Lead cryptographic compliance and risk management by assessing key management, encryption, TLS/PKI, and HSM implementations across applications, infrastructure, and cloud. Identify gaps, drive remediation, define governance processes, support audits, and enable PQC readiness while producing metrics and influencing stakeholders to achieve enterprise compliance.
Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Senior Information Security Engineer
Senior Information Security Engineer, Cryptographic Compliance & Risk Management
Location: O'Fallon, MO
Position Overview
Mastercard is seeking a highly motivated security professional to join the Cryptographic Compliance & Risk Management team. This role is responsible for strengthening Mastercard's enterprise cryptographic governance capabilities by assessing compliance with cryptographic and key management requirements, identifying risk, and driving remediation across technology platforms.
As cryptographic threats, regulatory expectations, and technology ecosystems continue to evolve, this position will help ensure that Mastercard's applications, infrastructure, cloud services, and operational environments comply with enterprise security standards and industry regulations. The ideal candidate combines technical security expertise with risk management and governance skills and can effectively influence stakeholders to achieve sustainable compliance outcomes.
Key Responsibilities• Drive execution of Mastercard's Cryptographic Compliance strategy and roadmap.• Assess applications, platforms, infrastructure, cloud environments, and services for adherence to cryptographic and key management standards.• Identify cryptographic compliance gaps, control weaknesses, and security risks, and partner with stakeholders to develop remediation plans.• Provide guidance on risk-based remediation approaches, compensating controls, and modernization strategies for legacy cryptographic implementations.• Support enterprise-wide cryptographic assessments, reviews, audits, and reporting activities.• Collaborate with engineering, architecture, product, infrastructure, and security teams to integrate cryptographic requirements into technology delivery processes.• Define, document, and maintain repeatable governance processes, compliance validation activities, and control assessment methodologies.• Analyze emerging regulatory, industry, and security requirements and translate them into actionable guidance.• Develop metrics, dashboards, and reports that provide visibility into cryptographic compliance posture, risk exposure, and remediation progress.• Support strategic initiatives including:
o Cryptographic inventory and discovery
o Key management modernization
o Cryptographic risk reduction programs
o Post-Quantum Cryptography (PQC) readiness and migration planning• Influence technology teams and business partners to prioritize remediation activities and achieve compliance objectives.
Required Qualifications• Experience in Information Security, Security Risk Management, Governance, Risk and Compliance (GRC), or Security Engineering.• Strong understanding of information security principles, risk management frameworks, and compliance practices.• Knowledge of applied cryptography and key management concepts, including:
o Encryption
o Hashing
o Digital certificates
o TLS/SSL
o PKI
o HSMs
o PKCS#12• Experience assessing security controls and driving remediation in complex enterprise environments.• Familiarity with industry and regulatory standards, including:
o PCI DSS
o FIPS
o ISO 27001/27002
o NIST frameworks and guidance• Ability to evaluate risk, prioritize remediation efforts, and influence technical and non-technical stakeholders.• Strong analytical, problem-solving, verbal, and written communication skills.• Ability to communicate complex security requirements in a clear, business-focused manner.
Preferred Qualifications• Experience leading or supporting cryptographic inventory and discovery programs.• Knowledge of Post-Quantum Cryptography (PQC) initiatives and migration planning.• Cloud security experience across modern cloud platforms and services.• Experience with PKI technologies and certificate lifecycle management.• Experience supporting payment industry or retail HSM environments.• Security metrics, reporting, and risk analytics experience.• Familiarity with modern application architectures and software delivery pipelines.
Core Competencies• Cryptographic Compliance• Key Management Governance• Security Risk Assessment• Security Controls Validation• Regulatory Compliance• Security Engineering• Risk Remediation Management• Stakeholder Engagement and Influence• Security Reporting and Analytics• Enterprise Governance
Relevant Experience
Candidates with experience in one or more of the following areas are encouraged to apply:• Security Governance, Risk, and Compliance (GRC)• Security Engineering• Security Consulting• Technology Risk Management• Cryptographic Compliance Programs• Key Management Programs• Application Security• Infrastructure Security• Cloud Security
Keywords
Cryptography, Key Management, TLS, PKI, HSM, PKCS#12, Compliance, Governance, Risk Assessment, Control Validation, Security Standards, PCI DSS, FIPS, ISO, NIST, PQC, Post Quantum Cryptography, Cryptographic Inventory, Security Engineering, Remediation, Risk Management.
Mastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact [email protected] and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
In line with Mastercard's total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary and may be eligible for an annual bonus or commissions depending on the role. The base salary offered may vary depending on multiple factors, including but not limited to location, job-related knowledge, skills, and experience. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance); flexible spending account and health savings account; paid leaves (including 16 weeks of new parent leave and up to 20 days of bereavement leave); 80 hours of Paid Sick and Safe Time, 25 days of vacation time and 5 personal days, pro-rated based on date of hire; 10 annual paid U.S. observed holidays; 401k with a best-in-class company match; deferred compensation for eligible roles; fitness reimbursement or on-site fitness facilities; eligibility for tuition reimbursement; and many more. Mastercard benefits for interns generally include: 56 hours of Paid Sick and Safe Time; jury duty leave; and on-site fitness facilities in some locations.
Pay Ranges
O'Fallon, Missouri: $115,000 - $184,000 USD
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Senior Information Security Engineer
Senior Information Security Engineer, Cryptographic Compliance & Risk Management
Location: O'Fallon, MO
Position Overview
Mastercard is seeking a highly motivated security professional to join the Cryptographic Compliance & Risk Management team. This role is responsible for strengthening Mastercard's enterprise cryptographic governance capabilities by assessing compliance with cryptographic and key management requirements, identifying risk, and driving remediation across technology platforms.
As cryptographic threats, regulatory expectations, and technology ecosystems continue to evolve, this position will help ensure that Mastercard's applications, infrastructure, cloud services, and operational environments comply with enterprise security standards and industry regulations. The ideal candidate combines technical security expertise with risk management and governance skills and can effectively influence stakeholders to achieve sustainable compliance outcomes.
Key Responsibilities• Drive execution of Mastercard's Cryptographic Compliance strategy and roadmap.• Assess applications, platforms, infrastructure, cloud environments, and services for adherence to cryptographic and key management standards.• Identify cryptographic compliance gaps, control weaknesses, and security risks, and partner with stakeholders to develop remediation plans.• Provide guidance on risk-based remediation approaches, compensating controls, and modernization strategies for legacy cryptographic implementations.• Support enterprise-wide cryptographic assessments, reviews, audits, and reporting activities.• Collaborate with engineering, architecture, product, infrastructure, and security teams to integrate cryptographic requirements into technology delivery processes.• Define, document, and maintain repeatable governance processes, compliance validation activities, and control assessment methodologies.• Analyze emerging regulatory, industry, and security requirements and translate them into actionable guidance.• Develop metrics, dashboards, and reports that provide visibility into cryptographic compliance posture, risk exposure, and remediation progress.• Support strategic initiatives including:
o Cryptographic inventory and discovery
o Key management modernization
o Cryptographic risk reduction programs
o Post-Quantum Cryptography (PQC) readiness and migration planning• Influence technology teams and business partners to prioritize remediation activities and achieve compliance objectives.
Required Qualifications• Experience in Information Security, Security Risk Management, Governance, Risk and Compliance (GRC), or Security Engineering.• Strong understanding of information security principles, risk management frameworks, and compliance practices.• Knowledge of applied cryptography and key management concepts, including:
o Encryption
o Hashing
o Digital certificates
o TLS/SSL
o PKI
o HSMs
o PKCS#12• Experience assessing security controls and driving remediation in complex enterprise environments.• Familiarity with industry and regulatory standards, including:
o PCI DSS
o FIPS
o ISO 27001/27002
o NIST frameworks and guidance• Ability to evaluate risk, prioritize remediation efforts, and influence technical and non-technical stakeholders.• Strong analytical, problem-solving, verbal, and written communication skills.• Ability to communicate complex security requirements in a clear, business-focused manner.
