Lead AI Security Engineer, AI Identities
Mastercard
Lead AI Security Engineer, AI Identities
Job Description Summary
As an Information Security Engineer – AI Identity Security, you will be responsible for securing the identities associated with AI systems, including models, agents, services, pipelines, and non‑human actors that interact with data, infrastructure, and other systems. This role focuses on the discovery, lifecycle management, control enforcement, and monitoring of AI identities to ensure they are properly governed, least‑privileged, and continuously assessed for risk.
AI Identity Discovery & Inventory
• Design and operate mechanisms to discover and inventory AI identities, including:
o AI models, agents, and autonomous workflows
o Service accounts, non‑human identities, and API principals used by AI systems
o Identities created dynamically through AI pipelines, orchestration tools, and integrations • Maintain authoritative visibility into where AI identities exist, what they can access, and how they are used across environments.
• Integrate AI identity discovery into broader identity, asset, and AI Security Posture Management (AI‑SPM) capabilities. AI Identity Lifecycle Management
• Define and operationalize lifecycle controls for AI identities, including creation, modification, rotation, suspension, and decommissioning.
• Ensure AI identities are created with strong provenance, ownership, and accountability, including linkage to business and technical owners.
• Implement controls to prevent identity sprawl, orphaned AI identities, and unmanaged credentials. Access Control & Policy Enforcement
• Design and enforce least‑privilege access models for AI identities, aligned with the sensitivity of data, models, and actions performed.
• Partner with IAM and platform teams to implement policy‑based access controls, including role‑based, attribute‑based, and context‑aware authorization for AI systems.
• Ensure AI identities comply with enterprise security standards for authentication strength, credential handling, and key/token management. Monitoring, Detection & Risk Assessment
• Implement continuous monitoring of AI identity behavior, including access patterns, privilege use, and anomalous activity.
• Detect and investigate identity‑based risks and threats, such as excessive permissions, credential misuse, lateral movement, or abuse of AI agents.
• Leverage telemetry from identity platforms, cloud providers, and AI security tools to assess ongoing AI identity risk. AI Security Assessments & Control Validation • Conduct security assessments focused on AI identity usage, including architecture reviews, threat modeling, and control effectiveness testing.
• Validate that AI identity controls are correctly implemented and enforced across development, testing, and production environments.
• Partner with engineering teams to remediate identified gaps and track risk reduction over time. Governance, Standards & Compliance • Support development and operationalization of AI identity security standards, patterns, and control requirements, aligned with NIST, ISO, and emerging AI guidance.
• Track regulatory, legal, and industry expectations related to identity, access, and AI accountability.
• Provide evidence, reporting, and metrics to support audits, risk reviews, and governance forums. Documentation, Reporting & Metrics
• Develop and maintain standard operating procedures (SOPs), design patterns, and runbooks for AI identity security.
• Produce clear reports on AI identity posture, including coverage, risk, and remediation progress.
• Contribute to AI identity KPIs and KRIs, such as unmanaged identities, privilege levels, and anomalous activity trends. Advisory, Training & Enablement
• Act as a trusted advisor on AI identity security, providing guidance on secure patterns and operational best practices.
• Educate engineering and platform teams on AI identity risks, controls, and monitoring expectations.
• Support internal communities of practice focused on AI security, IAM modernization, and responsible AI adoption. Research, Experimentation & Continuous Improvement
• Stay current on emerging trends in AI agents, autonomous systems, and non‑human identity security.
• Design and execute proofs of concept (POCs) to evaluate new AI identity security tools, controls, and monitoring approaches.
• Continuously improve AI identity security through automation, integration, and control refinement. Qualifications • Bachelor’s or Master’s degree in Computer Science, Information Security, Engineering, or a related field.
• Strong experience in identity and access management, security engineering, or security operations, with exposure to AI or highly automated systems.
• Expertise in Least Agency frameworks, Zero Trust Architecture, Delegated Authority Management, Cryptographic Identities, and Short Lived Credentialing.
• Practical experience securing non‑human identities, service accounts, APIs, or machine‑to‑machine access.
• Understanding of AI/ML architectures and how identities are used across data pipelines, model execution, and agent‑based systems.
• Proven ability to design, assess, and operationalize identity controls at scale.
