> Markdown version of [/jobs/ext/2474103-certification-and-assurance-senior-security-technology-risk-analyst](https://www.wearedevelopers.com/jobs/ext/2474103-certification-and-assurance-senior-security-technology-risk-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Certification and Assurance - Senior Security/Technology Risk Analyst - **Company:** MasterCard - **Location:** Greater London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Access, Microsoft Word, Microsoft Excel, Cyber Security, Document Management Systems, Microsoft Office, PCI Data Security Standards, Microsoft PowerPoint, Information Technology Security Auditing, IT General Controls (ITGC), Information Technology - **Published:** August 12, 2026 - **Apply:** https://dejobs.org/x/x/8E7638D1751A4B94B0EE295D46D60889/job/ ## About the Role The role requires an understanding of security and technology controls and frameworks, including working with a variety of standards, e.g. ISO27001, ISO22301, PCI DSS, PCI PIN, Swift, ISAE3000, etc. The applicant must have experience with at least one security standard and a proven ability to analyse or implement information security controls to ensure their design, implementation and operating effectiveness meet the requirements of the standard., * Experience of conducting security related audits/reviews. * Knowledge and experience of all areas of security. * Experience in control testing or assurance within security in a regulated environment. * Experience operating good practice security audit management and assurance processes. * Good investigative and analytical experience (e.g. enquiry, scanning, analysis, interviewing, testing), problem-solving, and decision-making skills. * Experience of working with control frameworks and standards (e.g. ISO27001, NIST, CRI, or PCI-DSS). * Ability to assess control design and operating effectiveness in complex environments and to identify control gaps and improvement opportunities. * Good communication and stakeholder engagement skills. Qualifications: * Professional certifications such as CISA, CISM, CISSP, PCI SSC ISA, CRISC, or equivalent is desirable. Preferred Skills & Attributes: * Bachelor's degree in Computer Science, Cyber Security, Information Technology, or a related field. * Good Knowledge of security controls and IT general controls across a variety of platforms and environments. * Knowledge of security related control frameworks and standards. * Proficiency in Microsoft Office Suite (MS Word, MS Excel, MS Access and MS PowerPoint) * Strong organisational skills with the ability to prioritise and manage multiple tasks. * Self-starter with a continuous improvement mindset. and a collaborative approach. ## Description The Vocalink Control Office function is seeking a Senior Technology Risk Analyst with Information Security knowledge and experience to support the Certification and Assurance team within Vocalink Limited. The role will be responsible for supporting Certifications, Certification Audits, and Assurance activities to support the retention of Vocalink Limited's certifications and the delivery of assurance requirements including conducting control testing., * Certification and Assurance Responsibilities * Support the preparation for annual certification audits. * Support the assessment and validation of controls and processes against a variety of security standards and obligations. * Assist in managing certifications (e.g., ISO27001, PCI DSS) and assurance activities (e.g., ISAE3000). * Evaluate compliance with internal policies, standards, regulatory requirements, and customer obligations. * Prepare clear and accurate control testing documentation, including test procedures, results, and supporting evidence. * Support periodic testing of controls in line with a Control Testing Methodology. * Timely collection of control testing evidence from relevant Control Owners to support scheduled testing activities. * Identify and document control deficiencies, ensuring timely escalation to the Manager and support remediation follow-up activities. Team Leadership, Collaboration and Stakeholder Engagement: * Support the team Director in delivering the Certification and Assurance plan. * Maintain close working relationships with Control and Process Owners and Operators to operate certificate maintenance and assurance activities efficiently and effectively. * Work closely with 1st Line teams to obtain evidence, clarify processes, and ensure accurate testing outcomes. * Liaise with 2nd Line Security partners and Internal Audit as directed, ensuring transparency and alignment with control testing activities. * Contribute to the preparation of management information, dashboards, and thematic analysis for governance forums. * Support control owners by providing observations on control effectiveness and contributing to discussions on remediation approaches. Governance and Continuous Improvement: * Support the development of certification management, assurance activities and control testing processes, standards, tools, and methodologies. * Adhere to established control testing standards, procedures, and documentation requirements. * Provide input on opportunities to streamline testing activities, improve efficiency, and enhance the consistency of outcomes. * Contribute to the maturity of the 3 Lines of Defence model and promote a culture of proactive risk management. * Stay informed on emerging risks, regulatory changes, certification changes and industry best practices with a focus on cybersecurity risks., All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must: * Abide by Mastercard's security policies and practices; * Ensure the confidentiality and integrity of the information being accessed; * Report any suspected information security violation or breach, and * Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [In-depth .NET Azure Functions: Isolated mode, performance and durable AI agents](https://www.wearedevelopers.com/videos/100207-in-depth-net-azure-functions-isolated-mode-performance-and-durable-ai-agents) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Developing the Rich Text Editor for DeepL.com](https://www.wearedevelopers.com/videos/1172-developing-the-rich-text-editor-for-deepl-com) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)