Lead AI Security Engineer, AI Identities-2
Mastercard
Lead AI Security Engineer, AI Identities-2
Job Description Summary
As an Information Security Engineer – AI Identity Security, you will be responsible for securing the identities associated with AI systems, including models, agents, services, pipelines, and non‑human actors that interact with data, infrastructure, and other systems. This role focuses on the discovery, lifecycle management, control enforcement, and monitoring of AI identities to ensure they are properly governed, least‑privileged, and continuously assessed for risk.
AI Identity Discovery & Inventory
• Design and operate mechanisms to discover and inventory AI identities, including:
o AI models, agents, and autonomous workflows
o Service accounts, non‑human identities, and API principals used by AI systems
o Identities created dynamically through AI pipelines, orchestration tools, and integrations • Maintain authoritative visibility into where AI identities exist, what they can access, and how they are used across environments.
• Integrate AI identity discovery into broader identity, asset, and AI Security Posture Management (AI‑SPM) capabilities. AI Identity Lifecycle Management
• Define and operationalize lifecycle controls for AI identities, including creation, modification, rotation, suspension, and decommissioning.
• Ensure AI identities are created with strong provenance, ownership, and accountability, including linkage to business and technical owners.
• Implement controls to prevent identity sprawl, orphaned AI identities, and unmanaged credentials. Access Control & Policy Enforcement
• Design and enforce least‑privilege access models for AI identities, aligned with the sensitivity of data, models, and actions performed.
• Partner with IAM and platform teams to implement policy‑based access controls, including role‑based, attribute‑based, and context‑aware authorization for AI systems.
• Ensure AI identities comply with enterprise security standards for authentication strength, credential handling, and key/token management. Monitoring, Detection & Risk Assessment
• Implement continuous monitoring of AI identity behavior, including access patterns, privilege use, and anomalous activity.
• Detect and investigate identity‑based risks and threats, such as excessive permissions, credential misuse, lateral movement, or abuse of AI agents.
• Leverage telemetry from identity platforms, cloud providers, and AI security tools to assess ongoing AI identity risk. AI Security Assessments & Control Validation • Conduct security assessments focused on AI identity usage, including architecture reviews, threat modeling, and control effectiveness testing.
• Validate that AI identity controls are correctly implemented and enforced across development, testing, and production environments.
• Partner with engineering teams to remediate identified gaps and track risk reduction over time. Governance, Standards & Compliance • Support development and operationalization of AI identity security standards, patterns, and control requirements, aligned with NIST, ISO, and emerging AI guidance.
• Track regulatory, legal, and industry expectations related to identity, access, and AI accountability.
• Provide evidence, reporting, and metrics to support audits, risk reviews, and governance forums. Documentation, Reporting & Metrics
• Develop and maintain standard operating procedures (SOPs), design patterns, and runbooks for AI identity security.
• Produce clear reports on AI identity posture, including coverage, risk, and remediation progress.
• Contribute to AI identity KPIs and KRIs, such as unmanaged identities, privilege levels, and anomalous activity trends. Advisory, Training & Enablement
• Act as a trusted advisor on AI identity security, providing guidance on secure patterns and operational best practices.
• Educate engineering and platform teams on AI identity risks, controls, and monitoring expectations.
• Support internal communities of practice focused on AI security, IAM modernization, and responsible AI adoption. Research, Experimentation & Continuous Improvement
• Stay current on emerging trends in AI agents, autonomous systems, and non‑human identity security.
• Design and execute proofs of concept (POCs) to evaluate new AI identity security tools, controls, and monitoring approaches.
• Continuously improve AI identity security through automation, integration, and control refinement. Qualifications • Bachelor’s or Master’s degree in Computer Science, Information Security, Engineering, or a related field.
• Strong experience in identity and access management, security engineering, or security operations, with exposure to AI or highly automated systems.
• Expertise in Least Agency frameworks, Zero Trust Architecture, Delegated Authority Management, Cryptographic Identities, and Short Lived Credentialing.
• Practical experience securing non‑human identities, service accounts, APIs, or machine‑to‑machine access.
• Understanding of AI/ML architectures and how identities are used across data pipelines, model execution, and agent‑based systems.
• Proven ability to design, assess, and operationalize identity controls at scale.
