Back to jobs

Principal Security Engineer
MastercardPune, Maharashtra, IndiaAdded 1h ago
Cloud Security Engineer
Full-time
Apply on company siteCraft my tailored resume free
Free to start · No card · 5 credits the moment you sign up
Job description
Job Title:
Principal Security Engineer
Overview:
Who is Mastercard
Mastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential.
Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all.
Mission First, People Always
As Corporate Security, we are responsible for keeping Mastercard safe and secure from cyber and physical threats, and it is our people on the frontlines who make this happen every day.
By taking care of our people, their wellbeing, and career development, we provide them the necessary tools and environment to ensure the success of our mission.
Overview
The Business Security Enablement ONE team is looking for a Principal Security Engineer to join our team. The Business Security Enablement Guild is a worldwide team of information security experts focused on helping Mastercard achieve its goals by ensuring security is at the heart of everything we do. The ideal candidate needs a high level of expertise in information security and secure engineering disciplines to advise product and operational teams on how to securely design applications and services following industry best practices.
Provide information security risk advisory and consultation to ONE (Operation, Network and Employee Digital experience) Program, including traditional applications and AI enabled platforms, through a strong understanding of business processes, data flows, and system architectures.
Enable ONE to proactively identify, manage, control, mitigate, and remediate security risks, including risks related to data usage, AI models, automation, and third party AI services, within the Mastercards defined risk appetite.
Partner with application development and platform teams to improve the security of application code, AI integrations, and system architectures, embedding security early in the SDLC.
Drive a strong risk aware and security first culture, promoting security and responsible AI awareness across Product and Technology organizations.
Collaborate with other security engineers to continuously improve security engineering processes, including the use of automation and AI assisted security reviews to scale delivery.
Apply deep knowledge of security principles, theories, and concepts across the business and development life cycle, including cloud native, data driven, and AI enabled solutions.
Take a lead security role in large, complex initiatives involving DevOps, CI/CD, IaaS/PaaS, Cloud, and AI platforms, including global, cross functional, and cross geographical programs.
Evaluate and provide recommendations for secure design patterns addressing:
oData protection and privacy
oIdentity, access, and privileged access
oSecure use of AI services, models, and automation
Recommend optimal solutions that meet security, regulatory, and compliance requirements for new and enhanced systems, balancing innovation velocity with enterprise risk.
Prepare and present clear, influential business and technical presentations, translating complex security and AI risks into actionable guidance for technical and non technical stakeholders.
All About You
710 years of progressive experience across multiple information security disciplines, with demonstrated depth in secure engineering and architecture.
CISSP or industry recognized security certification strongly preferred.
Expert level knowledge of security protocols, standards, third party technologies, secure architectures, and enterprise security design patterns.
Proven experience designing and securing cloud native and hybrid environments, including containerized technologies, IaaS/PaaS platforms, and associated security controls and processes.
Strong technical experience with programming languages and the ability to assess and influence secure coding practices.
Demonstrated expertise in security design and implementation for web based and distributed systems, including architectures supporting secure, high volume online transactions.
Deep technical knowledge of cryptography, including appropriate selection and application of cryptographic controls in enterprise systems.
Advanced hands on knowledge of symmetric and asymmetric encryption, digital certificates, SSL/TLS, VPN, IPSec, and enterprise security controls such as privileged identity management, logging, audit, file integrity monitoring, and IDS/IPS.
Intermediate to advanced scripting and automation skills, used to .