Lead Information Security Engineer

  • Arlington, VA
  • Posted 21 days ago | Updated 1 day ago

Overview

On Site
USD 159,000.00 - 254,000.00 per year
Full Time

Skills

SAFE
Data
Finance
Innovation
Customer experience
Analytical skill
Positive attitude
User experience
Test plans
Microsoft Windows
Microsoft
SaaS
Project documentation
Documentation
Business requirements
Strategy
Regulatory Compliance
Design
Windows PowerShell
Microsoft Azure
Active Directory
IDP
SAML
OAuth
Multi-factor authentication
SSO
Streaming
Thought leadership
Partnership
Leadership
Collaboration
Authentication
Management
Identity management
Cloud computing
Metrics
Auditing
Security controls
Governance
Communication
CISSP
Law
Recruiting
Policies
Reporting
Information security
Insurance
Life insurance

Job Details

Our Purpose

We work to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments and businesses realize their greatest potential. Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. We cultivate a culture of inclusion for all employees that respects their individual strengths, views, and experiences. We believe that our differences enable us to be a better team - one that makes better decisions, drives innovation and delivers better business results.

Title and Summary

Lead Information Security Engineer

The Modern Access team is looking for a Lead Identity Engineer to drive our move to the cloud and modernize authentication for the Enterprise. The ideal candidate is passionate about the customer experience journey, highly motivated, intellectually curious, analytical, and possesses an entrepreneurial mindset. You must be a team player with a positive attitude who is enthusiastic about bringing a vision of the future to life.

In this role, you will:

You will envision, design and lead how Mastercard will modernize authentication throughout the Enterprise, from clients to applications.

You will work with various organizations within Mastercard to gather and document requirements to establish a cloud identity provider, taking advantage of various features to improve the security and user experience of authenticating to cloud resources.

Lead project teams to implement new identity-related technology across the enterprise.

You will improve procedures and feature sets on how applications, both first and third-party, utilize Azure Active Directory as an IDP.

You will create and maintain documentation on how to securely consume Azure Active Directory as an IDP.

You will work with your team to create test plans and execute them for our authentication services, to include conditional access policies, the use of Azure MFA, and Windows Hello for Business.

You will test, implement, and configure Conditional Access Policies within Azure AD to meet business and security needs.

You will test, implement, and configure policies within a Cloud Access Security Broker like Microsoft's Cloud Application Security tool and Zscaler to meet business and security needs.

Be responsible for reviewing all project documentation, including maintaining technical documents and business requirements.

Raise opportunities for improvement to senior consulting and provides technical guidance for junior resources.

Define processes and drives strategy execution.

Be responsible for understanding security policies and industry best practices & compliance.

As SME in IAM, you will train and coach other team members.

All About You

The ideal candidate for this position should have:

An appreciation and clear mission for how users interact with Mastercard's cloud identity provider, focusing on the customer journey and balancing security with a user-friendly design.

Intermediate skills in PowerShell

Advance skills in Azure Active Directory or another IDP where an admin can configure conditions in which a user can authenticate and how they authenticate.

Advance knowledge of authentication methodologies (such as Single Sign On) and protocols, to include SAML, OAUTH 2.0, multi-factor authentication methods and conditional access policies.

Advance understanding of authentication mechanisms for applications and their use of secrets and certificates, including Passworless authentication with WHfB, FIDO2 and Apple platform SSO.

The ability to develop project plans for somewhat complex initiatives for streamlined execution, prioritizing various work streams and customer needs.

IT experience with demonstrated thought-leadership and cross-functional influence and partnership demonstrated by a successful track record of enabling business through these technical decisions

Able to lead project teams, collaborate with business partners, vendor/ consulting organizations and peer level professionals from other IT disciplines

Information Security experience including risk identification with options and compensating controls to remediate.

Successful track record in identifying ways to move modern authentication forward to keep up with the ever-changing technology & security landscape.

Experience initiating and managing improvement in Identity and Access Management for the cloud by leveraging process metrics and customer feedback.

Experience in auditing security controls, governance, and softer communication skills.

Advance understanding of security concepts and their application. This can be evidenced through certifications such CISSP.

Mastercard is an inclusive equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.

Corporate Security Responsibility

All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:

  • Abide by Mastercard's security policies and practices;
  • Ensure the confidentiality and integrity of the information being accessed;
  • Report any suspected information security violation or breach, and
  • Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.


In line with Mastercard's total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary based on location, experience and other qualifications for the role and may be eligible for an annual bonus or commissions depending on the role. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance), flexible spending account and health savings account, paid leaves (including 16 weeks new parent leave, up to 20 paid days bereavement leave), 10 annual paid sick days, 10 or more annual paid vacation days based on level, 5 personal days, 10 annual paid U.S. observed holidays, 401k with a best-in-class company match, deferred compensation for eligible roles, fitness reimbursement or on-site fitness facilities, eligibility for tuition reimbursement, gender-inclusive benefits and many more.

Pay Ranges

Arlington, Virginia: $159,000 - $254,000 USD
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.