Principal Security Engineer, Product & AI
As Marqeta’s Principal Security Engineer you will serve as the technical lead across our security engineering function. This role combines three critical responsibilities: leading product security engineering across our payment platform, building our AI security program as we scale generative AI and ML capabilities, and providing security architecture oversight across enterprise and infrastructure security.
Your primary focus will be product security and AI—threat modeling payment features, securing APIs, building genAI controls, and ensuring AI-powered capabilities ship securely. You'll also own the security architecture function and provide technical oversight for infrastructure security—endpoint protection, network security, VPN, and enterprise security controls—ensuring coherent security standards across everything we build and operate.
You'll partner closely with Product Security, Infrastructure Security, and Security Operations teams and serve as the security voice in our Model Risk Office. This is an individual contributor role with mentoring responsibilities and broad technical influence across the security, engineering, and business technology organizations.
We work Flexible First. This role can be performed remotely anywhere within the United States or from our Oakland office. We’d love for you to join us!
You'll have the chance to:
- Lead product security engineering for our payment platform—owning threat modeling, security architecture review, secure SDLC practices, and API security across the engineering organization
- Help mature our AI security programdeveloping genAI controls, securing ML pipelines, and working alongside the Model Risk Office for model evaluations.
- Provide security architecture oversight across infrastructure and enterprise security—endpoint, network, VPN, and corporate security controls—ensuring technical standards are coherent across all security domains
- Shape how security engineering scales across the organization through tooling, frameworks, security champions engagement, and engineering partnerships
The Impact You'll Have:
Product Security:
- Conduct security architecture reviews and threat modeling for new product features, APIs, and service integrations across the payment platform
- Define and maintain secure development lifecycle practices including secure code review standards, API security patterns, and authentication/authorization frameworks
- Develop self-service security tooling and developer-facing guardrails that reduce friction while maintaining security posture
AI Security:
- Lead security strategy and risk assessment for AI/ML systems including customer-facing AI products, fraud detection models, LLM integrations, and recommendation systems
- Build genAI security controls—prompt injection prevention, output filtering, model validation, and monitoring frameworks
- Perform security assessments of AI/ML model architectures, training pipelines, inference endpoints, and deployment infrastructure
- Evaluate and operationalize AI-powered security tools (e.g., AI-assisted code review, anomaly detection, automated threat intelligence) to improve security operations
Enterprise & Infrastructure Security Oversight:
- Provide technical oversight for infrastructure security including endpoint protection, network security, VPN, and enterprise security controls
- Ensure coherent security architecture standards across product, cloud infrastructure, and corporate environments
- Drive technical decisions for security tooling and controls that span the full environment—from developer laptops to production infrastructure
Across All Domains:
- Partner across Product Security, Infrastructure Security, and Security Operations teams as well as engineering, data science, and compliance
- Mentor security engineers and cross-functional teams, raising the organization's overall security engineering maturity
- Communicate security risks and strategy to executive and board-level audiences
Who You Are:
- 10+ years of security engineering experience with demonstrated technical leadership across multiple security domains; or equivalent combination of education and experience
- Deep product security expertise: threat modeling, security architecture review, secure code review, API security, authentication/authorization design, and secure SDLC practices
- Experience with or strong interest in AI/ML security—understanding of risks including adversarial attacks, model poisoning, prompt injection, data privacy, and AI supply chain threats. We want someone who is genuinely excited about AI technology and wants to secure it, not just govern it
- Broad security fluency across infrastructure and enterprise security—endpoint protection, network security, identity, and cloud security—even if your deepest expertise is in application and product security
- Experience working in cloud-native environments (AWS preferred) with familiarity across AI/ML services (Bedrock, SageMaker, etc.)
- Proven ability to build security frameworks, tools, and programs from the ground up
- Strong programming skills in at least one language (Python, Java, Go, or similar) with the ability to read and review code across multiple languages
- Experience with security assessment methodologies and risk management frameworks
- Working knowledge of compliance and control frameworks relevant to financial services (PCI DSS, SOX, SOC2, NIST CSF)
- Ability to communicate complex security risks to both technical and executive audiences
Nice to Have:
- Financial services or fintech experience strongly preferred
- Experience securing payment processing systems, card issuing platforms, fraud detection models, or transaction monitoring infrastructure
- Hands-on experience with LLM security: prompt injection mitigation, output filtering, RAG security, agent security patterns
- Experience with enterprise security platforms (EDR, SIEM, identity providers, network security tools)
- Experience with ML frameworks (PyTorch, TensorFlow) or background in data science / machine learning engineering
- Knowledge of AI governance, model risk management practices, and emerging AI regulatory frameworks (EU AI Act, NIST AI RMF)
- Background in supply chain security, CI/CD pipeline security, or secure software composition analysis
- Experience with privacy-preserving ML techniques (differential privacy, federated learning, secure multi-party computation)
- Experience with Kubernetes, containerized workloads, and Infrastructure as Code (Terraform)
- CISSP, CCSP, CISA, or other relevant security certifications
- Experience building and scaling security programs in high-growth environments
Typical Process:
- Application Submission
- Recruiter phone call
- Hiring manager video call
- Virtual “Onsite” consisting of 5-6, 45-60 min video calls
- Offer!
