Principal, Technology Risk Analyst

MastercardApplyPublished 21 hours agoFirst seen 6 hours ago
Apply

Our Purpose

Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.

Title and Summary

Principal, Technology Risk AnalystThis role is responsible for advancing Mastercard’s risk, controls and compliance capabilities across the Payment Networks Core technology environment. As a Principal-level individual contributor, you will drive the design, implementation, and continuous improvement of risk and control practices that are deeply embedded in technology solutions and the product lifecycle. You will serve as a thought leader and educator, enabling engineering and operational teams to build resilient, compliant systems through effective control design and risk-informed decision-making.

You will leverage deep expertise in technology risk, controls, and compliance together with operational and engineering experience to assess complex technology environments, identify control requirements, evaluate control design, and drive effective control testing and remediation activities. Your work will ensure risk and control strategies are measurable, scalable, and aligned with Mastercard's enterprise risk framework.

Key Responsibilities
Analyze end-to-end business processes, system architectures, transaction processing flows, and technology environments across Payment Networks Core technologies to identify operational, security, compliance, and technology risks and determine appropriate control strategies.
Partner with engineering, product, and operational teams to identify control requirements, assess control coverage, evaluate control design, and provide effective challenge to strengthen preventive, detective, and corrective controls.
Develop and execute risk-based control testing strategies to assess control design and operating effectiveness, identify deficiencies, evaluate remediation plans, and improve overall control maturity and effectiveness.
Serve as a trusted advisor to engineering, product, and operational teams by translating risk, regulatory, and compliance requirements into practical, scalable, and sustainable control solutions.
Drive enhancements to risk and control methodologies, governance practices, monitoring capabilities, and control frameworks to improve risk visibility, control effectiveness, and operational resilience.
Leverage data analytics, dashboards, and reporting tools to monitor control health, identify emerging risk trends, communicate risk posture, and provide actionable insights to stakeholders and senior leadership.
Independently lead complex risk and controls initiatives, translating broad business, technology, and regulatory objectives into actionable assessments, testing programs, remediation plans, and strategic recommendations while influencing stakeholders across engineering, product, compliance, and risk functions.

All About You
Deep experience independently analyzing complex technology ecosystems, system architectures, and end-to-end processing flows to identify operational, security, compliance, and technology risks and evaluate the effectiveness of existing control environments.
Skilled in conducting risk assessments, identifying control requirements, evaluating and challenging control design, developing and executing control testing approaches, and assessing design and operating effectiveness to drive remediation of control gaps and strengthen risk management outcomes.
Deep understanding of IT risk and control frameworks (e.g., NIST, ISO 27001, SOC 1, SOC 2, PCI-DSS) and experience applying them in complex, distributed environments.
Hands-on experience with system design, architecture, or engineering operations, enabling effective partnership with engineering and product teams to integrate risk and control requirements into technology solutions throughout the development and operational lifecycle.
Demonstrated ability to educate and influence technical and non-technical stakeholders on risk and compliance best practices.
Skilled in data analysis, dashboarding, and reporting tools to drive transparency and accountability.
Proven ability to operate independently in ambiguous environments, translating broad business, technology, or regulatory objectives into actionable assessments, control strategies, testing programs, and remediation plans while providing effective challenge and consulting to stakeholders.
Comfortable navigating large-scale, cross-functional environments, balancing technical depth with business impact to drive strategic outcomes.Mastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact reasonable_accommodation@mastercard.com and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.

Corporate Security Responsibility


All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:

  • Abide by Mastercard’s security policies and practices;

  • Ensure the confidentiality and integrity of the information being accessed;

  • Report any suspected information security violation or breach, and

  • Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.

In line with Mastercard’s total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary and may be eligible for an annual bonus or commissions depending on the role. The base salary offered may vary depending on multiple factors, including but not limited to location, job-related knowledge, skills, and experience. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance); flexible spending account and health savings account; paid leaves (including 16 weeks of new parent leave and up to 20 days of bereavement leave); 80 hours of Paid Sick and Safe Time, 25 days of vacation time and 5 personal days, pro-rated based on date of hire; 10 annual paid U.S. observed holidays; 401k with a best-in-class company match; deferred compensation for eligible roles; fitness reimbursement or on-site fitness facilities; eligibility for tuition reimbursement; and many more. Mastercard benefits for interns generally include: 56 hours of Paid Sick and Safe Time; jury duty leave; and on-site fitness facilities in some locations.

Pay Ranges

O'Fallon, Missouri: $142,000 - $234,000 USD