USNLX Diversity Jobs

USNLX Diversity Careers

Job Information

Mastercard Lead Information Security Engineer, Ekata (IDS1029) in Seattle, Washington

Our Purpose

We work to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments and businesses realize their greatest potential. Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. We cultivate a culture of inclusion (https://www.mastercard.us/en-us/vision/who-we-are/diversity-inclusion.html) for all employees that respects their individual strengths, views, and experiences. We believe that our differences enable us to be a better team – one that makes better decisions, drives innovation and delivers better business results.

Title and Summary

Lead Information Security Engineer, Ekata (IDS1029)

Job Description

To support our continued growth and success, we are seeking a Lead Information Security Engineer to assist in all operational aspects of our security program. The ideal candidate will drive several important components of our Information Security Program: vulnerability assessment and penetration testing, SDLC initiatives and application security, software security controls deployment and operation (WAF, vulnerability scanners, container scanners, static code analysis engines). If you are looking for a challenge that will allow you to collaborate within dynamic teams and work in a fast-paced environment, this position is for you.

Responsibilities:

· Collaborate with technical and business stakeholders advising on our security standards, policies and industry trends to help the business and customers succeed. Provide technical guidance as part of product and engineering design review sessions.

· Develop and build strong relationships to share knowledge and influence security objectives while being inclusive to all stake holders.

· Improve and maintain security services, focused on review efficiency, standards definition, and change management correctness.

· Maintain operational security posture through incident management, vulnerability management, key management, identity, and access management, etc.

· Implement, build and support a strong vulnerability program that meets business standards and objectives while maintaining an agile working environment. Build and automate vulnerability reporting systems to deliver actionable and data-driven reports on a regular basis.

· Perform various security service functions including internal vulnerability scans, user access review, configuration and hardening validation and automation of many of these tasks within our SIEM.

· Document risk and mitigation controls, including policy/procedure updates.

· Participate in penetration tests, audits, and assessments; provide operational and technical support, as appropriate.

· Analyze established operational security controls and procedures and recommend improvements.

· Evaluate and recommend appropriate tools for supporting the security operations function.

· Respond to security incidents, manage the process, and escalate as required.

· Participate in security on-call rotation.

Preference will be given to candidates with working experience in the following areas:

· Extensive Linux and Windows administration and troubleshooting experience.

· Strong familiarity with networking protocols and an ability to dig deep into the stack to identify and troubleshoot common issues.

· Extensive understanding of PKI infrastructure. An ability to guide and mentor cross-team members regarding best practice to ensure our systems meet the most stringent guidelines.

· HSM  for example Luna 7 or related appliances.

· Experience building and maintaining vulnerability management systems solutions across development and image publication systems. For example, Github, Bitbucket, Artifactory, Jenkins or related tools.

· Splunk and Rsyslog filtering.

· Hashicorp Vault as it pertains to secret and PKI management.

· SIEMs like Qradar/Splunk ES/LogRhythm  or related technologies

What you bring:

· Expertise with administration and guidance of the above and related technologies.

· Bachelor's Degree or equivalent experience/certification

· Windows and Linux/UNIX administration experience

Mastercard is an inclusive equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact reasonable_accommodation@mastercard.com and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.

Corporate Security Responsibility

All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:

  • Abide by Mastercard’s security policies and practices;

  • Ensure the confidentiality and integrity of the information being accessed;

  • Report any suspected information security violation or breach, and

  • Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.

In line with Mastercard’s total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary based on location, experience and other qualifications for the role and may be eligible for an annual bonus or commissions depending on the role. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance), flexible spending account and health savings account, paid leaves (including 16 weeks new parent leave, up to 20 paid days bereavement leave), 10 annual paid sick days, 10 or more annual paid vacation days based on level, 5 personal days, 10 annual paid U.S. observed holidays, 401k with a best-in-class company match, deferred compensation for eligible roles, fitness reimbursement or on-site fitness facilities, eligibility for tuition reimbursement, gender-inclusive benefits and many more.

Pay Ranges

Seattle, Washington: $159,000 - $254,000 USD

DirectEmployers