Role at a glance
- Job function
-
Legal & Compliance Compliance & Regulatory Affairs
- Salary
- Not Disclosed
- Location
- Dublin, Ireland
- Work arrangement
- On-site
- Employment
- Full-time
Spotted an issue?
We’ll check it against the original posting.
About the role
Original posting provided by Mastercard
Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Director, Technology RiskDirector, Second Line of Defense - Technology RiskOverview:
• Provide independent second-line oversight, review, and validation of technology risks across markets, with a focus on Europe, ensuring alignment with IT policies, standards, controls, and regulatory expectations.
• Support maintenance of a technology risk management framework aligned with regulatory requirements and Mastercard’s Enterprise Risk Management and Operational Risk and Control frameworks.
• Support development of a control framework aligned with approved risk appetite, regulatory obligations, and technology risk exposure.
• Review risk and technology-related regulatory requirements and assess the adequacy of management responses to supervisory inspections and feedback.
• Lead the development of clear, decision-useful risk reporting for market and Group governance forums, supporting effective escalation and transparency.
Role:
Technology Risk Oversight in Market:
• Provide independent second line oversight and constructive review of market (Europe) relevant risks and risk assessment activities focusing on Operational Resilience and Security risks, this includes risk assessments related to material product and technology changes.
• Provide second line oversight across key control areas focusing on technology (such as change management, system availability, security, access, and data), reviewing control design, assessing operational effectiveness, and examining control testing results and assurance outcomes. Identifies, highlights and escalates material control deficiencies and remediation delays.
• Ensure documentation and ongoing monitoring of market relevant risks focused on technology risks, controls, and issues, including security testing results, through remediation to closure in approved GRC tools.
• Support and review security and resilience frameworks and strategies, ensuring they address threats and vulnerabilities specific to market’s specific processes, products and services.
• Ensures technology teams develop policies and standards specific to the local market, reducing risk exposure and promoting the implementation of robust IT and security controls.
• Oversee the development of relevant metrics focused on technology and security risk metrics, ensuring they are risk meaningful and outcomes focused, and aligned with approved risk appetite and tolerance thresholds.
Risk Management Framework:
• Maintain and support the adoption of the Technology Risk Standard in markets and technology and contribute to the design and delivery of supporting processes and tools that meet local regulatory requirements.
• Support the execution of the Enterprise Risk Management (ERM) and Operational Risk and Controls (ORC) Framework in market and technology groups.
• Develop and manages local risk processes, ensuring best practices are followed and that all procedures are documented, reviewed, and refreshed regularly.
• Support maintaining a control framework in coordination with Group First line of defense Technology and Security Risk teams.
Technology Risk Governance:
• Act as the 2LOD Risk representative at governance forums, risk committees, and senior management discussions, providing clear, evidence-based insights to support effective decision making.
• Review the effectiveness of risk reporting (focusing on technology risk) to management and governance committees and promotes alignment with Group standards
• Oversee the reporting of key risk indicators to governance bodies, ensuring timely remediation actions are taken when breaches occur.
Regulatory Engagement:
• Support regulatory examinations in Europe and across markets on matters related to risk matters and technology and security risk and controls.
• Review and supports risk and technology related submissions to regulatory authorities.
• Evaluates and supports the preparation of technology risk and assurance reports.
All About You:
• Proven experience collaborating with cross functional and global teams, managing multiple stakeholders and navigating various regulatory environments.
• Ability to manage multiple priorities, deliverables, and initiatives simultaneously in a fast paced environment.
• Background in formal second line of defense roles, providing independent oversight rather than direct operational responsibility.
• Proactive and curious mindset, with the ability to engage broadly across the business while maintaining focus on core responsibilities.
• Experience advocating for policy and procedure enhancements when necessary.
• Strong ability to identify opportunities for improvement and driving continuous enhancement.
• Familiarity with enterprise risk and control frameworks such as ISO, NIST CSF, or other equivalent international standards.
• Experience working with, and presenting to, senior management and governance forums.
• Excellent verbal and written communication abilities.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Abide by Mastercard’s security policies and practices;
Ensure the confidentiality and integrity of the information being accessed;
Report any suspected information security violation or breach, and
Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.
About the company
Mastercard
Large Enterprise
Mastercard is a global technology company in the payments industry, committed to empowering individuals and businesses through secure and efficient payment solutions. With a presence in over 210 countries, Mastercard connects consumers, financial institutions, merchants, and governments, enabling seamless transactions across various platforms. The company is at the forefront of innovation, focusing on enhancing financial inclusion and expanding access to digital payment technologies. Through its advanced network and partnerships, Mastercard continues to revolutionize the way people engage in commerce worldwide.
Mastercard is a global technology company in the payments industry, committed to empowering individuals and businesses through secure and efficient payment solutions. With a presence in over 210 countries, Mastercard connects consumers, financial institutions, merchants, and governments, enabling seamless transactions across various platforms. The company is at the forefront of innovation, focusing on enhancing financial inclusion and expanding access to digital payment technologies. Through its advanced network and partnerships, Mastercard continues to revolutionize the way people engage in commerce worldwide.