Secure identities for AI systems by discovering and inventorying AI/non-human identities, enforcing least-privilege lifecycle controls, implementing access policies, monitoring identity behavior, performing assessments and remediation, supporting governance and compliance, producing metrics and runbooks, and advising engineering teams on AI identity security best practices.
Our Purpose
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Lead AI Security Engineer, AI Identities
Job Description Summary
As an Information Security Engineer - AI Identity Security, you will be responsible for securing the identities associated with AI systems, including models, agents, services, pipelines, and non-human actors that interact with data, infrastructure, and other systems. This role focuses on the discovery, lifecycle management, control enforcement, and monitoring of AI identities to ensure they are properly governed, least-privileged, and continuously assessed for risk.
Key Responsibilities
AI Identity Discovery & Inventory• Design and operate mechanisms to discover and inventory AI identities, including:
o AI models, agents, and autonomous workflows
o Service accounts, non-human identities, and API principals used by AI systems
o Identities created dynamically through AI pipelines, orchestration tools, and integrations
• Maintain authoritative visibility into where AI identities exist, what they can access, and how they are used across environments.• Integrate AI identity discovery into broader identity, asset, and AI Security Posture Management (AI-SPM) capabilities.
AI Identity Lifecycle Management• Define and operationalize lifecycle controls for AI identities, including creation, modification, rotation, suspension, and decommissioning.• Ensure AI identities are created with strong provenance, ownership, and accountability, including linkage to business and technical owners.• Implement controls to prevent identity sprawl, orphaned AI identities, and unmanaged credentials.
Access Control & Policy Enforcement• Design and enforce least-privilege access models for AI identities, aligned with the sensitivity of data, models, and actions performed.• Partner with IAM and platform teams to implement policy-based access controls, including role-based, attribute-based, and context-aware authorization for AI systems.• Ensure AI identities comply with enterprise security standards for authentication strength, credential handling, and key/token management.
Monitoring, Detection & Risk Assessment• Implement continuous monitoring of AI identity behavior, including access patterns, privilege use, and anomalous activity.• Detect and investigate identity-based risks and threats, such as excessive permissions, credential misuse, lateral movement, or abuse of AI agents.• Leverage telemetry from identity platforms, cloud providers, and AI security tools to assess ongoing AI identity risk.
AI Security Assessments & Control Validation
• Conduct security assessments focused on AI identity usage, including architecture reviews, threat modeling, and control effectiveness testing.• Validate that AI identity controls are correctly implemented and enforced across development, testing, and production environments.• Partner with engineering teams to remediate identified gaps and track risk reduction over time.
Governance, Standards & Compliance
• Support development and operationalization of AI identity security standards, patterns, and control requirements, aligned with NIST, ISO, and emerging AI guidance.• Track regulatory, legal, and industry expectations related to identity, access, and AI accountability.• Provide evidence, reporting, and metrics to support audits, risk reviews, and governance forums.
Documentation, Reporting & Metrics• Develop and maintain standard operating procedures (SOPs), design patterns, and runbooks for AI identity security.• Produce clear reports on AI identity posture, including coverage, risk, and remediation progress.• Contribute to AI identity KPIs and KRIs, such as unmanaged identities, privilege levels, and anomalous activity trends.
Advisory, Training & Enablement• Act as a trusted advisor on AI identity security, providing guidance on secure patterns and operational best practices.• Educate engineering and platform teams on AI identity risks, controls, and monitoring expectations.• Support internal communities of practice focused on AI security, IAM modernization, and responsible AI adoption.
Research, Experimentation & Continuous Improvement• Stay current on emerging trends in AI agents, autonomous systems, and non-human identity security.• Design and execute proofs of concept (POCs) to evaluate new AI identity security tools, controls, and monitoring approaches.• Continuously improve AI identity security through automation, integration, and control refinement.
Qualifications
• Bachelor's or Master's degree in Computer Science, Information Security, Engineering, or a related field.• Strong experience in identity and access management, security engineering, or security operations, with exposure to AI or highly automated systems.• Expertise in Least Agency frameworks, Zero Trust Architecture, Delegated Authority Management, Cryptographic Identities, and Short Lived Credentialing. • Practical experience securing non-human identities, service accounts, APIs, or machine-to-machine access.• Understanding of AI/ML architectures and how identities are used across data pipelines, model execution, and agent-based systems.• Proven ability to design, assess, and operationalize identity controls at scale.• Strong analytical and communication skills, with the ability to translate identity risk into actionable security outcomes.• Relevant certifications such as CISSP, GIAC, CIAM/IAM-related certifications, or cloud security certifications are desirable.
This role aligns to the NICE Cybersecurity Workforce Framework, with primary alignment to Identity and Access Management, Security Control Assessment, Cybersecurity Architecture, Systems Security Management, and Incident Response work roles.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.
Title and Summary
Lead AI Security Engineer, AI Identities
Job Description Summary
As an Information Security Engineer - AI Identity Security, you will be responsible for securing the identities associated with AI systems, including models, agents, services, pipelines, and non-human actors that interact with data, infrastructure, and other systems. This role focuses on the discovery, lifecycle management, control enforcement, and monitoring of AI identities to ensure they are properly governed, least-privileged, and continuously assessed for risk.
Key Responsibilities
AI Identity Discovery & Inventory• Design and operate mechanisms to discover and inventory AI identities, including:
o AI models, agents, and autonomous workflows
o Service accounts, non-human identities, and API principals used by AI systems
o Identities created dynamically through AI pipelines, orchestration tools, and integrations
• Maintain authoritative visibility into where AI identities exist, what they can access, and how they are used across environments.• Integrate AI identity discovery into broader identity, asset, and AI Security Posture Management (AI-SPM) capabilities.