• Strong analytical and communication skills, with the ability to translate identity risk into actionable security outcomes.
• Relevant certifications such as CISSP, GIAC, CIAM/IAM‑related certifications, or cloud security certifications are desirable.
This role aligns to the NICE Cybersecurity Workforce Framework, with primary alignment to Identity and Access Management, Security Control Assessment, Cybersecurity Architecture, Systems Security Management, and Incident Response work roles. Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
- Abide by Mastercard’s security policies and practices;
- Ensure the confidentiality and integrity of the information being accessed;
- Report any suspected information security violation or breach, and
- Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.
- ...range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation... ...realize their greatest potential. Title and Summary Lead AI Security Engineer, AI Identities Job Description Summary As an Information...SuggestedFull timeWorldwide
- ...We are looking for a Senior Security Engineer to own and drive Corporate Security... ...SaaS applications, corporate identities ( Okta/Google Workspace ),... ...security workflows Lead security reviews of new SaaS... ...safely in an environment where AI agents act autonomously across...SuggestedFull timeRemote work
- ...cybersecurity, online privacy, identity protection and... ...them grow, manage and secure their digital and financial... ...-impact talent who see AI as a teammate –... ...Fullstack Senior Software Engineer with strong MERN stack... ...execution focused: you will lead the design and delivery...SuggestedFull timeFlexible hours
- ...choices, making transactions secure, simple, smart and... ...Principal Security Engineer Who is Mastercard?... ...traditional applications and AI enabled platforms,... ...solutions. • Take a lead security role in large,... ...protection and privacy o Identity, access, and privileged...SuggestedFull timeWorldwide
- ...services for the video game industry, is looking for a skilled AI Engineer. You will play a key role in developing, deploying, and... ...with vector databases. Use Model Context Protocol (MCP) to securely connect AI models with external data sources and tools. Requirements...SuggestedFull timeFlexible hours
- ...boutique consultancy specializing in IT professional services and engineering talent solutions. With a strong background in software... ...valuable code repositories and are interested in licensing them for AI training. How It Works Connect your existing Git repositories...
- ...a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation,... ...governments realize their greatest potential. Title and Summary AI Engineer Job Description Our Purpose Mastercard powers...Full timeWorldwide
- ...digital payments choices, making transactions secure, simple, smart and accessible. Our... ...greatest potential. Title and Summary Senior AI Engineer, AI Engineering Mastercard’s Business... ...data into actionable strategies that lead to better outcomes and sustained competitive...Full timeWork experience placementWorldwide
- ...a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation,... ...governments realize their greatest potential. Title and Summary AI Engineer Job Description Summary We believe in power of data. We...Full timeWorldwide
- ...We are seeking an experienced and innovative Senior AI Engineer. In this remote role, you will be responsible for designing and developing autonomous AI agents that automate virtual pre-construction, 3D digital twin generation, and estimation workflows. You'll play a key...Full timeLocal areaRemote workWork from home
- ...digital payments choices, making transactions secure, simple, smart and accessible. Our... ...potential. Title and Summary Manager AI Engineering Mastercard's Business & Market Insights... ...advantage. We are looking for a Lead Engineer, Generative AI & ML Engineering...Full timeWorldwide
- ...digital payments choices, making transactions secure, simple, smart and accessible. Our... .... Title and Summary Principal Applied AI App Engineer Who is Mastercard? Mastercard is a... ...Engineer role: • Serve as the GBSC’s design lead for AI based solutions within Mastercard...Full timeWorldwide
- ...As an LLM Systems / AI Agent Engineer , you will focus on building and evolving production AI agents on foundation models, covering orchestration... ...hire, working directly alongside the engineer who currently leads this function. The product currently uses a custom...Full timeSummer workImmediate startShift work
- ...choices, making transactions secure, simple, smart and accessible.... ...Title and Summary Software Engineer II Overview Mastercard is... ...DevSecOps best practices, automation, AI-enabled productivity, and... ...and Reverse Proxies Identity & Access Management (IAM) Authentication...Full timeWorldwide
