Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Lead AI Security Engineer
Overview
Mastercard is seeking a Lead AI Security Engineer to support a strategic AI engineering team focused on foundation model development and AI use case delivery. This role is responsible for the hands-on implementation of model security, AI product platform security and responsible-AI practices. Testing models for vulnerabilities, building the guardrails, access controls, API security, secure data usage and mitigations recommended by Mastercard's central security and AI governance teams, and ensuring those recommendations are actually built into the platform, not just documented. This is an execution-focused engineering role: Mastercard's dedicated security and governance teams already own policy, advisory guidance, and formal review. This role is the team's technical owner for turning that guidance into working, tested implementation.
Role
In this role, you will be responsible for implementing and maintaining the technical controls, tests, and mitigations that keep the platform's models secure and its AI use responsible in practice. Along with ensuring our developers, data engineers and AI engineers are incorporating security standards into their builds.
Key responsibilities:
Implement the technical recommendations produced by central security and AI governance review teams. Translating advisory guidance into concrete engineering work, and tracking it through to completion.
Test models for security vulnerabilities directly. Running practical assessments for risks such as membership inference, model inversion, data leakage through embeddings or outputs, and adversarial input manipulation.
Build and maintain guardrails and mitigations identified through vulnerability testing or governance review. For example, output filtering, input validation, rate limiting on sensitive queries, or access restrictions tied to specific risk findings.
Implement bias and fairness testing for models and use cases, working from criteria and guidance set by central AI ethics/governance teams
Build technical evidence and test results to support governance and security reviews. Providing concrete, reproducible proof (test results, logs, benchmark outputs) that central governance teams need.
Stay current on emerging model vulnerability research and attack techniques (e.g., new inversion or extraction methods relevant to embeddings and transformer-based models) and proactively test the platform against them.
Partner closely with central security, privacy, and AI governance teams as the team's primary technical point of contact. Understanding their requirements accurately and representing the platform's architecture to them clearly.
Advise engineering peers on secure design choices during development, providing practical, specific input on API, data pipeline, and model-serving designs before they reach formal review.
Support incident response for security or model-vulnerability findings, including reproducing issues, implementing fixes, and verifying remediation.
All About You
Required skills and experience:
Hands-on experience testing ML/AI models for security vulnerabilities. Adversarial robustness testing, membership inference, model inversion, or similar practical red-teaming of models, not just familiarity with the concepts.
Strong applied security engineering skills. Able to build and implement real technical controls (guardrails, filters, access restrictions), not only assess or advise on them.
Experience implementing bias/fairness testing or mitigation for ML models.
Familiarity with the unique security risks of embeddings and foundation models specifically. How they differ from traditional application security risks, and awareness of current research/attack techniques in this space.
Practical experience with access control and audit logging implementation, particularly across distributed or hybrid (cloud and on-premises) environments.
Working knowledge of relevant regulatory context for financial/payment data (e.g., PCI DSS, data protection regulation) sufficient to implement controls correctly.
Software engineering fundamentals. Able to build production-quality tooling and tests, not just one-off scripts or proofs of concept.
Clear, precise communicator, able to work effectively with both hands-on engineering peers and external specialist/advisory teams.
Cloud platform familiarity (AWS preferred; Azure or GCP valuable), particularly within a modern data/AI platform such as Databricks.
Comfortable working from external guidance and translating it into engineering work. Takes direction from specialist governance/security partner teams while retaining the technical judgment to implement it correctly for this platform's specific architecture.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
- Abide by Mastercard's security policies and practices;
- Ensure the confidentiality and integrity of the information being accessed;
- Report any suspected information security violation or breach, and
- Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
Skills Required
- Hands-on experience testing ML or AI models for security vulnerabilities, including adversarial robustness, membership inference, model inversion, or practical model red-teaming
- Applied security engineering experience implementing technical controls such as guardrails, filters, and access restrictions
- Experience implementing bias and fairness testing or mitigation for machine learning models
- Knowledge of security risks affecting embeddings and foundation models, including current attack and vulnerability research
- Practical experience implementing access controls and audit logging in distributed or hybrid cloud and on-premises environments
- Working knowledge of financial and payment data regulations, including PCI DSS and data protection regulations
- Software engineering fundamentals and ability to build production-quality tooling and tests
- Clear communication skills for collaborating with engineering, security, privacy, governance, and advisory teams
- Familiarity with cloud platforms, preferably AWS; Azure or GCP experience is valuable
- Experience with modern data and AI platforms such as Databricks
- Ability to translate external security and governance guidance into platform-specific engineering work
Mastercard Compensation & Benefits Highlights
-
Retirement Support — Retirement plans are highlighted as especially strong, featuring a notably generous company match and added financial-planning resources. Feedback suggests this component stands out as a key strength of the overall package.
-
Parental & Family Support — Parental and family benefits are consistently portrayed as robust, including extended new-parent leave and assistance for fertility, adoption, and surrogacy. Feedback suggests these programs are a signature part of the offering.
-
Leave & Time Off Breadth — Paid time off is described as substantial, with multiple leave types and generous vacation and personal days noted in U.S. materials. Feedback suggests time off is frequently praised as a differentiator.
Mastercard Insights
What We Do
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re building a resilient economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Why Work With Us
We live the Mastercard Way: creating value in the communities we touch, growing together through the opportunities we see, and moving fast to innovate and scale. Our collaborative culture and our passionate people are the key to what we do, driving meaningful change as one team and connecting everyone to priceless possibilities.
Gallery
Mastercard Teams
Mastercard Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
In our ongoing workplace evolution, we’ve introduced hybrid work, Work-From-Elsewhere Weeks and Meeting-Free Days.






.jpg)