• Strong analytical and communication skills, with the ability to translate identity risk into actionable security outcomes.
• Relevant certifications such as CISSP, GIAC, CIAM/IAM‑related certifications, or cloud security certifications are desirable.
This role aligns to the NICE Cybersecurity Workforce Framework, with primary alignment to Identity and Access Management, Security Control Assessment, Cybersecurity Architecture, Systems Security Management, and Incident Response work roles. Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
- Abide by Mastercard’s security policies and practices;
- Ensure the confidentiality and integrity of the information being accessed;
- Report any suspected information security violation or breach, and
- Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.
- ...range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation... ...realize their greatest potential. Title and Summary Lead AI Security Engineer, AI Identities-2 Job Description Summary As an Information...SuggestedFull timeWorldwide
- ...would love for you to join us. AI native product is fundamentally different engineering problem than building deterministic... ...an Applied AI Engineer with 2-5 years of experience building... ...appropriate safeguards for privacy, security, reliability, human oversight, and...SuggestedFull timeFlexible hoursShift work
- ...As an LLM Systems / AI Agent Engineer , you will focus on building and evolving production AI agents... ...alongside the engineer who currently leads this function. The product currently... ...against roadmap timelines. Requirements ~2+ years of experience building...SuggestedFull timeSummer workImmediate startShift work
$3,200 per month
...Senior Software Engineer, Labor Planning & Forecasting... ...be able to write secure, efficient,... ...serving as technical lead throughout the full... ...The award-winning, AI-driven Legion WFM platform... ..., gender identity, gender expression,... ...job application. 2. How We Use Personal...SuggestedHourly payPermanent employmentFull timeLocal areaRemote work- ...digital payments choices, making transactions secure, simple, smart and accessible. Our... ...greatest potential. Title and Summary AI Engineer Mastercard’s Business & Market Insights... ...complex data into actionable strategies that lead to better outcomes and sustained...SuggestedFull timeWork experience placementWorldwide
- ...boutique consultancy specializing in IT professional services and engineering talent solutions. With a strong background in software... ...valuable code repositories and are interested in licensing them for AI training. How It Works Connect your existing Git repositories...
- ...humanity. We are seeking an experienced, talented and ambitious AI Engineer with expertise in computer vision and strong development... ...frameworks. Thoroughly document POCs and experiments. Plan and lead long-term research activities. Assist in recruiting talent...Full time
- ...technological convergence, our engineering talent is a catalyst for... ...diagnostics and resolving Tier 2 and Tier 3 incidents that impact... ...corrections Implementation of AI-driven diagnostic tools to... ...sex, sexual orientation, gender identity, national origin, disability,...Local areaFlexible hoursNight shift
- ...We are hiring a hands-on Principal Engineer to lead our new AI-first engineering pod — a small, high... ...triggers into PR and CI/CD workflows: security analysis, bug-risk review, test gap detection... ...assessment of our .NET Core 2.1 estate and a pragmatic upgrade recommendation...Full timeLive in
- ...We are hiring an SDE 2 Backend Engineer to support the design, development, and maintenance of scalable backend services and APIs. The role will... ...in a high-growth startup for 2+ years . Exposure to AI/ML-integrated solutions or interest in working alongside data...Full time
- ...Building AI-native products is a different problem than building deterministic software... ...always produce the same output. Good product engineering here means designing experiences that stay... ...re looking for a Software Engineer with 2-7 years of experience who thinks like a...Full timeShift work
- We are seeking an experienced and innovative Senior AI Engineer. In this remote role, you will be responsible for designing and developing autonomous AI agents that automate virtual pre-construction, 3D digital twin generation, and estimation workflows. You'll play a key...Full timeRemote work
- ...looking for a Principal Software Engineer to provide hands-on... ...Central Platform Group. You will lead the architecture, design,... ...You will also help build secure, reliable AI experiences that connect customers... ..., backend services, APIs, identity and access capabilities,...Full time
- ...technological convergence, our engineering talent is a... ...Lead the design, execution... ...scaling of end-to-end AI/ML and GenAI initiatives... ...integration into scalable, secure cloud-native... ...or AI, and at least 2+ years in a leadership... ..., gender identity, national origin, disability...Local area
- ...the future of work with Computer – your AI teammate. Unlike traditional tools,... ...Thursday. You will work directly with customer engineering, operations, and executive teams —... ...What You Will Do Discover & Design Lead technical discovery: map customer workflows...Full timeShift work
- ...oriented annotators to help label robot manipulation videos for AI training purposes. You'll watch short videos of robots performing... ...the overhead view to understand the overall scene and object identity, and the close-up wrist views to confirm exact contact and grasp...
