Manager, 1st Line Controls Testing, Certification and Assurance

Posted Yesterday
Be an Early Applicant
London, Greater London, England, GBR
Hybrid
Entry level
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
We are a global technology company in the payments industry.
The Role
Manages first-line controls testing, certification audits, assurance activities, and compliance assessments across security frameworks. Evaluates control design and operating effectiveness, identifies gaps, tracks remediation, prepares audit documentation, and coordinates external audits. Supervises junior analysts, supports governance reporting, partners with control owners, and improves assurance methodologies. The role focuses on cybersecurity risk management, regulatory compliance, certification maintenance, and control effectiveness across complex technology environments.
Summary Generated by Built In
Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Manager, 1st Line Controls Testing, Certification and Assurance
Main purpose of the role
The 1st Line Control Office function within Vocalink Limited (VLL) is seeking a Manager to join the Control Testing, Certification and Assurance team.
This role will be responsible for managing Certifications, Certification Audits, and other Assurance activities including conducting control testing to support the retention of VLL's certifications across multiple frameworks and the delivery of assurance obligations.
This position requires a broad understanding of security and technology control frameworks, with hands-on experience across standards such as: ISO 27001, ISO 22301, PCI DSS, PCI PIN, SWIFT CSP, ISAE 3000 etc. The successful candidate must have proven expertise in analysing and assessing control design, implementation and operating effectiveness against at least one of these standards, ensuring compliance and identifying gaps.
The role will also include coordinating and managing external audits to ensure smooth execution, therefore, experience of this is needed.
Key Responsibilities:• Certification and Assurance Responsibilities • Maintain certification and assurance related documentation.• Prepare the organisation for annual certification audits.• Support the assessment and validation of controls and processes against a variety of security standards and obligations. • Support the team in the management of VLL certifications, e.g. ISO27001 and PCI DSS.• Support the team in the management of other assurance activities, e.g. ISAE3000.• Conduct periodic testing of key and non-key controls in line with the Control Testing Methodology.• Evaluate compliance with internal policies, standards, regulatory requirements, and customer obligations.• Prepare and review control testing documentation, including test procedures, results, and identified gaps.• Ensure timely escalation of control deficiencies and support remediation tracking.• Create and quality assure reports and team outputs. • Team Leadership, Collaboration & Stakeholder Engagement• Supervise and mentor junior team members (e.g. Senior Analysts), providing guidance on certification requirements, assurance requirements, testing execution and quality assurance.• Support the Vice President and Director of Certification and Assurance in the development and maintenance of the annual Control Testing, Certification and Assurance plan. • Build and maintain strong partnerships with Control and Process Owners and Operators to ensure efficient and effective execution of certification maintenance and assurance activities.• Contribute to reporting for governance forums, including dashboards, thematic reviews, and trend analysis.• Governance & Continuous Improvement• Support the development and refinement of certification management, assurance/control testing processes, standards, tools, and methodologies.• Contribute to the maturity of the 3 Lines of Defence model and promote a culture of proactive risk management.• Stay informed on emerging risks, regulatory changes, certification changes and industry best practices with a focus on cybersecurity risks.
Experience• Experience of working with security related control frameworks and standards (e.g. ISO27001, NIST, CRI, or PCI-DSS).• Experience of conducting security related audits/reviews and managing/coordinating external audits including certification audits.• Ability to assess control design and operating effectiveness in complex environments and to identify control gaps and improvement opportunities.• Experience of resolving certification and assurance issues.• Knowledge and experience of all areas of security.• Strong investigative and analytical experience (e.g. enquiry, scanning, analysis, interviewing, testing), problem-solving, and decision-making skills.• Experience collaborating cross-functionally to identify and implement good practice security audit management and assurance processes.• Excellent communication and stakeholder engagement skills.
Qualifications• Certifications such as ISO27001 Lead Auditor, CISA, CISM, CISSP, PCI SSC ISA, CRISC, or equivalent is desirable.
Preferred Skills & Attributes• Bachelor's degree in Computer Science, Cyber Security, Information Technology, or a related field.• Good Knowledge of security controls and IT general controls across a variety of technologies and environments.• Proficiency in Microsoft Office Suite (MS Word, MS Excel, MS Access and MS PowerPoint)• Strong organisational skills with the ability to prioritise and manage multiple tasks.• Self-starter with a continuous improvement mindset and a collaborative approach.• Experience creating presentations for business discussions and reporting.• Experience of Risk Management / GRC related technologies and toolsets. • Experience working in cross-functional large projects with dispersed teams.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
  • Abide by Mastercard's security policies and practices;
  • Ensure the confidentiality and integrity of the information being accessed;
  • Report any suspected information security violation or breach, and
  • Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.

