Mastercard
Lead Response Technology and Automation Security Engineer
About This Role
About Mastercard
Mastercard Inc. is a prominent American multinational technology company that specializes in global payment card services. Founded in 1966 and headquartered in Purchase, New York, Mastercard connects consumers, financial institutions, merchants, governments, and businesses across over 210 countries and territories. The company operates a capital-light model focused on processing electronic payments, rather than issuing cards or providing consumer loans directly. Mastercard offers a wide range of payment solutions, including core payment processing through the Mastercard Network, which handles transactions for credit, debit, and prepaid cards. The company also provides digital and real-time payment services, security and fraud prevention solutions, and data analytics and advisory services. With a diverse customer base that includes banks, merchants, consumers, and government entities, Mastercard facilitates secure and accessible financial transactions worldwide, serving more than 37 million businesses globally.
Security at Mastercard
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
“The stated approach is developer-centric enablement rather than security gatekeeping: security engineers advise developers and architects, provide coaching and real-time guidance, and embed security into normal workflows. Mastercard job materials explicitly describe security as enhancing rather than hindering delivery, while governance remains present through policy, regulatory requirements, design and architecture reviews, threat modeling, and tracked security user stories. The stated risk approach is evidence-based and risk-oriented, using exploitability, reachability, data sensitivity, business criticality, external exposure, dependency paths, compensating controls, and risk appetite. Publicly stated goals include validating AI-generated findings, reducing false positives, improving missing context and model precision, reducing manual effort, standardizing workflows, and increasing the quality and speed of vulnerability closure. No direct contradiction was found between developer enablement and governance. Information not publicly available for a formal AppSec mission statement, a named reporting chain below the Chief Security Officer, or published AppSec remediation SLAs.”
Security Team
As of, Mastercard publicly describes a worldwide Business Security Enablement function that partners with technology, engineering, product, architecture, operations, and business teams. Public profiles identify Michael Lashlee (Chief Security Officer), Ann Johnson (Executive Vice President, Security Solutions), Joseph Arcelo (Director, Information Security Operations), and Asheesh Agarwal (Director, Information Security Engineering). The public evidence does not establish a separate AppSec reporting line or employee count. Team-size estimate: Information not publicly available. The Cyber and Corporate Security careers page listed 19 total security-category openings; this is not a team-size measure. Four active AppSec-relevant postings were identified: Lead Program Security Engineer (R-276394), Principal Security Engineer (R-289452), Principal Vulnerability Analyst (R-282738), and Senior Information Security Engineer (R-278352). Repeated requirements include secure design, threat modeling, developer enablement, cloud and API security, DevSecOps and CI/CD, vulnerability validation, risk-based prioritization, and remediation tracking. All leader descriptions are.
Key Initiatives
Security Champions: Evidence Found. The Lead Program Security Engineer role requires partnering with security champions and delivering targeted training. Shift-left and secure SDLC practices include embedding secure-coding, data-protection, and IAM requirements into the SDLC; using CI/CD and automated deployments; and applying security guidance from discovery through deployment. Secure SDLC ceremonies and artifacts include design and code reviews, solution-architecture approvals, threat-model reviews, third-party technology reviews, technical-architecture-diagram approvals, Network-as-a-Service approvals, vulnerability-management support, and security user stories tracked to closure during PI Planning. Vulnerability intake includes Mastercard's ongoing public bug-bounty program and AI-generated findings. The AI Vulnerability Operations workflow validates code context, dependency data, architecture, runtime exposure, exploitability, reachability, business criticality, and compensating controls; classifies true positives, false positives, duplicates, accepted risks, and configuration or dependency issues; confirms ownership; provides remediation guidance; verifies fixes through retesting and supporting evidence; and records residual risk and closure evidence. The bug-bounty program publicly reports a 25-day validation measure and uses priority adjustments based on likelihood or impact. Recent initiatives within the six months ending include AI Vulnerability Operations, Mastercard's March 2026 foundation-model work for cyber defenses, the June 2026 Cyber Pulse report, and active bug-bounty activity in August 2026. No public evidence was found of a named AppSec scanner rollout, a formal published remediation SLA, or a specific AppSec policy change during this period.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.
Interested in this role?
Apply on LinkedIn