This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Business Security Engineering Guild is looking for a Senior Information Security Engineer to contribute and maintain reusable security requirements that software engineering teams will leverage. The ideal candidate is passionate about cybersecurity, has broad knowledge & experience in various security domains and has a creative mindset.
Job Responsibility:
Develop, deliver and maintain the reusable security requirements
Create and maintain documentation, procedures and analytics with respect to the security requirements
Work with cross-functional teams to help them understand security requirements and gather feedback to make the process more efficient
Consult with development and operational teams to securely design applications and services following industry best practices
Demonstrate a working knowledge of information security principles, theories and concepts
Perform security reviews and threat modelling for Mastercard applications
Identify methods to mitigate threats, attacks, and risks to payment applications
Abide by Mastercard’s security policies and practices
Ensure the confidentiality and integrity of the information being accessed
Report any suspected information security violation or breach
Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines
Requirements:
Knowledge of information security, risk management, and data privacy within the domain of digital commerce, including relevant practical experience
Good understanding of identity management, user authentication and authorization principles
Experience working and implementing S-SLDC at scale. Demonstrate a broad awareness of security engineering concepts and practices across all phases of the software development lifecycle
Experience providing security architecture advice for web-based network environments and secure communication between environments, including web services, web applications, and mobile applications
Experience in mobile security architecture concepts, design, and implementation along with Android and iOS is a plus
Basic knowledge and experience in cryptography, including several of the following: encryption, hashing, key management, digital certificates, and TLS
Technical experience with Java or similar enterprise programming language, especially related to secure coding best practices, is a plus
Working knowledge and technical security experience with Linux is a plus
Demonstrated the ability to articulate and communicate effectively to diverse audiences and properly translate security and risk management terminology into business terms, and recommend alternative solutions to these stakeholders
National Initiative for Cybersecurity Education (NICE) competency proficiency levels of proficient to advanced in the following areas: Information Assurance, Information Management, Information Technology Assessment, Requirement Analysis, Technology Awareness, Threat Analysis, Data Privacy and Protection, Communication, Critical Thinking, Problem Solving
Nice to have:
Experience in mobile security architecture concepts, design, and implementation along with Android and iOS is a plus
Technical experience with Java or similar enterprise programming language, especially related to secure coding best practices, is a plus
Working knowledge and technical security experience with Linux is a plus