Leads Mastercard’s technology risk and controls governance strategy, including control testing methodologies, risk-based prioritization, control integration, audit and regulatory support, executive reporting, and continuous maturity improvement. Partners with technology, risk, security, regulatory, and business stakeholders to standardize controls, automate processes, manage emerging technology risks, and strengthen enterprise compliance and operational resilience.
Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
VP, Technology Risk Management
Overview
The Technology Risk and Controls Governance (TR&CG) organization is a business enabler and industry leader in technology and security risk management practices, supported by a multidisciplinary team of technology, security, and risk professionals. Our mission is to exceed stakeholder expectations by providing enhanced visibility into technology risks, strengthening governance practices, and promoting a secure and resilient operational environment.
Within TR&CG, the Technology Controls Governance (TCG) team is responsible for establishing and maturing technology controls, standards, risk management, and control testing practices across Mastercard's technology landscape. The TCG team is seeking a Vice President, Technology Risk Management to drive alignment across enterprise risk management, technology controls, standards, and testing functions within the first and second lines of defense. This individual will help shape and execute a unified multi-year strategy that enables consistent implementation and sustainable risk management practices across first-line technology organizations.
Responsibilities• Lead the planning, execution, reporting, and continuous improvement of Mastercard's technology control testing methodology.• Align strategic and tactical objectives across TR&CG to ensure Technology Risk and Controls Management capabilities can be effectively implemented by any Mastercard organization that manages technology assets.• Develop and maintain risk-based testing methodologies, including testing frequencies, control inventories, testing priorities, and standardized approaches for integration entities such as mergers and acquisitions and directly regulated entities.• Serve as a strategic partner to business owners and stakeholders by providing guidance on control design, remediation, testing prioritization, and technology integration within existing frameworks to reduce risk exposure and strengthen control effectiveness.• Partner with Technology, Risk, Second Line of Defense, and Regulatory teams to continuously enhance testing processes through iterative feedback, align executive expectations, and drive complex cross-functional risk initiatives.• Assist in the standardization of control management practices for integration entities, including mergers and acquisitions and directly regulated entities, while managing variances from business-as-usual processes.• Establish and oversee the integration of controls into emerging technologies while streamlining testing procedures, evidence requirements, sampling methodologies, and scalable business processes.• Drive standardization, automation, AI, analytics, and process optimization to enhance control effectiveness, compliance, auditability, and operational efficiency.• Analyze federated testing priorities, identify opportunities for testing synergies, and develop executive reporting and presentations on program progress.• Provide guidance to First and Second Line of Defense stakeholders to inform testing decisions, connect control testing results to emerging risk themes, and communicate key insights to leadership and governance forums.• Develop and maintain consolidated reporting, metrics, and continuous maturity assessments to measure program effectiveness and support strategic decision-making.• Support audits, regulatory examinations, and assurance activities through clear reporting, documentation, consolidated metrics, and presentations of progress and results for First and Second Line of Defense stakeholders.• Manage collaborative relationships across the organization and influence the ongoing maturity of Mastercard's technology risk and control environment.
Requirements • Degree in technology, information systems management, information security management, security policy or related program desired, but not required.• IT certification(s) preferred such as CISSP/CISA/CRISC.• Familiarity with industry frameworks such as NIST, ISO 27001, SOX, SOC 1/2, PCI, CRI, or UCF preferred. • Strong knowledge of regulatory technology and security risk management expectations.• Expertise in current and emerging technologies and their potential for exploitation.• Bridge governance and execution by developing scalable operating models, processes, and stakeholder relationships that enable business units to effectively implement risk management, controls, and control testing requirements.• Deep knowledge of business unit risk and control frameworks, including the oversight and governance of control testing activities to support compliance, risk management, and continuous improvement.• Familiarity with laws, regulations, policies, and ethics as they relate to cybersecurity and IT management (GDPR, FBA, CBA, CROE, etc.).• Project management expertise, including planning, prioritization, stakeholder management, risk mitigation, resource coordination, and delivery of complex initiatives.• Experience collaborating cross-functionally, geographically to identify and implement best practice assurance/compliance processes.• Systematic problem-solving approach, coupled with strong communication skills and a sense of ownership and drive.• Proven success in navigating multi-national organizations and operating effectively within a diverse multicultural organization.
Mastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact [email protected] and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
In line with Mastercard's total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary and may be eligible for an annual bonus or commissions depending on the role. The base salary offered may vary depending on multiple factors, including but not limited to location, job-related knowledge, skills, and experience. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance); flexible spending account and health savings account; paid leaves (including 16 weeks of new parent leave and up to 20 days of bereavement leave); 80 hours of Paid Sick and Safe Time, 25 days of vacation time and 5 personal days, pro-rated based on date of hire; 10 annual paid U.S. observed holidays; 401k with a best-in-class company match; deferred compensation for eligible roles; fitness reimbursement or on-site fitness facilities; eligibility for tuition reimbursement; and many more. Mastercard benefits for interns generally include: 56 hours of Paid Sick and Safe Time; jury duty leave; and on-site fitness facilities in some locations.
Pay Ranges
O'Fallon, Missouri: $189,000 - $312,000 USD
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
VP, Technology Risk Management
Overview
The Technology Risk and Controls Governance (TR&CG) organization is a business enabler and industry leader in technology and security risk management practices, supported by a multidisciplinary team of technology, security, and risk professionals. Our mission is to exceed stakeholder expectations by providing enhanced visibility into technology risks, strengthening governance practices, and promoting a secure and resilient operational environment.
Within TR&CG, the Technology Controls Governance (TCG) team is responsible for establishing and maturing technology controls, standards, risk management, and control testing practices across Mastercard's technology landscape. The TCG team is seeking a Vice President, Technology Risk Management to drive alignment across enterprise risk management, technology controls, standards, and testing functions within the first and second lines of defense. This individual will help shape and execute a unified multi-year strategy that enables consistent implementation and sustainable risk management practices across first-line technology organizations.
Responsibilities• Lead the planning, execution, reporting, and continuous improvement of Mastercard's technology control testing methodology.• Align strategic and tactical objectives across TR&CG to ensure Technology Risk and Controls Management capabilities can be effectively implemented by any Mastercard organization that manages technology assets.• Develop and maintain risk-based testing methodologies, including testing frequencies, control inventories, testing priorities, and standardized approaches for integration entities such as mergers and acquisitions and directly regulated entities.• Serve as a strategic partner to business owners and stakeholders by providing guidance on control design, remediation, testing prioritization, and technology integration within existing frameworks to reduce risk exposure and strengthen control effectiveness.• Partner with Technology, Risk, Second Line of Defense, and Regulatory teams to continuously enhance testing processes through iterative feedback, align executive expectations, and drive complex cross-functional risk initiatives.• Assist in the standardization of control management practices for integration entities, including mergers and acquisitions and directly regulated entities, while managing variances from business-as-usual processes.• Establish and oversee the integration of controls into emerging technologies while streamlining testing procedures, evidence requirements, sampling methodologies, and scalable business processes.• Drive standardization, automation, AI, analytics, and process optimization to enhance control effectiveness, compliance, auditability, and operational efficiency.• Analyze federated testing priorities, identify opportunities for testing synergies, and develop executive reporting and presentations on program progress.• Provide guidance to First and Second Line of Defense stakeholders to inform testing decisions, connect control testing results to emerging risk themes, and communicate key insights to leadership and governance forums.• Develop and maintain consolidated reporting, metrics, and continuous maturity assessments to measure program effectiveness and support strategic decision-making.• Support audits, regulatory examinations, and assurance activities through clear reporting, documentation, consolidated metrics, and presentations of progress and results for First and Second Line of Defense stakeholders.• Manage collaborative relationships across the organization and influence the ongoing maturity of Mastercard's technology risk and control environment.
