Mastercard logo
Mastercard

Founded in 1966, Mastercard is a worldwide transaction, payment-processing, and consulting company best known for its line of personal and business credit cards. As an employer, Ma

Information Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteEntry LevelTeam 38,800Since 1966

Location

Mexico

Posted

6 days ago

Salary

0

Seniority

Entry Level

English

Job Description

Information Security Engineer

Mastercard

Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential. Title and Summary Information Security Engineer Job Description Summary Mission First, People Always As Corporate Security, we are responsible for keeping Mastercard safe and secure from cyber and physical threats, and it is our people on the frontlines who make this happen every day. By taking care of our people, their wellbeing, and career development, we provide them the necessary tools and environment to ensure the success of our mission. Overview The Cloud Security team is looking for an Information Security Engineer II to join our team to support the design and implementation of cloud native and cloud agnostic security solutions in support of Mastercard's cloud security strategy. This position will focus on enabling business opportunities by ensuring the secure deployment of Mastercard applications and services. The ideal candidate is passionate about cybersecurity policies and governance, highly motivated, intellectually curious, and analytical. Key Responsibilities In this role, you will:• Perform technology evaluations, supporting business case development, test case definition, and vendor selection based on industry standard criteria.• Support the design, test, and implementation of security solutions to meet security and regulatory requirements for cloud environments.• Support senior cloud security engineers and development and operational teams to securely design applications and services following industry best practices.• Cultivate and maintain working relationships with variety of internal stakeholders, including business owners, end-users, customers, project managers, engineers, and leaders.• Demonstrate a working knowledge of information security principles, theories, and concepts.• Support security analysis of application architectures and cloud services. All about you:• 1-3 years of experience, ideally with exposure to AWS and/or Azure environments.• Strong understanding of information security (cybersecurity) fundamentals, risk management, and data privacy - especially in fintech.• Familiarity with both the capabilities and limitations of cybersecurity as it relates to cloud-native and multi-cloud applications and infrastructure.• In-depth knowledge of networking, firewalls, and application security principles.• Strong understanding of identity management, user authentication, and authorization.• Ability to work independently, showing initiative and autonomy in managing projects and tasks. NICE Framework References Mastercard Corporate Security Roles have been aligned with the NICE framework (National Initiative for Cybersecurity Education). For this role the NICE Work Roles most closely aligned are:• Cybersecurity Architecture• Secure Systems Development• Security Control Assessment• Systems Authorization• Systems Security Management Corporate Security Responsibility Every person working for, or on behalf of, Mastercard is responsible for information security. All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and therefore, it is expected that the successful candidate for this position must: • Abide by Mastercard's security policies and practices.• Ensure the confidentiality and integrity of the information being accessed.• Report any suspected information security violation or breach, and• Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines. Corporate Security Responsibility All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must: - Abide by Mastercard's security policies and practices; - Ensure the confidentiality and integrity of the information being accessed; - Report any suspected information security violation or breach, and - Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.

Related Categories

Related Job Pages

More Security Engineer Jobs

InComm Payments logo

Information Security Engineer III

InComm Payments

Quando você pensar na InComm Payments, pense em tecnologia inovadora de pagamentos. Fomos fundados há mais de 30 anos e continuamos a ser pioneiros na indústria de pagamentos (FinTech). Desde a nossa criação estamos em continuo crescimento e somos uma equipe de mais de 3.000 funcionários em mais de 34 países ao redor do mundo. Possuímos mais de 400 patentes técnicas globais e uma rede que inclui mais de 525.000 pontos de distribuição no varejo que apontam para nossa experiência no setor. A InComm Payments está altamente focada em nosso pessoal e em seu crescimento, e trabalhamos duro para tornar a sua carreira significativa e gratificante. Valorizamos a inovação, a qualidade, a paixão, a integridade e a responsabilidade em tudo o que fazemos e procuramos pessoas excelentes para se juntarem à nossa equipa à medida que avançamos em direção a um futuro muito brilhante. Antecipamos o desenvolvimento de futuros líderes para nossas equipes no Brasil!

Full TimeRemoteTeam 1,001-5,000

Role Description As an Information Security Engineer III, you will work on securing applications across InComm Payments by integrating security tools into CI/CD pipelines, conducting threat modeling, and supporting incident response. The role involves: - Integrating SAST tooling into CI/CD pipelines, ensuring compatibility and efficient scanning within development workflows. - Providing tailored SAST integration support for development teams at varying maturity levels with diverse toolsets and security requirements. - Analyzing application logs for anomalous patterns, communicating findings to leadership, and persuading them to take appropriate action. - Participating in on-call rotation in support of WAF incidents. - Validating security vulnerabilities identified by automated tools and fine-tuning configurations to minimize false positives and reduce noise. - Developing threat models with development teams to help expose risks in their deliverables. - Conducting regular assessments of security configurations and controls within Azure, AWS, and OCI environments. - Assisting in investigating security incidents with CSOC and implementing corrective actions. - Participating in application design and architectural reviews. - Facilitating activities such as blue/red team events and bug bounty programs. - Leading prioritization discussions to gain traction on important security issues. - Acting as a liaison with 3rd parties performing vulnerability scans and penetration testing to validate findings and inform priorities and strategies for remediation. - Drafting, evaluating, and monitoring compliance with application and development security standards. - Ensuring development teams are validating for OWASP Top 10 and performing industry-leading application security practices. Qualifications - 5+ years of application security experience. - Strong background with CI/CD processes and associated tooling, such as Jenkins, GitHub Actions, Azure Pipelines, or similar. - Strong scripting experience – PowerShell, Python, etc. - Extensive experience with SAST & DAST application scanning tools and knowledge of OWASP methodologies. - Application security experience with high-level programming languages (e.g., Java, C, C++, C#, VB, .NET, ASP.NET, ASP, PHP, J2EE, JSP). - Experience with Container technologies – Docker, Docker Swarm, Kubernetes. - Experience in cloud security, specifically with Azure, AWS, and OCI, preferably in the Fintech or related sectors and multi-cloud environments. - Knowledge of Web Application Firewalls (WAF). - Experience with Identity and Access Management security solutions and protocols (e.g., SAML, OpenID, and OAuth). - Experience with performing web, API, and mobile manual penetration testing; preparing reports to document findings; and presenting the report to development teams. - Familiarity with regulatory controls and industry best practices such as HIPAA, PCI, HiTrust, NIST etc. - Communication skills to create documentation, videos, and conduct training classes. - Ability to manage multiple tasks simultaneously and meet established deadlines. - Ability to collaborate with IT teams on security-related tasks and projects. - Ability to work productively while remote and communicate effectively in a virtual team environment. - Ability to stay current with new technology. Company Description InComm Payments is a pioneer in the payment (FinTech) industry, founded over 30 years ago. We have grown to a team of over 3,000 employees in 35 countries, owning over 400 global technical patents and a network that includes over 525,000 points of retail distribution. We work with the most recognized and valued brands in the world and are highly focused on our people and their growth, valuing innovation, quality, passion, integrity, and responsibility.