- ...an experienced Apigee Cloud Engineer to join our team on a contract... ...role, you will design, deploy, secure, and automate API management... ...Cloud Armor. API Security & Identity Validation : Implement enterprise... ...policies leveraging OAuth 2.0 , JWT token validation ,...Contract workTemporary work
- ...choices, making transactions secure, simple, smart and accessible.... ...are looking at implementing an AI based solution to support increased... ...-world problems. • Promote engineering best practices and contribute... ...• Hands on experience of 2-3 years in implementing LLM models...Full timeWorldwide
- ...AI Architecture & Development Architect and develop... ...strategies for prompt engineering, model routing, fine-tuning... ...Technical Leadership Lead, mentor, and develop AI/... ...Data Science, Platform, Security, and Compliance teams to... ...systems. ~ At least 2+ years of hands-on experience...Full time
- ...Senior Site Reliability Engineer . This role presents an... ...experience to play, and with AI tooling , you should be... ...team’s roadmap, leading us to higher levels of reliability... ...for observability, security, and CI/CD across teams.... ...schedule of 6:00 AM to 2:00 PM EST . While the...Full timeFlexible hours
- ...group with a simple hypothesis: people in tier-2/3 towns weren’t really using the internet... ...-language internet + deep India insight+ AI. When someone opens a product we’ve built,... ...market in the Philippines. We are backed by leading global and domestic investors including Y...Full timeLocal area
- ...? You'll own AppSec and Cloud Security automation across a platform used... ...in regulated industries, with AI as your primary force... ...required. Application Security: Lead threat modeling, security reviews... ...APIs, and services. Work with engineering to eliminate vulnerability classes...Full time
- ...and related infrastructure Coordinate AIS verification terminal version upgrades... ...Qualifications ~7+ years of experience in security operations, including substantial hands-... ...ADFS certificate renewals and related identity federation components ~ Experience supporting...Full timeRemote workShift work
- ...What You Will Own The Identity Lifecycle: You will own the core... ...allow over 150+ downstream engineers to integrate security features into their products... .../AuthZ primitives: OAuth 2.0, OIDC, SAML, and JWT mechanics... ...Artificial Intelligence (AI) tools to help us work more...Full time
- ...technological convergence, our engineering talent is a catalyst for... ...Responsibilities Working with PO and lead in the development of the... ...skills. Should have mindset for AI knowledge absorption and use... ..., sexual orientation, gender identity, national origin, disability,...Local area
- ...choices, making transactions secure, simple, smart and... ..., Software Development Engineering Overview: Providing... ...Formally supervise and coach 2+ teams of engineers to... ...to industry-leading design, architecture, and... ...regard to gender, gender identity, race, colour, ethnicity...Full timeWorldwide
- ...The Senior Software Engineer, Full-Stack owns features end-to-end across Epic's web application --... ...engineers through code review and pairing. Lead technical design reviews, RFCs, and architecture discussions. Use AI-assisted development tools to accelerate delivery...Full timeRemote work
- ...choices, making transactions secure, simple, smart and accessible.... ...and Summary Senior Software Engineer Overview Mastercard is a... ...ownership, and the ability to lead complex engineering initiatives... ...Engineering metrics/DORA Identity & authentication integrations...Full timeWorldwide
- ...digital payments choices, making transactions secure, simple, smart and accessible. Our... ...potential. Title and Summary Software Engineer - 1 Job Description Summary Overview... ...This program leverages business rules & AI engines, a streaming big data cluster, an...Full timeWork at officeWorldwide
- ...digital payments choices, making transactions secure, simple, smart and accessible. Our... ...potential. Title and Summary Software Engineer II Our Purpose We work to connect and... ...Hibernate, use of software development tools, AI pair programming. Familiar with DevOps...Full timeWork experience placementWorldwide
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead AI Security Engineer, AI Identities-2. Be the first to apply!