Requirements • Degree in technology, information systems management, information security management, security policy or related program desired, but not required.• IT certification(s) preferred such as CISSP/CISA/CRISC.• Familiarity with industry frameworks such as NIST, ISO 27001, SOX, SOC 1/2, PCI, CRI, or UCF preferred. • Strong knowledge of regulatory technology and security risk management expectations.• Expertise in current and emerging technologies and their potential for exploitation.• Bridge governance and execution by developing scalable operating models, processes, and stakeholder relationships that enable business units to effectively implement risk management, controls, and control testing requirements.• Deep knowledge of business unit risk and control frameworks, including the oversight and governance of control testing activities to support compliance, risk management, and continuous improvement.• Familiarity with laws, regulations, policies, and ethics as they relate to cybersecurity and IT management (GDPR, FBA, CBA, CROE, etc.).• Project management expertise, including planning, prioritization, stakeholder management, risk mitigation, resource coordination, and delivery of complex initiatives.• Experience collaborating cross-functionally, geographically to identify and implement best practice assurance/compliance processes.• Systematic problem-solving approach, coupled with strong communication skills and a sense of ownership and drive.• Proven success in navigating multi-national organizations and operating effectively within a diverse multicultural organization.
Mastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact [email protected] and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
- Abide by Mastercard's security policies and practices;
- Ensure the confidentiality and integrity of the information being accessed;
- Report any suspected information security violation or breach, and
- Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
In line with Mastercard's total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary and may be eligible for an annual bonus or commissions depending on the role. The base salary offered may vary depending on multiple factors, including but not limited to location, job-related knowledge, skills, and experience. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance); flexible spending account and health savings account; paid leaves (including 16 weeks of new parent leave and up to 20 days of bereavement leave); 80 hours of Paid Sick and Safe Time, 25 days of vacation time and 5 personal days, pro-rated based on date of hire; 10 annual paid U.S. observed holidays; 401k with a best-in-class company match; deferred compensation for eligible roles; fitness reimbursement or on-site fitness facilities; eligibility for tuition reimbursement; and many more. Mastercard benefits for interns generally include: 56 hours of Paid Sick and Safe Time; jury duty leave; and on-site fitness facilities in some locations.
Pay Ranges
O'Fallon, Missouri: $189,000 - $312,000 USD
Mastercard San Francisco, California, USA Office
123 Mission Street, San Francisco, CA, United States, 94105
Similar Jobs at Mastercard
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Lead go-to-market and commercialization for Property & Casualty Insurance B2B payments across North America. Build pipeline, engage issuers and distribution channels, close deals, partner cross-functionally (Finance, Sales, Marketing, Customer Delivery), track performance in SFDC, create SMB growth strategies and sales enablement materials, and drive organizational alignment to shift legacy payment flows to modern card-based solutions.
Top Skills:
Salesforce (Sfdc)
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Manage localization of Mastercard Digital Enablement Service products across markets with domestic payment schemes or complex regulatory requirements. Assess market needs, identify product gaps, define scalable localization approaches, and coordinate delivery with product, technology, legal, compliance, privacy, and regional teams. Translate business and regulatory requirements into product capabilities, create internal and customer-facing documentation, and represent the product team during certification processes.
Top Skills:
AgileEmvcoGenerative Ai ToolsMastercard Digital Enablement Service (Mdes)Payment TokenizationTransaction ProcessingWaterfall
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Leads Talent Acquisition Operations across North and Latin America, overseeing hiring support from recruitment through Day 1 onboarding. Manages regional teams, workforce capacity, service metrics, governance, stakeholder relationships, escalations, and continuous process improvement. Partners with Talent Acquisition, HR, Legal, Compliance, Technology, and business teams to deliver efficient, consistent hiring services and support executive hiring, audits, acquisitions, and operational initiatives.
Top Skills:
ExcelHr SystemsMS OfficeOutlookWord
What you need to know about the San Francisco Tech Scene
San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.
Key Facts About San Francisco Tech
- Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Google, Apple, Salesforce, Meta
- Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
- Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
- Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

