About the Role
The 1st Line Security Controls Testing Manager will support the delivery of control testing activities across security control domains within Vocalink Limited (VLL), a critical national infrastructure company. This role is key to embedding a strong control environment by executing tests, identifying gaps, and supporting risk management improvements.
Responsibilities
- Conduct periodic testing of key and non-key controls in line with the Control Testing Methodology.
- Evaluate compliance with internal policies, standards, regulatory requirements, and customer obligations.
- Prepare and review control testing documentation, including test procedures, results, and identified gaps.
- Ensure timely escalation of control deficiencies and support remediation tracking.
- Supervise and mentor junior team members, providing guidance on testing execution and quality assurance.
- Support the Director of Control Testing in delivering the annual testing plan and contributing to team development.
- Engage with 1st Line teams while coordinating closely with 2nd Line Security partners and maintaining effective liaison with Internal Audit.
- Contribute to reporting for governance forums, including dashboards, thematic reviews, and trend analysis.
- Partner with control owners, providing guidance on control effectiveness and remediation.
- Support the development and refinement of control testing standards, tools, and methodologies.
- Contribute to the maturity of the 3 Lines of Defence model and promote a culture of proactive risk management.
- Stay informed on emerging risks, regulatory changes, and industry best practices with a focus on cybersecurity risks.
Requirements
- Experience in control testing, assurance, and risk management within security in a regulated environment.
- Strong investigative and analytical experience (e.g., enquiry, scanning, analysis, interviewing, testing), problem-solving, and decision-making skills.
- Strong understanding of control frameworks and standards (e.g., NIST, CRI, ISO and PCI-DSS).
- Ability to assess control design and operating effectiveness in complex environments and to identify control gaps and improvement opportunities.
- Excellent communication and stakeholder engagement skills.
- All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must: Abide by Mastercard’s security policies and practices; Ensure the confidentiality and integrity of the information being accessed; Report any suspected information security violation or breach, and Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.
Skills
- NIST
- CRI
- ISO
- PCI-DSS
- UNIX
- HP Nonstop
- Windows
- SDLC
- DevOps
- Cloud technologies
- ACL
- Microsoft Office Suite (MS Word, MS Excel, MS Access and MS PowerPoint)
Location
- United Kingdom
Work Type
- Full-time
Experience Level
- Manager
Education Level
- Bachelor’s degree in Computer Science, Cyber Security, Information Technology, or related field is preferred.
- Professional certifications such as CISA, CISM, CISSP, CRISC, ISO 27001 or equivalent is desirable.
About the Company
- Mastercard powers economies and empowers people in 200+ countries and territories worldwide.
- Together with our customers, we’re helping build a sustainable economy where everyone can prosper.
- We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible.
- Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
- Vocalink Limited (VLL) is a Bank of England regulated, Critical National Infrastructure (CNI) company that enables the payments of 90% of salaries, 70% of utility bills, most ATM transactions and every cheque cleared in the UK.
