Lead Program Security Engineer

Mastercard

Bray (OK)

On-site

USD 180,000 - 240,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Mastercard seeks a Lead Program Security Engineer (L6) for Data & AI to champion security across data-centric products. You will partner with technology, engineering, and business teams to embed secure design, risk management, and privacy into data-driven solutions and AI initiatives.

The role requires deep security expertise, strong leadership across global teams, and the ability to drive security by design in a fast-paced environment.

Qualifications

  • Typically 7–10 years in information security with hands-on secure software development and secure architecture/design.
  • Experience with cloud platforms, APIs, and distributed systems.
  • Excellent communication skills to influence stakeholders and drive security across teams.
  • Familiarity with PCI-DSS, NIST SP 800-53, COBIT and data privacy in analytics and AI solutions.

Responsibilities

  • Serve as the primary security partner for Data Commercialization and AI initiatives.
  • Translate security policies into actionable guidance for Data & AI teams and embed security in the SDLC.
  • Collaborate with engineering and architecture to improve security of data pipelines, cloud services and AI models.
  • Lead governance activities: design/code reviews, threat modeling, architecture approvals, and vulnerability management.

Skills

Security leadership
Secure software
Cloud platforms
Risk management
DevSecOps
Data & AI security
Cross-functional collaboration

Tools

CI/CD tooling

Job description

Our Purpose

_Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential._


Title and Summary

Lead Program Security Engineer


Overview

Mastercard's Business Security Enablement (BSE) team is seeking a seasoned Lead Security Engineer (L6) - Data & AI to serve as the primary security advocate and advisor for our Data Commercialization and Artificial Intelligence initiatives. The BSE team is a worldwide group of information security experts focused on helping Mastercard achieve its goals by ensuring that security is at the heart of everything we do. In this role, you will collaborate with technology, engineering, and business teams to integrate strong security practices into Mastercard's data-driven products and AI solutions. The ideal candidate possesses a high level of expertise in information security and secure engineering disciplines, enabling them to advise product and development teams on designing secure applications and services following industry best practices. You will apply deep knowledge of security principles, theories, and concepts throughout the business and development lifecycles. As an L6 Security Engineer, you are expected to take a lead security role in large, complex, global, cross-functional initiatives. You will work closely with developers and architects to evaluate business needs, determine feasibility, and recommend optimal security solutions that meet both security and regulatory requirements. Furthermore, you will champion a strong security risk culture across the organization, proactively managing risks in alignment with Mastercard's risk appetite and ensuring data and AI innovations are secure by design.


Role


  • Security Partnership & Advocacy: Serve as the primary security partner for Data Commercialization and AI programs. Provide security risk guidance from discovery through deployment, and advise product, engineering, and operations teams on secure design and delivery of data-driven and AI-powered solutions.

  • Security Engineering Enablement: Translate Corporate Security policies, standards, and controls into actionable guidance for Data & AI teams. Partner with security champions and deliver targeted training. Maintain security dashboards/documentation and ensure requirements (secure coding, data protection, IAM controls) are embedded in the SDLC. Ensure adherence to security policy, regulatory requirements, and industry standards (e.g., PCI-DSS, privacy).

  • Collaboration & Leadership: Partner with Business Security Officers (BSOs) and act as a bridge between Corporate Security and Data/AI product teams. Work with engineering and architecture to improve security of code, data pipelines, cloud services, and AI solutions. Promote a security-first culture across the domain.

  • Security Reviews & Oversight: Lead key security governance for Data & AI work, including design/code reviews, Solution Architecture approvals, Threat Model reviews, Third-Party technology reviews, Technical Architecture Diagram approvals, Network as a Service approval, and vulnerability management support. Drive security user stories in PI Planning and ensure requirements are tracked to closure.

  • Innovation & Continuous Improvement: Monitor emerging threats and best practices across data analytics and AI. Partner with cross-functional teams to strengthen protection for sensitive data and ML models. Improve architectures and processes through standardization and automation of security controls and tooling.


