Mastercard is looking for Vice President, Software Supply Chain Security (O’Fallon) in O'Fallon, MO.
This local job opportunity with ID 3770127733 is live since 2026-08-01 10:50:39.
Title and Summary Vice President, Software Supply Chain Security Overview The Network Engineering Services team is looking for a Vice President of Software Supply Chain Security. The VP is a senior leader responsible for protecting the integrity, provenance, and trustworthiness of all software that powers the company’s global payments ecosystem. This role ensures end‑to‑end security across internal development, third‑party software, CI/CD pipelines, cloud workloads, vendor integrations, and payment processing platforms that require the highest levels of reliability, compliance, and resiliency. Role Define the Software Supply Chain Security Strategy aligned to the company’s global payments mission, regulatory obligations, and risk appetite. Build and lead high‑performing global DevSecOps, platform engineering, and security automation teams. Architect security for CI/CD pipelines, infrastructure‑as‑code frameworks, and automation platforms. Embed security controls into development workflows, including SAST/DAST, SBOM, dependency scanning, secrets management, to eliminate preventable exposure. Establish governance for software bill of materials (SBOM), artifact integrity, code provenance, and policy‑as‑code guardrails. Promote a secure‑by‑default engineering culture with paved roads for secure component consumption, signing, building, and deployment. Partner with Vulnerability Management on strategy and outcomes for end‑to‑end detection, triage, risk acceptance, remediation, validation and overall exposure management. Partner with DevOps on cloud strategy and operations (AWS, Azure, GCP, or hybrid), ensuring resilient, scalable, and secure infrastructure. Partner with Legal, Third‑Party Risk Management (TPRM), and Procurement to enforce contractual obligations for secure development, reporting, incident notification, and replace/patch SLAs. All About You Demonstrated effectiveness leading Security, Platform/DevOps, or Software Engineering teams. Proven track record of implementing software supply chain controls across complex, multicloud and hybrid environments. Demonstrated ability to balance regulatory, security, and developer experience requirements at enterprise scale. Deep expertise in CI/CD, artifact registries, Kubernetes/container security, cryptographic signing, and OSS governance. Strong knowledge of SLSA, NIST SSDF, OWASP SCVS/SCVST, ISO 27001/27036, and regulatory frameworks. Hands‑on familiarity with SAST/DAST/IAST/SCA, secrets and dependency management, API security, and runtime protections. Strong stakeholder management and executive communication skills; proven record influencing Product and Engineering leaders. NICE Framework references National Initiative for Cybersecurity Education (NICE) competency proficiency levels of limited in leadership, limited to developing in operational and professional, and developing to proficient in technical. This Mastercard role shares KSAs with related NICE work roles. OV-SPP-002, OPM751, Cyber Policy and Strategy Planner. OV-EXL-001, OPM901, Executive Cyber Leadership. OV-MGT-001, OPM722, Information Systems Security Manager. Corporate Security Responsibility Abide by Mastercard’s security policies and practices. Ensure the confidentiality and integrity of the information being accessed. Report any suspected information security violation or breach. Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines. EEO Statement Mastercard is a merit‑based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disability or veteran status, or any other characteristic protected by law. Benefits Benefits include insurance (medical, prescription drug, dental, vision, disability, life insurance), flexible spending and health savings accounts, paid leaves (including 16 weeks new parent leave, up to 20 days bereavement leave), 80 hours of Paid Sick and Safe Time, 25 days of vacation, 5 personal days, 401k with a best‑in‑class company match, debt compensation for eligible roles, fitness reimbursement or on‑site facilities, tuition reimbursement, and more. Pay Ranges O’Fallon, Missouri: $212,000 – $339,000 USD. J-18808-Ljbffr5c143e31-5e48-4549-b638-05792d185386
read more