Mastercard logo

Director, Technology Risk Management

Mastercard · Posted Oct 7

Global technology company connecting consumers, financial institutions, merchants, and businesses through secure payment processing and digital commerce solutions

Pune, Mahārāshtra, IndiaFull-timeHybridDirector/Executive12+ years₹60.0L–₹1.0Cr yearly49 applicants
PaymentsFinancial ServicesFintechCredit CardsBankingPublic Company
Full time

Get a personal compatibility score

Add a resume for personal matches

About the role

Mastercard Transaction Services (MTS) enables secure, innovative and regulated money movement services globally, and this role sits in the second line of defence risk management function supporting MTS regulated entities. The position leads independent technology risk oversight spanning technology, cyber, operational resilience, outsourcing and third-party risk, while contributing to the broader MTS Risk Management Framework. It involves credible challenge of risk assessments and remediation plans, governance and regulatory engagement, and partnership with Technology, Engineering, Product, Cyber Security, Compliance and Legal Entity Management stakeholders in a global payments environment.

What you will do

  • Lead independent second line oversight and challenge of technology, cyber and operational resilience risks across MTS regulated entities.
  • Evaluate material technology initiatives, transformation programmes and strategic investments from a risk perspective.
  • Provide credible, evidence-based challenge of technology risk assessments, control environments, risk acceptances, control weaknesses and remediation plans.
  • Monitor emerging technology and cyber risks, assess their relevance to MTS, and advise senior stakeholders on potential business and regulatory impacts.
  • Oversee second line challenge of outsourcing, critical third-party arrangements, technology dependencies and concentration risks.
  • Play a leading role in the continued development, implementation and embedding of the MTS Risk Management Framework beyond the technology risk domain.
  • Drive enhancements to risk governance, risk appetite, risk assessment, issue management, risk event management, risk acceptance and reporting processes.
  • Contribute to the development and maintenance of risk policies, standards, methodologies, procedures and guidance.
  • Lead or facilitate enterprise and legal entity risk assessments and support consistent application of the framework across regulated entities.
  • Provide oversight and challenge of material non-technology risks, issues, events and remediation activities where required by the broader Risk team agenda.
  • Partner with first line stakeholders to improve risk identification, assessment, escalation and management practices while preserving second line independence.
  • Prepare and present clear risk insights to executive leadership, governance committees and Boards.
  • Lead or support regulatory examinations, supervisory engagements, independent reviews, audits and associated remediation programmes.
  • Provide subject matter expertise on regulatory expectations relating to technology, operational resilience and broader risk governance.
  • Contribute to strategic risk reporting, risk appetite oversight and escalation of material risk matters.
  • Build trusted relationships across Technology, Engineering, Product and control functions and influence decisions through clear, practical risk advice.
  • Promote a strong risk culture and constructive challenge across MTS.
  • Mentor and develop risk professionals and contribute to capability building across the wider Risk Management function.
  • Operate effectively across multiple legal entities, jurisdictions and risk domains in a complex global organisation.

Skills used in this role

technology riskcyber riskoperational riskinformation securityIT audittechnology controlsoperational resiliencethird-party risk managementoutsourcing riskrisk governancerisk appetiteenterprise risk assessmentissue managementrisk event managementpolicy developmentregulatory reportingCRISCCISSPCISMCISACOBITITILstakeholder managementexecutive communicationinfluencing

What the employer is looking for

  • Significant experience in technology risk, cyber risk, operational risk, information security governance, technology controls, IT audit or a related discipline.
  • Experience operating at senior level within financial services, payments, banking, fintech or another highly regulated sector.
  • Demonstrated ability to provide independent oversight and credible challenge across complex technology environments and change programmes.
  • Experience engaging senior executives, governance committees, Boards, regulators, auditors or independent reviewers.
  • Proven ability to assess complex risks, identify material themes and translate them into clear, pragmatic recommendations.
  • Strong executive communication, stakeholder management and influencing skills.
  • A bachelor's degree in technology, information security, computer science, risk management or a related discipline is preferred. Relevant professional experience will also be considered.
  • Professional certifications such as CRISC, CISSP, CISM, CISA, COBIT or ITIL are desirable.
  • Credible technology risk leader with the breadth to contribute to the full Risk Management Framework.
  • Independent and appropriately challenging, with a collaborative and solutions-oriented style.
  • Comfortable moving between strategic governance, regulatory priorities and detailed risk matters.
  • Able to create clarity from complexity and focus stakeholders on material risks and outcomes.
  • Committed to high standards of integrity, judgement and second line independence.

Preferred qualifications

  • Experience designing, implementing, enhancing or embedding an enterprise or legal entity Risk Management Framework.
  • Practical experience across broader risk disciplines such as risk appetite, enterprise risk assessments, issue management, risk event management, risk acceptance, policy development and governance reporting.
  • Experience working across technology and non-technology risk domains rather than within a single specialist discipline.
  • Knowledge of payment systems, money movement platforms, e-money institutions or regulated payment service providers.
  • Experience supporting regulatory examinations, supervisory engagements, remediation programmes or regulatory change initiatives.
  • Knowledge of operational resilience, business continuity, outsourcing and third-party risk management.
  • Experience working across multiple regulated entities or jurisdictions.

Benefits and support

  • Compensation and benefits are detailed in the job posting

About Mastercard

Mastercard is a global technology company in the payments industry that connects consumers, financial institutions, merchants, governments, and businesses worldwide. It operates a fast and secure payment processing network that spans more than 200 countries and territories. Through innovative products and solutions in credit, debit, digital assets, and security, Mastercard makes commerce safer, simpler, and more accessible.

Industry
Payments
Company size
10001+ employees
Founded
1966
Location
Purchase, New York, USA
Funding stage
Public Company

Funding

Public Company · $115M raised

Public Shareholders

Leadership

MM
Michael Miebach

Chief Executive Officer

SM
Sachin Mehra

Chief Business Officer

EM
Ed McLaughlin

President & Chief Technology Officer

SM
Susan Muigai

Chief People Officer