This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Mastercard is seeking candidates to join the Data Protection team with a focus on ShadowIT risk management, governance, and enforcement. As Mastercard accelerates innovation through SaaS, cloud services, and automation platforms, unapproved technology usage presents material data security, privacy, and compliance risks. This role is critical to defining and operating a clear, defensible blocking and escalation framework that protects Mastercard data while enabling informed business decisions. Can you design and operate a structured blocking and escalation strategy for unapproved applications? Can you balance security risk, business impact, and policy alignment in high visibility decisions? Can you lead governance processes and metrics that scale across a global enterprise?
Job Responsibility:
Contribute to the execution of the Shadow IT and Data Protection roadmap, with primary ownership of enforcement, escalation, and governance processes
Develop and maintain a Shadow IT blocking strategy framework for unapproved applications, including: Blocking criteria and decision thresholds, Risk scoring aligned to data sensitivity, access, and exposure, Defined escalation paths for exceptions and high impact cases
Document all blocking decisions with clear business justification, technical impact assessment, and alignment to security and data protection policy
Establish and maintain communication protocols to notify stakeholders of application blocks, including timelines, approved alternatives, and available support resources
Manage unblock requests and escalations and exception processing, coordinating with Security Operations and business stakeholders to evaluate risk and determine outcomes
Partner with application, platform, and business teams to define paths to compliance, including remediation, onboarding to approved services, or decommissioning
Track and report Shadow IT metrics, including blocking trends, unblock volumes, escalation outcomes, incidents, and stakeholder satisfaction
Work side by side with other team members to build and mature the Shadow IT governance process, while taking lead ownership of defined processes such as: Escalations and exception handling, Cross functional coordination, Technical impact assessment, Policy alignment and enforcement
Build and operationalize a next generation Shadow IT governance model that provides transparency, consistency, and defensibility across the enterprise
Develop a way to automatically tag approved apps
Work with stakeholders to ensure all browser types experience is consistent (notifications, blocks, etc)
Work with stakeholders to ensure
Requirements:
Experience operating or designing security governance or enforcement programs in large, complex environments
Strong understanding of information security, data protection, and risk management, particularly as applied to SaaS and third party technologies
Demonstrated ability to make and defend risk based decisions that balance security, policy, and business impact
Experience working cross functionally with Legal, Privacy, Compliance, and Technology teams
Ability to clearly document decisions and articulate technical and business impact to diverse audiences
Strong verbal and written communication skills, including executive ready summaries
Demonstrated technical competency in security engineering through hands on experience or relevant qualifications
Design and implement data models and analytics frameworks to support Shadow IT blocking decisions, escalation tracking, and governance reporting
Develop automated processes and dashboards to provide visibility into blocking activity, unblock requests, escalation outcomes, and trend analysis
Evaluate and integrate data sources (e.g., SaaS discovery tools, cloud telemetry, intake systems) to ensure accurate and timely Shadow IT decisioning data
Analyze and interpret complex datasets to identify risk patterns, repeat offenders, policy gaps, and opportunities for control improvement
Perform completeness and quality assessments to validate Shadow IT enforcement coverage and identify governance gaps or process breakdowns
Demonstrated ability to perform data analysis across security policies and technology usage to identify trends, assess risk, and inform governance decisions, including the capability to quickly learn and operate tooling used to manage product roadmaps and evaluate scoring criteria for alignment with Mastercard’s risk appetite
Data security and governance (in depth knowledge)
Information security engineering
Risk assessment and decision frameworks
Policy interpretation and enforcement
Cross functional coordination and escalation management
Nice to have:
Experience with SaaS security posture management (SSPM), CASB, or DSPM
Familiarity with enterprise intake, exception, or risk acceptance processes
Cloud security experience
Automation or data analytics experience
Alteryx (or equivalent ETL), PowerBI (or equivalent visualization), PowerAutomate, etc experience is a plus
Application development experience is preferred, including the ability to develop scripts, work with APIs, and leverage AI capabilities in support of Shadow IT initiatives