Senior Security Engineer
MarqetaCanada1w ago
SecurityEngineeringremotecurated-jd
Job description
Senior Security Engineer at Marqeta.
About the role
Marqeta is looking for a Senior Security Engineer focused on Identity and Access Management within a fully cloud-based environment running on AWS. You will help define and execute modern identity strategies across all company systems and services, with no on-premises data center infrastructure to manage.
Key facts
What you'll do
- Build and mature Identity Governance and Administration capabilities across the organization
- Deploy and run Privileged Access Management in an AWS-first environment
- Architect a Certificate Lifecycle Management solution tailored for cloud-native workloads
- Connect IAM systems with AWS services, SaaS applications, and developer/DevOps pipelines
- Create identity and access controls for AI/ML systems, covering training data, models, and inference APIs
- Automate user provisioning, de-provisioning, and access reviews using AI tools and infrastructure-as-code
- Implement and enforce least privilege and zero-trust principles through policy automation
- Guide junior engineers and act as technical lead on IAM initiatives
- Partner with Security, DevOps, and Infrastructure teams to embed IAM controls throughout engineering workflows
- Monitor emerging threats and compliance shifts to refine IAM strategy
Requirements
- 8 years related experience with a Bachelor's degree, or 5 years with a Master's degree, or 3 years with a PhD, or equivalent combination
- Hands-on experience with IAM platforms such as Okta, CyberArk, Ping, or SailPoint
- Deep understanding of AWS IAM including roles, policies, permissions boundaries, and federation
- Proficiency with infrastructure-as-code tools like Terraform or CloudFormation
- Working knowledge of SAML, OAuth2, OpenID Connect, and Kerberos protocols
- Familiarity with directory services including Active Directory, LDAP, and cloud-based alternatives
- Scripting ability in Python or PowerShell for automating IAM tasks
- Understanding of compliance frameworks such as NIST, SOC 2, and PCI DSS
- Track record integrating IAM into CI/CD pipelines, secrets management, and DevOps workflows
- Strong communication skills with ability to lead cross-functional teams
Nice to have
- Certifications such as CISSP, CISM, CIAM/CAMS, CyberArk Certified, or Okta Certified Consultant
- Experience with AWS services including Lambda, S3, DynamoDB, RDS, Aurora, SNS, SQS, CloudTrail, CloudWatch, CodePipeline, and AWS Developer Tools
- Background with DevOps tooling, secrets management, and CI/CD pipelines
Skills & tools
- Okta, CyberArk, Ping, SailPoint
- AWS IAM, Lambda, EC2, S3, DynamoDB, RDS, Aurora, SNS, SQS, CloudTrail, CloudWatch, CodePipeline
- Terraform, CloudFormation
- SAML, OAuth2, OpenID Connect, Kerberos
- Active Directory, LDAP
- Python, PowerShell
- SSO, MFA, PAM, IGA, secrets management, certificate lifecycle management
Practical notes
- Flex First policy allows working from home or a company office; pay is calibrated by location
- Annual bonus based on individual and company performance
- Equity in a publicly traded company
- Multiple health insurance options
- Flexible vacation time
- Retirement savings with company contribution
- Monthly remote work stipend
- Annual development dollars for growth and learning
- Family-forming benefits and up to 20 weeks of Parental Leave
- Marqeta is an equal opportunity employer and provides reasonable accommodations for applicants with disabilities