Analyst, Business Analysis (Security Due Diligence)

MasterCard Worldwide

The Business Analyst for Security Due Diligence (SDD) within Global Information Security at MasterCard is responsible for the performance of risk assessments involving internal information systems and vendors. The SDD group is also responsible for the policy exception process and other projects. As a Business Analyst in SDD, you will be responsible for a wide range of tasks, including:

'Perform risk assessments around security risks to the organization. Consult with subject matter experts, as well as persons in the relevant business units that are involved in the issue being assessed.
'Work with appropriate personnel to identify and document compensating controls to mitigate or lower risk exposure.
'Work with business owner and/or vendor to prepare remediation plans to limit impact to the business, yet maintain a secure and compliant environment.
'Analyze all information available to determine accurate risk exposure and document findings.
'Ensure that business owners understand how the discovered security risks impact the business and MasterCard's reputation.
'Support issue resolution, maintain department database, and support department goals and metrics.

Required Skills:
'Results driven: pushes self and others to meet deadlines and creatively address issues to mitigate risks.
'Strong written and verbal communication skills to interface technical issues with non technical personnel, as well as to support executive level escalations.
'Influencing and negotiating skills to build understanding and formulate acceptable remediations and plans.
'Team player, able to assist others and suggest enhancements.
'Broad knowledge of multiple IT disciplines including Windows (Workstation and Server), Unix, Linux, databases (Oracle, Microsoft SQL Server), networking (routers, switches, firewalls, NIDS, DMZs) and protocols (TCP/IP, FTP, Telnet, HTTP, SSH, SNMP, DNS, NFS) to evaluate and disclose security issues.
'Ability to plan, organize and prioritize tasks to complete independently and within established time frames on multiple reviews or projects.
'Detailed oriented, ability to understand Information Security policies and standards, and visualize problem areas in the responses given by application owners and vendors.
'Information Security knowledge/experience a plus

Education:
BS degree in Information Technology, Computer Science, Engineering or equivalent combination of experience and formal education.

RESPOND HERE! Respond immediately by accessing the following
dedicated online response form which will allow you to cut and paste your
resume. This form will go directly and immediately to the
hiring authority for this position. Access the online response form at:
http://sh.webhire.com/servlet/resp/rf?jobid=2405153&boardid=749
Company:
  MasterCard International
Location:
  63366
Job Category:
  IT/Software Development
Career Level:
  Experienced (Non-Manager)
Company:
  MasterCard International
Reference Code:
  mast-00015218