- ...at the intersection of AI and fintech. At Ocrolus... ...-the-loop verification engine, Ocrolus captures data... ...business requirements that securely scale over millions of... .... ~ Experience leading and owning projects from... ...of race, gender, gender identity, age, disability, national...Full timeRemote work
- ...About Ping Identity: At Ping Identity, we believe in making digital experiences both secure and seamless for all users, without compromise... ...hands-on Principal Software Engineer to build PingOne Privilege, our... ...privileged access platform, and the AI security capabilities that...Full timeLocal areaWorldwideFlexible hours
- ...assets for the world’s leading financial institutions,... ...About the team The Data Engineering team at Paxos builds... ...scalable, reliable, and secure data access to support... ...service accounts, and identity provider integrations... ...practices ~ Active use of AI tools (e.g., Claude,...Full time
- ...: Walter is recruiting on behalf of a leading global agriculture technology enterprise... ...We are seeking a highly experienced AI/Python Engineer to design, build, and optimize intelligent... ...with international data privacy and security regulations. Required Skills & Qualifications...Full timeRemote workWorldwideFlexible hours
- ...Syntiant Corp. is an industry-leading innovator delivering... ...models for Edge AI deployment. Syntiant’s... ...minded Embedded Software Engineer to join our global engineering... ...Systems Programmer, or identical low-level hardware-... ...-based root of trust security subsystems. What We...Permanent employmentFull timeWork at officeRemote workShift work
- ..., and complex SLA-driven performance analytics. Built on high-performance mathematical solvers and distributed cloud systems, this engine helps operations teams maximize field efficiency and lower resource overhead under dynamic conditions. Position Overview We are...Full timeLocal areaRemote workWork from homeFlexible hours
- ...humanity. We are seeking an experienced, talented and ambitious AI Engineer with expertise in computer vision and strong development... ...frameworks. Thoroughly document POCs and experiments. Plan and lead long-term research activities. Assist in recruiting talent...Full time
- ...forums to ensure every distributed worker truly thrives. Position Overview We are seeking a highly autonomous, execution-focused AI Engineer to take technical ownership of improving, restructuring, and stabilizing an existing AI-powered voice platform built natively on...Contract workSummer workRemote workMonday to FridayShift work
- We are seeking an experienced and innovative Senior AI Engineer. In this remote role, you will be responsible for designing and developing autonomous AI agents that automate virtual pre-construction, 3D digital twin generation, and estimation workflows. You'll play a key...Full timeRemote work
- ...574851_AI/GenAI RAG , LLM , Agentic AI _HTADM 7+ Years Strong handson experience in AI/GenAI RAG , LLM , Agentic... ...working with GCP Node JS experience is a plus Should be able to lead a team Working in an agile environment, Independent problem...
- ...About Ping Identity: At Ping Identity, we believe in... ...digital experiences both secure and seamless for all users... ...critical parts of the engineering system that help... ...platform capabilities, and AI-enabled engineering tooling... ...developer platform, lead engineers, shape technical...Full timeWork at officeLocal areaWorldwideFlexible hours2 days per week3 days per week
- ...elite, award-winning data and AI consulting partner that bridges... ...-focused Senior Applied AI Engineer to join our Applied AI practice... ...that reason, retrieve, and act securely across complex enterprise tech... ...ticket log management, you will lead an active Retrieval-Augmented...Full timeCasual workRemote workShift work
- ...Global Capital, CoinFund, Gumi Cryptos) and crypto projects (Aave and Kyber Network). About the role You'll be the dedicated security engineer at a derivative exchange (~250 people, 50-100 person dev team). All infra is AWS. DevOps builds it; you make sure it's secure...Full time
- ...choices, making transactions secure, simple, smart and accessible.... ...Title and Summary Senior Data Engineer, Data Engineering Job Description... ...for all. Our Team: The AI Network Services Team (AI &... ..., security, fraud, digital identity and authentication. The team is...Full timeWorldwide
- ...payments choices, making transactions secure, simple, smart and accessible. Our... ...potential. Title and Summary Sr Data Engineer Overview The AI Innovation at Scale team is seeking a... ...centric data models that support merchant identity resolution and longitudinal profiling...Full timeWorldwide
- ...a hub for technological convergence, our engineering talent is a catalyst for innovation in multimedia... ...and agentic workflows to drive AI-first architecture and maximize value realization... ..., sex, sexual orientation, gender identity, national origin, disability, or protected...Local area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead AI Security Engineer, AI Identities. Be the first to apply!