At this point, we hope you're feeling excited about the role. You're encouraged to apply even if your experience doesn't precisely match the job description. Your skills and passion will stand out—and set you apart—especially if your career has taken some extraordinary twists and turns. We know the confidence gap and imposter syndrome can get in the way of meeting spectacular candidates, so again, don’t hesitate to apply — we’d love to hear from you.
Compensation and Benefits:
Marqeta is a Flex First company which allows you to choose your best working environment, whether that be from home or at a company office. To support Flex First, we calibrate pay to a competitive value according to working location. Compensation is aligned according to three tiers within the United States:
- National: A baseline tier that applies to most of the geographic territory of the United States.
- Premium: Slightly elevated from the National tier, and oriented toward a narrower set of higher cost-of-living areas, such as Los Angeles CA and Seattle WA
- Premium Plus: A tier for the most expensive working areas, like the San Francisco Bay area and New York City.
Visit this page or consult with a Recruiter to determine which tier would be applicable to you.
When determining salaries, we consider several factors including, but not limited to, skills, prior experience, and work location. The new-hire base salary range for this position is:
- National: $218,300 - $272,900
- Premium: $236,200 - $295,300
- Premium Plus: $256,800 - $321,000
We also believe in recognizing the contributions of our people. That's why we award annual bonuses to eligible employees, rewarding both individual performance and the success of the entire company.
Along with monetary compensation, Marqeta offers
- Multiple health insurance options
- Flexible time off – take what you need
- Retirement savings program with company contribution and after tax contributions
- Equity in a publicly-traded company and an Employee Stock Purchase Program
- Family-forming benefits, fertility support, and up to 20 weeks of Parental Leave
- Free therapy sessions, financial and professional coaching, and legal advice
- Monthly stipend to support our remote work model
- Annual “development dollars” to support our people growth and development
- Through Flex First, the freedom to live and work wherever you and your family thrive
About Marqeta
Marqeta is on a mission to change the way money moves. We’re one of the earliest enablers of embedded finance, a market opportunity sized up in the trillions. Our card issuing platform provides unprecedented flexibility and control for companies to issue cards, authorize transactions, and manage payment operations in real time. Marqeta is powering the most well known brands in the new economy (Block, Cash App, Affirm, Instacart, Doordash, Uber, Walmart, etc). You don’t need to be a Payments expert to join the Marqeta Team, let us help you with that. This is the opportunity of a lifetime to work with innovators around the world and unlock equitable financial access for all.
Marqeta’s Values
– Solve for the Customer: With a deep understanding of our customers' business and empathy for their needs, we deliver products and services that drive their success. Earning and keeping their trust guides everything we do.
– Do What's Right: Knowing businesses and livelihoods depend on us, we pursue solutions that disrupt responsibly and deliver high-quality results that our customers count on. We own our work from start to finish.
– Simplify and Innovate: We approach challenges with curiosity and take smart risks. Innovation comes from finding better, simpler ways to achieve extraordinary outcomes.
– Win as a Team: We succeed together by embracing diverse perspectives and pushing each other to raise the bar. We lead with humility and set aside hierarchy to work as a team.
– Make it Count: We drive forward with focus and agility. With a sense of urgency and purpose, we get the job done, and done right.
Equal Employment Opportunity, Accommodations and Privacy
Marqeta is an equal opportunity employer committed to an inclusive workplace that fosters belonging. We do not discriminate based on race, color, religion, sex (including pregnancy, lactation, childbirth, or related medical conditions), veteran status or uniformed service member status, age, national origin or ancestry, citizenship or immigration status, physical or mental disability, gender identity, gender expression, sexual orientation, genetic information (including testing or characteristics) or any other characteristic protected by applicable law. We also consider qualified applicants with criminal histories, consistent with legal requirements.
Marqeta endeavors to make reasonable accommodations for applicants with disabilities. If you are an individual with a disability and require a reasonable accommodation to submit this application, complete any pre-employment testing, or otherwise participate in the employee selection process, please submit this form with your specific accommodation request.
Personal data that is provided as part of the application and recruitment process is processed in accordance with the Applicant Privacy Notice. Additional information for California residents can be found here.
Create a Job Alert
Interested in building your career at Marqeta? Get future opportunities sent straight to your email.
Apply for this job
*
indicates a required field