Australia
3Cloud logo

Principal Architect – Security

3Cloud

Delivering the ultimate Microsoft Azure experience.

Full TimeRemoteTeam 501-1,000H1B No Sponsor

• Lead and deliver complex security engagements centered on Azure Security, Identity & Access Management (IAM), and Microsoft Purview / AI Governance. • Serve as a principal-level architect, thought leader, and trusted advisor who shapes secure cloud, data, and AI governance strategies for enterprise clients while remaining deeply engaged in delivery. • Provide senior technical leadership across multiple strategic client engagements. Lead executive and architectural design sessions, define target-state security architectures, and guide delivery teams through implementation with a strong focus on quality, scalability, and measurable business outcomes. • Act as a trusted advisor to client stakeholders, including security, infrastructure, data, and executive leaders. Shape security roadmaps, advise on operating models and governance, and bring forward innovative perspectives on Azure security, identity modernization, data protection, and AI governance. • Remain hands-on in delivery while overseeing complex programs from strategy through implementation. Partner with delivery leadership to align milestones, manage technical risk, remove blockers, and ensure successful outcomes across architecture, implementation, and adoption phases. • Design and lead implementation of enterprise security architectures across Azure and hybrid environments, including Microsoft Entra ID, Conditional Access, Identity Protection, Privileged Identity Management (PIM), role-based access control, Zero Trust controls, workload protection, and security monitoring patterns aligned to least privilege and strong governance. • Lead engagements focused on Microsoft Purview, information protection, data security posture management, data loss prevention, compliance, and governance for Copilot, AI applications, and AI agents. Help clients establish secure and compliant approaches for data access, policy enforcement, monitoring, lifecycle management, and responsible AI enablement. • Contribute approximately 25-30% of role capacity to sales enablement and solution development activities. Partner with account teams and solution leaders to shape opportunities, lead discovery conversations, develop solution approaches, support estimates and statements of work, contribute to proposals, and articulate differentiated value in client pursuits. • Help scale the security practice through reusable assets, reference architectures, accelerators, and delivery standards. Mentor architects and engineers, coach teams on emerging Microsoft security capabilities, and strengthen organizational readiness across Azure security, identity, data governance, and AI security disciplines.

United States
$158.2K - $227.3K / year
Intetics logo

Incident Editorial Specialist

Intetics

Where software concepts come alive™

Full TimeRemoteTeam 501-1,000Since 1995H1B No Sponsor

Role Description Intetics Inc., глобальна технологічна компанія, що надає послуги з розробки програмного забезпечення на замовлення, створення розподілених команд, оцінки якості програмних продуктів та all-things-digital рішень, шукає Incident Editorial Specialist до нашої команди. Приєднуйтесь до нашої редакційної команди нічної зміни та працюйте з редагуванням дорожніх інцидентів у реальному часі для глобальної картографічної платформи. Попередній досвід не потрібен - ми надаємо повне навчання. Це чудова можливість розпочати кар’єру в IT та отримати досвід роботи на міжнародних проєктах. Це повна зайнятість у віддаленому форматі. Ви працюватимете з даними англійською мовою, застосовуючи чіткі правила та зберігаючи концентрацію під час нічних змін. Qualifications - Рівень англійської від B1+ - Висока уважність до деталей, особливо в умовах обмеженого часу - Впевнена робота з кількома вкладками/вікнами, швидкий набір тексту - Пунктуальність, зосередженість і надійність - критично важливі для нічної роботи

Ukraine
Job Closed
DeepSeas logo

Offensive Security Supervisor

DeepSeas

First & only Managed Detection & Response solution covering all attack surfaces for enterprises & the mid-market.

Full TimeRemoteTeam 201-500Since 30 yearsH1B No Sponsor

• The Offensive Security Supervisor bridges hands-on technical delivery with day-to-day team leadership. • This is a senior individual contributor role does not carry formal people management responsibilities but plays a critical role in keeping the team running smoothly, maintaining quality standards, and developing junior consultants. • Supervisors are expected to remain active technical contributors while serving as the first point of escalation for the team during the Manager's absence or when dealing with engagement-level challenges.

California
Job Closed