Director, Technology Risk Management

Posted 2 Days Ago
Be an Early Applicant
Pune, Maharashtra, IND
Hybrid
Expert/Leader
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
We are a global technology company in the payments industry.
The Role
Leads second-line technology risk oversight across Mastercard’s regulated entities, covering cyber, operational resilience, outsourcing, third-party, and technology risks. Develops and embeds the broader risk management framework, challenges risk assessments and remediation, supports regulatory examinations, and presents insights to executives, boards, and governance committees. Partners across technology and control functions, strengthens risk culture, and mentors risk professionals in a global payments environment.
Summary Generated by Built In
Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Director, Technology Risk Management
Director, Technology Risk Management
Lead technology risk oversight and help advance the broader MTS Risk Management Framework.
LOCATION: Pune (hybrid)
BUSINESS UNIT: Mastercard Services
FUNCTION: Second Line Risk Management
SHAPE THE FUTURE OF RISK MANAGEMENT AT MASTERCARD
Mastercard Transaction Services (MTS) enables secure, innovative and regulated money movement services globally. As the business grows and evolves, we are seeking an experienced Director, Technology Risk Management to strengthen independent technology risk oversight across our regulated entities and help advance the wider MTS Risk Management Framework.
This is a highly visible leadership role within the second line of defence. Technology risk is the primary focus, spanning technology, cyber, operational resilience, outsourcing and third-party risk. The successful candidate will also contribute across broader risk disciplines, including risk appetite, risk assessments, issue and risk event management, governance, reporting, policy and framework development.
Working with senior leaders across Technology, Engineering, Product, Cyber Security, Compliance, Regulatory Affairs and Legal Entity Management, you will provide credible challenge, translate complex risk matters into clear business insight, and support sound decision-making within a fast-moving global payments environment.
WHAT WILL YOU BE ACCOUNTABLE FOR
Strategic technology risk oversight
-Lead independent second line oversight and challenge of technology, cyber and operational resilience risks across MTS regulated entities.
-Evaluate material technology initiatives, transformation programmes and strategic investments from a risk perspective.
-Provide credible, evidence-based challenge of technology risk assessments, control environments, risk acceptances, control weaknesses and remediation plans.
-Monitor emerging technology and cyber risks, assess their relevance to MTS, and advise senior stakeholders on potential business and regulatory impacts.
-Oversee second line challenge of outsourcing, critical third-party arrangements, technology dependencies and concentration risks.
Broader Risk Management Framework leadership
-Play a leading role in the continued development, implementation and embedding of the MTS Risk Management Framework beyond the technology risk domain.
-Drive enhancements to risk governance, risk appetite, risk assessment, issue management, risk event management, risk acceptance and reporting processes.
-Contribute to the development and maintenance of risk policies, standards, methodologies, procedures and guidance.
-Lead or facilitate enterprise and legal entity risk assessments and support consistent application of the framework across regulated entities.
-Provide oversight and challenge of material non-technology risks, issues, events and remediation activities where required by the broader Risk team agenda.
-Partner with first line stakeholders to improve risk identification, assessment, escalation and management practices while preserving second line independence.
Governance, regulatory and Board engagement
-Prepare and present clear risk insights to executive leadership, governance committees and Boards.
-Lead or support regulatory examinations, supervisory engagements, independent reviews, audits and associated remediation programmes.
-Provide subject matter expertise on regulatory expectations relating to technology, operational resilience and broader risk governance.
-Contribute to strategic risk reporting, risk appetite oversight and escalation of material risk matters.
Leadership and influence
-Build trusted relationships across Technology, Engineering, Product and control functions and influence decisions through clear, practical risk advice.
-Promote a strong risk culture and constructive challenge across MTS.
-Mentor and develop risk professionals and contribute to capability building across the wider Risk Management function.
-Operate effectively across multiple legal entities, jurisdictions and risk domains in a complex global organisation.
WHAT ARE WE LOOKING FOR
Essential experience
-Significant experience in technology risk, cyber risk, operational risk, information security governance, technology controls, IT audit or a related discipline.
-Experience operating at senior level within financial services, payments, banking, fintech or another highly regulated sector.
-Demonstrated ability to provide independent oversight and credible challenge across complex technology environments and change programmes.
-Experience engaging senior executives, governance committees, Boards, regulators, auditors or independent reviewers.
-Proven ability to assess complex risks, identify material themes and translate them into clear, pragmatic recommendations.
-Strong executive communication, stakeholder management and influencing skills.
Desirable experience and knowledge
-Experience designing, implementing, enhancing or embedding an enterprise or legal entity Risk Management Framework.
-Practical experience across broader risk disciplines such as risk appetite, enterprise risk assessments, issue management, risk event management, risk acceptance, policy development and governance reporting.
-Experience working across technology and non-technology risk domains rather than within a single specialist discipline.
-Knowledge of payment systems, money movement platforms, e-money institutions or regulated payment service providers.
-Experience supporting regulatory examinations, supervisory engagements, remediation programmes or regulatory change initiatives.
-Knowledge of operational resilience, business continuity, outsourcing and third-party risk management.
-Experience working across multiple regulated entities or jurisdictions.
Qualifications
-A bachelor's degree in technology, information security, computer science, risk management or a related discipline is preferred. Relevant professional experience will also be considered.
-Professional certifications such as CRISC, CISSP, CISM, CISA, COBIT or ITIL are desirable.
The leadership profile
-Credible technology risk leader with the breadth to contribute to the full Risk Management Framework.
-Independent and appropriately challenging, with a collaborative and solutions-oriented style.
-Comfortable moving between strategic governance, regulatory priorities and detailed risk matters.
-Able to create clarity from complexity and focus stakeholders on material risks and outcomes.
-Committed to high standards of integrity, judgement and second line independence.
WHY JOIN MASTERCARD
-Influence technology risk management across a global, regulated money movement business.
-Help shape the evolution of the broader MTS Risk Management Framework.
-Engage directly with senior leaders, governance forums and regulatory stakeholders.
-Work on complex challenges spanning technology, cyber security, operational resilience, governance and enterprise risk.
-Make a meaningful contribution to the safety, resilience and responsible growth of Mastercard Transaction Services.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
  • Abide by Mastercard's security policies and practices;
  • Ensure the confidentiality and integrity of the information being accessed;
  • Report any suspected information security violation or breach, and
  • Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.