Preferred Qualifications• Experience leading or supporting cryptographic inventory and discovery programs.• Knowledge of Post-Quantum Cryptography (PQC) initiatives and migration planning.• Cloud security experience across modern cloud platforms and services.• Experience with PKI technologies and certificate lifecycle management.• Experience supporting payment industry or retail HSM environments.• Security metrics, reporting, and risk analytics experience.• Familiarity with modern application architectures and software delivery pipelines.
Core Competencies• Cryptographic Compliance• Key Management Governance• Security Risk Assessment• Security Controls Validation• Regulatory Compliance• Security Engineering• Risk Remediation Management• Stakeholder Engagement and Influence• Security Reporting and Analytics• Enterprise Governance
Relevant Experience
Candidates with experience in one or more of the following areas are encouraged to apply:• Security Governance, Risk, and Compliance (GRC)• Security Engineering• Security Consulting• Technology Risk Management• Cryptographic Compliance Programs• Key Management Programs• Application Security• Infrastructure Security• Cloud Security
Keywords
Cryptography, Key Management, TLS, PKI, HSM, PKCS#12, Compliance, Governance, Risk Assessment, Control Validation, Security Standards, PCI DSS, FIPS, ISO, NIST, PQC, Post Quantum Cryptography, Cryptographic Inventory, Security Engineering, Remediation, Risk Management.
Mastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact [email protected] and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
- Abide by Mastercard's security policies and practices;
- Ensure the confidentiality and integrity of the information being accessed;
- Report any suspected information security violation or breach, and
- Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
In line with Mastercard's total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary and may be eligible for an annual bonus or commissions depending on the role. The base salary offered may vary depending on multiple factors, including but not limited to location, job-related knowledge, skills, and experience. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance); flexible spending account and health savings account; paid leaves (including 16 weeks of new parent leave and up to 20 days of bereavement leave); 80 hours of Paid Sick and Safe Time, 25 days of vacation time and 5 personal days, pro-rated based on date of hire; 10 annual paid U.S. observed holidays; 401k with a best-in-class company match; deferred compensation for eligible roles; fitness reimbursement or on-site fitness facilities; eligibility for tuition reimbursement; and many more. Mastercard benefits for interns generally include: 56 hours of Paid Sick and Safe Time; jury duty leave; and on-site fitness facilities in some locations.
Pay Ranges
O'Fallon, Missouri: $115,000 - $184,000 USD
Mastercard New York, New York, USA Office

Mastercard’s NYC Tech Hub unites experts from diverse backgrounds and disciplines, from software development to finance, data architecture to cybersecurity and beyond, to build systems that never fail for a world that never stops.
Similar Jobs at Mastercard
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
The Senior Software Engineer at Mastercard will develop AI-driven solutions using Java and Python, focusing on scalable, high-performance systems while mentoring peers.
Top Skills:
Ai FrameworksDockerHugging FaceJavaPythonPyTorchTensorFlow
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Technical leader driving architecture and delivery of large-scale, cloud-native payment platforms. Leads design for distributed, event-driven systems using Kafka, Kubernetes/PCF, microservices, and CI/CD. Owns performance, reliability, security, observability, and adoption of AI-assisted engineering practices while mentoring engineers and guiding technical governance.
Top Skills:
Agentic AiAi AgentsCapacity PlanningCi/CdDockerJavaKafkaKubernetesLoad TestingMcpMicroservicesObservabilityPcf (Pivotal Cloud Foundry)RagRest ApisSpring Boot
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Lead modernization of Mastercard's global billing platform: define strategy and roadmap, manage product backlogs and write epics/stories, partner with engineering/finance/operations, prioritize and decompose work, drive platform rationalization and migrations, measure performance, manage risks, and mentor a small team of Senior Business Analysts.
Top Skills:
APIsConfluenceIso 20022Iso 8583JIRA
What you need to know about the NYC Tech Scene
As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.
Key Facts About NYC Tech
- Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
- Key Industries: Artificial intelligence, Fintech
- Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
- Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory


