Sr. SW Engineer - AI Security

VisaAshburn, VirginiaOn-siteFull-timeSenior, 5–8 yearsListed 2 hours ago

Apply now

About this role

About Us
Visa is a world leader in payments technology, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories, dedicated to uplifting everyone, everywhere by being the best way to pay and be paid.

At Visa, you'll have the opportunity to create impact at scale — tackling meaningful challenges, growing your skills and seeing your contributions impact lives around the world.

Join Visa and do work that matters – to you, to your community, and to the world. Progress starts with you.

Job Description

Visa's Cyber Analytics and AI Innovation organization builds the security capabilities that let the enterprise adopt Generative AI responsibly and safely. This is an innovation-oriented team: our charter evolves as GenAI threats evolve, and our core service is a growing suite of guardrail services that protects AI applications, LLMs, agents, tools, and data interactions from AI-specific threats.

As a Senior Software Engineer, GenAI Security, you'll be a hands-on individual contributor who owns problems end-to-end — from technical design and prototyping through production deployment, monitoring, and support. Because this is an innovation org, you won't be boxed into one feature lane: your work may span detection engines, agent and tool security, evaluation frameworks, or platform integration as priorities shift, and you'll often be handed a problem with real latitude in how you solve it rather than a fixed spec.

Essential Functions

- Build and operate GenAI security systems: design, build, deploy, and maintain production services and APIs that detect and mitigate risks such as prompt injection, jailbreak attempts, sensitive-data exposure, and unauthorized or unexpected tool/agent behavior — spanning LLMs, agents, tools, APIs, MCP servers, plugins, and enterprise data sources. Apply deterministic, policy-driven controls where predictable enforcement matters, and model-based approaches where judgment is needed.
- Measure and improve: build automated evaluation, testing, and feedback loops, plus production observability (logging, metrics, tracing, alerting, dashboards), so detection quality, latency, and false-positive/negative rates stay visible and auditable — then use that telemetry to close gaps.
- Integrate and scale: containerize and deploy services with Docker and Kubernetes, and integrate GenAI security capabilities into enterprise applications, model gateways, developer workflows, and cloud or on-premises platforms.
- Practice secure engineering: apply threat modeling, secure coding, dependency and secrets management, code review, and vulnerability remediation; participate in architecture and design reviews and document decisions, interfaces, and operational requirements clearly.
- Explore and influence: evaluate emerging GenAI security technologies and frameworks through structured proofs of concept, provide technical guidance to other engineers, and help shape the team's engineering standards and practices.
- Collaborate and operate: work with engineers, researchers, architects, product managers, and infrastructure teams to translate emerging AI-security risks into product capabilities, and support production releases, incident analysis, and defect resolution.

Position Location

This position may be based in Ashburn, Virginia, under Visa's hybrid working model. The expectation for days in the office will be confirmed by the hiring manager.

No relocation budget is available for this position.

Visa requires at least 3 days in office, expectations of these days will be confirmed by your Hiring Manager.

Qualifications

Basic Qualifications

- 2+ years of relevant work experience and a Bachelors degree, OR 5+ years of relevant work experience
- Professional software-development experience building backend services, APIs, platforms, or distributed applications.
- Experience developing production software using Python, Java, Go, or another modern programming language.
- Experience with cybersecurity, secure software development, application security, cloud security, AI security, or a closely related discipline.

Preferred Qualifications

- Advanced degree (M.S. or Ph.D.) in computer science, applied math, or a related field.
- Strong proficiency in Python and at least one additional language such as Java, Go, or Rust, with solid grounding in distributed-systems fundamentals — software architecture, design patterns, data structures, concurrency, API design, and performance optimization — applied to highly available RESTful, asynchronous, or event-driven services.
- Hands-on experience with Generative AI application architectures, including LLM APIs, embeddings, agentic workflows, tool calling, model gateways, and orchestration frameworks such as LangChain, LangGraph, Semantic Kernel, AutoGen, or LlamaIndex, along with familiarity with MCP, AI-agent tools, plug-ins, or similar emerging integration patterns.
- Understanding of GenAI-specific security risks (prompt injection, jailbreaking, sensitive-data exposure, insecure output handling, unauthorized tool use, data exfiltration) and hands-on experience implementing controls such as input validation, output filtering, policy enforcement, access control, audit logging, rate limiting, and secrets management.
- Knowledge of secure software-development lifecycle practices — threat modeling, vulnerability management, and application-security principles — applied in day-to-day engineering.
- Experience developing evaluation frameworks or test suites for LLM applications, including adversarial or red-team testing, regression testing, and false-positive/false-negative analysis.
- Experience with cloud-native deployment and operations — Docker, Kubernetes, CI/CD, infrastructure automation, and observability platforms (such as Splunk, Elasticsearch, or Grafana) for metrics, logging, tracing, alerting, and production troubleshooting.
- Familiarity with GPU-backed inference, CUDA, NVIDIA technologies, or model-serving frameworks is beneficial but not required.
- Ability to evaluate new technologies objectively against security, quality, latency, scalability, maintainability, and operational-readiness criteria, and to work independently on ambiguous, complex assignments.
- Clear written and verbal communication skills, including the ability to explain technical and security tradeoffs to different audiences, and experience collaborating effectively in Agile, cross-functional environments spanning engineering, cybersecurity, infrastructure, research, and product.

Information for US Applicants
For roles located in the US, the estimated salary range for this position is $118,700.00 to $ 183,600.00 USD per year, which may include potential sales incentive payments (if applicable). Salary may vary depending on job-related factors which may include knowledge, skills, experience, and location. In addition, this position may be eligible for bonus and equity.Visa has a comprehensive benefits package for which this position may be eligible that includes Medical, Dental, Vision, 401(k), FSA/HSA, Life Insurance, Paid Time Off, and Wellness Program.

Work Hours

Varies upon the needs of the department.

Travel Requirements

This position requires travel 5-10% of the time.

Mental/Physical Requirements

This position will be performed in an office setting. The position will require the incumbent to sit and stand at a desk, communicate in person and by telephone, frequently operate standard office equipment, such as telephones and computers.

Visa is an EEO Employer
Qualified applicants will receive consideration for employment without regard to race, color religion, sex, national origin, sexual orientation, gender identity, disability or protect veteran status. Visa will also consider for employment qualified applicants with criminal histories in a manner consistent with the EEOC guidelines and applicable local law.