Skills Required

  • Significant experience in technology risk, cyber risk, operational risk, information security governance, technology controls, IT audit, or a related discipline
  • Senior-level experience in financial services, payments, banking, fintech, or another highly regulated sector
  • Experience providing independent oversight and credible challenge across complex technology environments and change programs
  • Experience engaging senior executives, governance committees, boards, regulators, auditors, or independent reviewers
  • Ability to assess complex risks, identify material themes, and translate them into pragmatic recommendations
  • Strong executive communication, stakeholder management, and influencing skills
  • Experience designing, implementing, enhancing, or embedding an enterprise or legal entity risk management framework
  • Experience with risk appetite, enterprise risk assessments, issue management, risk events, risk acceptance, policy development, and governance reporting
  • Experience across technology and non-technology risk domains
  • Knowledge of payment systems, money movement platforms, e-money institutions, or regulated payment service providers
  • Experience supporting regulatory examinations, supervisory engagements, remediation programs, or regulatory change initiatives
  • Knowledge of operational resilience, business continuity, outsourcing, and third-party risk management
  • Experience working across multiple regulated entities or jurisdictions
  • Bachelor’s degree in technology, information security, computer science, risk management, or a related discipline
  • Professional certification such as CRISC, CISSP, CISM, CISA, COBIT, or ITIL

What the Team is Saying

Jenny
Mastercard
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Purchase, NY
38,800 Employees
Year Founded: 1966

What We Do

Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re building a resilient economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.

Why Work With Us

We live the Mastercard Way: creating value in the communities we touch, growing together through the opportunities we see, and moving fast to innovate and scale. Our collaborative culture and our passionate people are the key to what we do, driving meaningful change as one team and connecting everyone to priceless possibilities.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Mastercard Teams

Team
Technology
Team
Cybersecurity and Threat Intelligence
Team
Consulting
Team
AI and Data
About our Teams

Mastercard Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

In our ongoing workplace evolution, we’ve introduced hybrid work, Work-From-Elsewhere Weeks and Meeting-Free Days.

Typical time on-site: 3 days a week
Company Office Image
HQPurchase, NY
Arlington, VA
Company Office Image
Atlanta, GA
Bogotá, CO
Boston, MA
Chicago, IL
Company Office Image
Dublin, Dublin
Gurugram, Gurugram
Company Office Image
London, GB
Company Office Image
Miami, FL
Mumbai, Maharashtra
Company Office Image
New York, NY
Company Office Image
O'Fallon, MO
Company Office Image
Pune, Maharashtra
Ramat Gan, IL
Company Office Image
Saint Leonards, St Leonards
San Francisco, CA
São Paulo, SP
Seattle, WA
Singapore, SG
Company Office Image
Toronto, Ontario
Vancouver, BC
Learn more

Similar Jobs

Mastercard Logo Mastercard

Manager, Transaction Services

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Pune, Maharashtra, IND
38800 Employees

Mastercard Logo Mastercard

Specialist, HR Services

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Pune, Maharashtra, IND
38800 Employees

Mastercard Logo Mastercard

Senior Software Engineer

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Pune, Maharashtra, IND
38800 Employees

Mastercard Logo Mastercard

Software Engineer

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Pune, Maharashtra, IND
38800 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account