About this role
Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Principal Security Engineer
Who is Mastercard? Mastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential.
Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all. Mission First, People Always As Corporate Security, we are responsible for keeping Mastercard safe and secure from cyber and physical threats, and it is our people on the frontlines who make this happen every day. By taking care of our people, their wellbeing, and career development, we provide them the necessary tools and environment to ensure the success of our mission. Overview The Business Security Enablement ONE team is looking for a Principal Security Engineer to join our team. The Business Security Enablement Guild is a worldwide team of information security experts focused on helping Mastercard achieve its goals by ensuring security is at the heart of everything we do. The ideal candidate needs a high level of expertise in information security and secure engineering disciplines to advise product and operational teams on how to securely design applications and services following industry best practices. • Provide information security risk advisory and consultation to ONE (Operation, Network and Employee Digital experience) Program, including traditional applications and AI enabled platforms, through a strong understanding of business processes, data flows, and system architectures. • Enable ONE to proactively identify, manage, control, mitigate, and remediate security risks, including risks related to data usage, AI models, automation, and third party AI services, within the Mastercard’s defined risk appetite. • Partner with application development and platform teams to improve the security of application code, AI integrations, and system architectures, embedding security early in the SDLC. • Drive a strong risk aware and security first culture, promoting security and responsible AI awareness across Product and Technology organizations. • Collaborate with other security engineers to continuously improve security engineering processes, including the use of automation and AI assisted security reviews to scale delivery. • Apply deep knowledge of security principles, theories, and concepts across the business and development life cycle, including cloud native, data driven, and AI enabled solutions. • Take a lead security role in large, complex initiatives involving DevOps, CI/CD, IaaS/PaaS, Cloud, and AI platforms, including global, cross functional, and cross geographical programs. • Evaluate and provide recommendations for secure design patterns addressing: o Data protection and privacy o Identity, access, and privileged access o Secure use of AI services, models, and automation • Recommend optimal solutions that meet security, regulatory, and compliance requirements for new and enhanced systems, balancing innovation velocity with enterprise risk. • Prepare and present clear, influential business and technical presentations, translating complex security and AI risks into actionable guidance for technical and non technical stakeholders. All About You • 7–10 years of progressive experience across multiple information security disciplines, with demonstrated depth in secure engineering and architecture. • CISSP or industry recognized security certification strongly preferred. • Expert level knowledge of security protocols, standards, third party technologies, secure architectures, and enterprise security design patterns. • Proven experience designing and securing cloud native and hybrid environments, including containerized technologies, IaaS/PaaS platforms, and associated security controls and processes. • Strong technical experience with programming languages and the ability to assess and influence secure coding practices. • Demonstrated expertise in security design and implementation for web based and distributed systems, including architectures supporting secure, high volume online transactions. • Deep technical knowledge of cryptography, including appropriate selection and application of cryptographic controls in enterprise systems. • Advanced hands on knowledge of symmetric and asymmetric encryption, digital certificates, SSL/TLS, VPN, IPSec, and enterprise security controls such as privileged identity management, logging, audit, file integrity monitoring, and IDS/IPS. • Intermediate to advanced scripting and automation skills, used to improve security engineering efficiency, consistency, and scale. • Moderate to extensive hands on administrative and security experience with Linux systems, including security hardening and operational troubleshooting. • Ability to communicate effectively with security engineers, domain owners, architects, and business stakeholders, translating complex technical risks into clear, actionable guidance. • Strong written and verbal communication skills, with the capability to influence decisions, lead technical discussions, and present security recommendations with confidence. • Experience evaluating security risks in modern, data driven, and AI enabled systems, applying sound engineering judgment to emerging technologies. • NICE Framework References This Mastercard role shares knowledge, skills, and abilities with related NICE work roles. • SP-DEV-002, OPM622, Secure Software Assessor • SP-ARC-002, OPM652, Security Architect Corporate Security Responsibility Every person working for, or on behalf of, Mastercard is responsible for information security. All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and therefore, it is expected that the successful candidate for this position must: • Abide by Mastercard’s security policies and practices. • Ensure the confidentiality and integrity of the information being accessed. • Report any suspected information security violation or breach. • Complete all periodic mandatory security training in accordance with Mastercard’s guidelines.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
• Abide by Mastercard’s security policies and practices;
• Ensure the confidentiality and integrity of the information being accessed;
• Report any suspected information security violation or breach, and
• Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.