🏢
Marqeta
Principal Security Engineer, Product & AI
Job Description
ABOUT THE ROLE
As Marqeta's Principal Security Engineer, you will serve as the technical lead across our security engineering function. This role combines three critical responsibilities: leading product security engineering across our payment platform, building our AI security program as we scale generative AI and ML capabilities, and providing security architecture oversight across enterprise and infrastructure security.
WHAT YOU'LL DO
Your primary focus will be product security and AI—threat modeling payment features, securing APIs, building genAI controls, and ensuring AI-powered capabilities ship securely. You'll also own the security architecture function and provide technical oversight for infrastructure security—endpoint protection, network security, VPN, and enterprise security controls—ensuring coherent security standards across everything we build and operate. You'll partner closely with Product Security, Infrastructure Security, and Security Operations teams and serve as the security voice in our Model Risk Office.
WHAT YOU'LL NEED
- 10+ years of security engineering experience with demonstrated technical leadership across multiple security domains; or equivalent combination of education and experience
- Deep product security expertise: threat modeling, security architecture review, secure code review, API security, authentication/authorization design, and secure SDLC practices
- Experience with or strong interest in AI/ML security—understanding of risks including adversarial attacks, model poisoning, prompt injection, data privacy, and AI supply chain threats
- Broad security fluency across infrastructure and enterprise security—endpoint protection, network security, identity, and cloud security—even if your deepest expertise is in application and product security
- Experience working in cloud-native environments (AWS preferred) with familiarity across AI/ML services (Bedrock, SageMaker, etc.)
- Proven ability to build security frameworks, tools, and programs from the ground up
- Strong programming skills in at least one language (Python, Java, Go, or similar) with the ability to read and review code across multiple languages
- Experience with security assessment methodologies and risk management frameworks
- Working knowledge of compliance and control frameworks relevant to financial services (PCI DSS, SOX, SOC2, NIST CSF)
- Ability to communicate complex security risks to both technical and executive audiences
WHY REMOTE
We work Flexible First. This role can be performed remotely anywhere within the United States or from our Oakland office.