AI Identity Lifecycle Management• Define and operationalize lifecycle controls for AI identities, including creation, modification, rotation, suspension, and decommissioning.• Ensure AI identities are created with strong provenance, ownership, and accountability, including linkage to business and technical owners.• Implement controls to prevent identity sprawl, orphaned AI identities, and unmanaged credentials.
Access Control & Policy Enforcement• Design and enforce least-privilege access models for AI identities, aligned with the sensitivity of data, models, and actions performed.• Partner with IAM and platform teams to implement policy-based access controls, including role-based, attribute-based, and context-aware authorization for AI systems.• Ensure AI identities comply with enterprise security standards for authentication strength, credential handling, and key/token management.
Monitoring, Detection & Risk Assessment• Implement continuous monitoring of AI identity behavior, including access patterns, privilege use, and anomalous activity.• Detect and investigate identity-based risks and threats, such as excessive permissions, credential misuse, lateral movement, or abuse of AI agents.• Leverage telemetry from identity platforms, cloud providers, and AI security tools to assess ongoing AI identity risk.
AI Security Assessments & Control Validation
• Conduct security assessments focused on AI identity usage, including architecture reviews, threat modeling, and control effectiveness testing.• Validate that AI identity controls are correctly implemented and enforced across development, testing, and production environments.• Partner with engineering teams to remediate identified gaps and track risk reduction over time.
Governance, Standards & Compliance
• Support development and operationalization of AI identity security standards, patterns, and control requirements, aligned with NIST, ISO, and emerging AI guidance.• Track regulatory, legal, and industry expectations related to identity, access, and AI accountability.• Provide evidence, reporting, and metrics to support audits, risk reviews, and governance forums.
Documentation, Reporting & Metrics• Develop and maintain standard operating procedures (SOPs), design patterns, and runbooks for AI identity security.• Produce clear reports on AI identity posture, including coverage, risk, and remediation progress.• Contribute to AI identity KPIs and KRIs, such as unmanaged identities, privilege levels, and anomalous activity trends.
Advisory, Training & Enablement• Act as a trusted advisor on AI identity security, providing guidance on secure patterns and operational best practices.• Educate engineering and platform teams on AI identity risks, controls, and monitoring expectations.• Support internal communities of practice focused on AI security, IAM modernization, and responsible AI adoption.
Research, Experimentation & Continuous Improvement• Stay current on emerging trends in AI agents, autonomous systems, and non-human identity security.• Design and execute proofs of concept (POCs) to evaluate new AI identity security tools, controls, and monitoring approaches.• Continuously improve AI identity security through automation, integration, and control refinement.
Qualifications
• Bachelor's or Master's degree in Computer Science, Information Security, Engineering, or a related field.• Strong experience in identity and access management, security engineering, or security operations, with exposure to AI or highly automated systems.• Expertise in Least Agency frameworks, Zero Trust Architecture, Delegated Authority Management, Cryptographic Identities, and Short Lived Credentialing. • Practical experience securing non-human identities, service accounts, APIs, or machine-to-machine access.• Understanding of AI/ML architectures and how identities are used across data pipelines, model execution, and agent-based systems.• Proven ability to design, assess, and operationalize identity controls at scale.• Strong analytical and communication skills, with the ability to translate identity risk into actionable security outcomes.• Relevant certifications such as CISSP, GIAC, CIAM/IAM-related certifications, or cloud security certifications are desirable.
This role aligns to the NICE Cybersecurity Workforce Framework, with primary alignment to Identity and Access Management, Security Control Assessment, Cybersecurity Architecture, Systems Security Management, and Incident Response work roles.
Corporate Security Responsibility
All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must:
- Abide by Mastercard's security policies and practices;
- Ensure the confidentiality and integrity of the information being accessed;
- Report any suspected information security violation or breach, and
- Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.
Mastercard Pune, Mahārāshtra, IND Office



Poona Club Road, Pune, Maharashtra, India, 411001
Similar Jobs at Mastercard
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Design and oversee Wintel and VMware platform solutions across lifecycle: produce high-level designs, maintain technology roadmaps, ensure standards for performance, availability, security and manageability, assess risks, evaluate new technologies, and collaborate with delivery, engineering, and operations teams.
Top Skills:
MicrosoftNsxSccmVMwareWindowsWintel
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Lead automation and platform engineering for Unix estates (RedHat, OEL, Solaris). Build and maintain Ansible playbooks, IaC pipelines, and automation frameworks; standardize builds, patching, and compliance; integrate with Git and CI/CD; drive platform modernization, performance optimization, and operational excellence while collaborating with development, security, and third parties.
Top Skills:
AnsibleAWSAwx/TowerBashConfluenceDnsGitGitopsJIRALdapOelOvmPythonQualysRed Hat SatelliteRedhatSolarisSplunkSshTcp/IpTerraformVMware
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Designs, implements, secures and supports a multi-site network environment. Manages network projects and upgrades, troubleshoots complex issues, collaborates cross-team and with vendors, enforces PCI/DSS compliance, performs hardware baseline checks, mentors peers, and supports a 24x7 global network with occasional travel.
Top Skills:
BgpCcnpCiscoDss/PciEncryptionFirewallsLanLoad BalancingMplsSnmpSshTcp/IpVpnWan
What you need to know about the Pune Tech Scene
Once a far-out concept, AI is now a tangible force reshaping industries and economies worldwide. While its adoption will automate some roles, AI has created more jobs than it has displaced, with an expected 97 million new roles to be created in the coming years. This is especially true in cities like Pune, which is emerging as a hub for companies eager to leverage this technology to develop solutions that simplify and improve lives in sectors such as education, healthcare, finance, e-commerce and more.




