Senior Security Engineer - Cloud Identity

Marqeta Marqeta · Fintech · Canada · Remote · CyberSecurity

Seeking a Senior Security Engineer with expertise in Identity and Access Management (IAM) and cloud-native environments (AWS) to secure access across Marqeta's systems. The role involves building and evolving IGA and PAM capabilities, designing certificate lifecycle management, integrating IAM across AWS services and SaaS platforms, and specifically designing identity and access controls to protect AI/ML systems. Responsibilities include developing IAM strategies, operationalizing the IAM program, automating provisioning/de-provisioning using AI tools, designing integrations, promoting least privilege, mentoring junior engineers, and collaborating with other teams.

What you'd actually do

  1. Designing identity and access controls to protect AI/ML systems—ensuring secure access to training data, models, and inference APIs.
  2. Automate identity provisioning, de-provisioning, and access reviews using AI tools and infrastructure-as-code.
  3. Design IAM integrations for AWS-native services (Lambda, EC2, S3, IAM, etc.), SaaS platforms, and third-party identity tools (e.g., Okta, CyberArk).
  4. Promote and enforce least privilege and zero-trust principles through scalable access controls and policy automation.
  5. Mentor junior engineers and serve as a technical lead for IAM-related projects.

Skills

Required

  • 8 years related experience with a Bachelor’s degree; or 5 years and a Master’s degree; or a PhD with 3 years’ experience; or equivalent combination of related education and work experience.
  • Strong experience with IAM tools (e.g., Okta, CyberArk, Ping, SailPoint).
  • Deep knowledge of IAM in cloud-native environments, especially AWS IAM, roles, policies, permissions boundaries, and federation.
  • Proficiency in infrastructure-as-code (e.g., Terraform, CloudFormation).
  • Familiarity with authentication and authorization protocols (SAML, OAuth2, OpenID Connect, Kerberos).
  • Strong grasp of directory services like Active Directory, LDAP, and cloud-based alternatives.
  • Hands-on skills in scripting (e.g., Python, PowerShell) to automate IAM operations.
  • Solid understanding of compliance standards: NIST, SOC 2, PCI DSS, etc.
  • Proven experience integrating IAM into CI/CD pipelines, secrets management, and DevOps workflows.
  • Excellent communication skills and ability to influence and lead cross-functional teams.

Nice to have

  • Relevant certifications such as CISSP, CISM, or IAM-specific credentials (e.g., CIAM/CAMS, CyberArk Certified, Okta Certified Consultant).
  • Experience with AWS technologies such as Lambda, S3, DynamoDB, RDS, Aurora, SNS, SQS, CloudTrail, CloudWatch, Code Pipeline, AWS Developer Tools, and IAM roles and permissions
  • Experience with DevOps tools and practices, including secrets management and CICD pipelines

What the JD emphasized

  • AWS
  • IAM
  • cloud-native environments
  • Identity and Access Management(IAM)
  • AI/ML systems