Information Security Engineer
Mastercard.com
Office
Budapest, Hungary (Ekata)
Full Time
Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title And Summary
Information Security EngineerWe areThe Identity Solutions team is seeking a skilled and experienced Security Engineer. You will play a crucial role to ensure products integrate security requirements during design and throughout the product’s lifecycle. You will work closely with various security teams to provide product engineers with security capabilities and recommendations. You'll mentor and guide technology, product and software development teams, ensuring high-quality outcomes, and play a vital role in shaping our technology and security landscape.What You'll Do:
• Collaborate with software developers, system engineers, and other stakeholders to integrate security controls into the development lifecycle
• Provide input to designs and architectures that include business and regulatory requirements
• Provide guidance on best practices for secure designs
• Guide developers through proper application development during various design phases
• Conduct risk assessments and perform threat modeling to identify potential security vulnerabilities and design weaknesses
• Identify security controls that will address security gaps
• Evaluate and recommend security technologies, tools, and services
• Perform security reviews and audits of system designs and implementations
• Stay updated on industry trends, emerging threats, and best practices in security designs
What you bring:
• Strong communication skills with the ability to collaborate with technical and non-technical stakeholders
• Experience as a Security Design Engineer or in a similar role
• Experience with secure software development methodologies (e.g. OWASP Top 10, CWE/SANS Tops 25, etc.)
• Knowledge of encryption algorithms, authentication protocols, and secure communication protocols
• Strong understanding of network security best practices, security principles and standards, and frameworks (e.g., ISO 27001, NIST Cybersecurity Framework, etc.)
• Understanding of network protocols, architecture, and topology for cloud and on-premises implementations
• Familiarity with cloud security principles and best practices (AWS, GCP, Azure)
• Ability to perform risk assessments and threat modeling to identify security risks and mitigations
• Effective communication and interpersonal skills, with the ability to work collaboratively in a team environment
Additional nice to have:
• Technical experience with scripting/programming languages
• CISSP, CCSP or industry-recognized / vendor-specific security certification(s)
• Previous experience in an audited environment complying with common regulation standards
• Experience with DevSecOps
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
- Abide by Mastercard’s security policies and practices;
- Ensure the confidentiality and integrity of the information being accessed;
- Report any suspected information security violation or breach, and
- Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.