All About You


  • Extensive Security and Engineering Experience: Typically, 7-10 years in information security, with hands-on secure software development and secure architecture/design, including reviewing code/systems for vulnerabilities. Experience with cloud platforms, APIs, and distributed systems preferred.

  • Leadership and Collaboration: Proven ability to work effectively in a global environment, build strong relationships, and influence cross-functional and executive stakeholders across varying technical depth.

  • Security Knowledge and Technical Skills: Advanced knowledge of security principles, domains, protocols, and standards, with familiarity with ISO 27001, PCI-DSS, NIST SP 800-53, and COBIT. Strong grounding in risk management and data privacy for data analytics, digital commerce, and AI solutions, and experience designing secure, multi-domain architectures.

  • Cryptography Security: Strong experience with cryptography and network security, including encryption, hashing, key management, PKI/certificates, TLS/SSL, VPN, IPsec, and related protocols.

  • DevSecOps: Experience with DevOps/DevSecOps, including CI/CD and automated deployments, with security controls embedded throughout the SDLC.

  • Technical Domain Expertise: Proficiency with data technologies, analytics platforms, and AI/ML frameworks; experience securing data platforms and/or AI/ML models.

  • Business & Industry Acumen: Knowledge of the payments and e-commerce landscape and security considerations for data-centric and AI-powered products, including best practices for protecting data assets and algorithms and awareness of emerging threats.

  • Mindset and Soft Skills: Professional, proactive, and solutions-oriented, with strong problem-solving and continuous-learning mindset. Excellent communication skills to articulate security risks and mitigations to technical and business audiences, and comfort operating in a fast-paced, global environment.


NICE Framework References


  • SP-DEV-002 (OPM622) - Secure Software Assessor

  • SP-ARC-002 (OPM652) - Security Architect

  • OV-SPP-002 (OPM751) - Cyber Policy and Strategy Planner


Corporate Security Responsibility

At Mastercard, every person working for or on behalf of the company is responsible for information security. All activities involving access to Mastercard assets, information, and networks come with an inherent risk to the organization. Therefore, it is expected that the successful candidate for this position will:



  • Abide by Mastercard's security policies and practices.

  • Ensure the confidentiality and integrity of the information being accessed.

  • Report any suspected information security violation or breach in a timely manner.

  • Complete all periodic mandatory security training courses in accordance with Mastercard's guidelines.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager Security Engineer & Enablement
Manager Security Engineer & Enablement

Mastercard • Bray (OK)

On-site
USD 120,000 - 160,000
Lead Data & AI Security Engineer
Lead Data & AI Security Engineer

Mastercard • Bray (OK)

On-site
USD 180,000 - 240,000
Principal Software Engineer
Principal Software Engineer

Mastercard • Bray (OK)

On-site
USD 180,000 - 250,000
Lead Data Scientist at Mastercard Mexico
Lead Data Scientist at Mastercard Mexico

Ellenco Estágios e Treinamentos • Town of Mexico (NY)

On-site
USD 120,000 - 210,000
Senior AI Engineer
Senior AI Engineer

Mastercard • Bray (OK)

On-site
USD 130,000 - 190,000
Unified Checkout Services Product Development Director
Unified Checkout Services Product Development Director

Mastercard • Bray (OK)

On-site
USD 180,000 - 280,000
Specialist-1
Specialist-1

Mastercard • Seattle (WA)

On-site
USD 120,000 - 180,000
Lead Data Scientist at Mastercard Lane County, KS
Lead Data Scientist at Mastercard Lane County, KS

Ellenco Estágios e Treinamentos • Kansas

On-site
USD 140,000 - 200,000
Senior Vice President - Software Engineering, Commercial Acceptance
Senior Vice President - Software Engineering, Commercial Acceptance

Mastercard • Bray (OK)

On-site
USD 250,000 - 350,000
Director - Segment Sales Enablement - Enterprise & Credit Risk
Director - Segment Sales Enablement - Enterprise & Credit Risk

Mastercard • Bray (OK)

On-site
USD 180,000 - 300,000