible spending account and health savings account; paid leaves (including 16 weeks of new parent leave and up to 20 days of bereavement leave); 80 hours of Paid Sick and Safe Time, 25 days of vacation time and 5 personal days, pro-rated based on date of hire; 10 annual paid U.S. observed holidays; 401k with a best-in-class company match; deferred compensation for eligible roles; fitness reimbursement or on-site fitness facilities; eligibility for tuition reimbursement; and many more. Mastercard benefits for interns generally include: 56 hours of Paid Sick and Safe Time; jury duty leave; and on-site fitness facilities in some locations.

Pay Ranges

New York City, New York: $106,000 - $169,000 USD

Share This Job

Apply for this position

Interested? Click below to submit your application.

Apply to this job
Mastercard logo

Mastercard

Website

Connecting everyone to priceless possibilities

Mastercard drives economic growth and enables individuals across more than 200 countries and territories globally. Collaborating with customers, it fosters a sustainable economy that promotes prosperity for all. The company offers diverse digital payment options, ensuring transactions are secure, easy, intelligent, and accessible. Through its technology, innovation, partnerships, and networks, Mastercard delivers distinctive products and services that empower people, businesses, and governments to achieve their fullest potential.

5,001+ employees
Purchase, NY, New York, US
Public Company
technology
consulting
processing
risk management
fintech
payments
fraud prevention
cybersecurity

Salary Benchmark

This role pays $106K$169K per year. The average salary for Compliance & Risk roles in web3 is $127K$323K, based on 14 jobs with published salary data.

At Market Rate
$50K$127K$323K avg$1000K

View all Compliance & Risk salaries →