Skills Required

  • Experience working with security-related control frameworks and standards such as ISO 27001, NIST, CRI, or PCI DSS
  • Experience conducting security-related audits and reviews
  • Experience managing or coordinating external and certification audits
  • Ability to assess control design and operating effectiveness in complex environments
  • Experience identifying control gaps, improvement opportunities, and resolving certification or assurance issues
  • Knowledge and experience across security domains, including security controls and IT general controls
  • Strong investigative, analytical, problem-solving, and decision-making skills
  • Experience developing security audit management and assurance processes collaboratively across functions
  • Excellent communication and stakeholder engagement skills
  • Certification such as ISO 27001 Lead Auditor, CISA, CISM, CISSP, PCI SSC ISA, CRISC, or equivalent
  • Bachelor's degree in Computer Science, Cyber Security, Information Technology, or a related field
  • Proficiency in Microsoft Word, Excel, Access, and PowerPoint
  • Experience with risk management, GRC technologies, and toolsets
  • Experience working on cross-functional large projects with dispersed teams

What the Team is Saying

Jenny
Mastercard

Mastercard Compensation & Benefits Highlights

  • Retirement Support Retirement plans are presented as best-in-class with a high company match on 401(k) or local equivalents. Career materials and U.S. postings consistently highlight retirement matching as a standout feature.
  • Leave & Time Off Breadth U.S. postings describe generous paid time off including vacation, personal days, holidays, sick/safe time, and additional bereavement leave. A hybrid policy and a limited “work from elsewhere” option further support time away.
  • Parental & Family Support Company pages state a global minimum of 16 weeks of paid new-parent leave across birth, adoption, and foster, plus family-building assistance where permitted. Mental-health resources and caregiving supports are also emphasized.

Mastercard Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Purchase, NY
38,800 Employees
Year Founded: 1966

What We Do

Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re building a resilient economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.

Why Work With Us

We live the Mastercard Way: creating value in the communities we touch, growing together through the opportunities we see, and moving fast to innovate and scale. Our collaborative culture and our passionate people are the key to what we do, driving meaningful change as one team and connecting everyone to priceless possibilities.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Mastercard Teams

Team
Technology
Team
Cybersecurity and Threat Intelligence
Team
Consulting
Team
AI and Data
About our Teams

Mastercard Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

In our ongoing workplace evolution, we’ve introduced hybrid work, Work-From-Elsewhere Weeks and Meeting-Free Days.

Typical time on-site: 3 days a week
Company Office Image
HQPurchase, NY
Arlington, VA
Company Office Image
Atlanta, GA
Bogotá, CO
Boston, MA
Chicago, IL
Company Office Image
Dublin, Dublin
Gurugram, Gurugram
Company Office Image
London, GB
Company Office Image
Miami, FL
Mumbai, Maharashtra
Company Office Image
New York, NY
Company Office Image
O'Fallon, MO
Company Office Image
Pune, Maharashtra
Ramat Gan, IL
Company Office Image
Saint Leonards, St Leonards
San Francisco, CA
São Paulo, SP
Seattle, WA
Singapore, SG
Company Office Image
Toronto, Ontario
Vancouver, BC
Learn more

Similar Jobs

Mastercard Logo Mastercard

Counsel

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
London, Greater London, England, GBR
38800 Employees

Mastercard Logo Mastercard

Vice President, Corporate Development

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
London, Greater London, England, GBR
38800 Employees

Mastercard Logo Mastercard

Vice President, Internal Audit (Senior Leadership Role)

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
London, Greater London, England, GBR
38800 Employees

Mastercard Logo Mastercard

Manager, Product Management - Resiliency Operations (Stand-In & On-Demand Decisioning)

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
London, Greater London, England, GBR
38800 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account