07 Aug
|
Marqeta
|
Toronto
Senior Security Engineer at Marqeta.
About the role
Marqeta is in search of a Senior Security Engineer who will specialize in Identity and Access Management (IAM) within a fully cloud-based infrastructure utilizing AWS. This position involves the development and execution of contemporary identity strategies across all organizational systems and services, without the burden of managing any on-premises data center infrastructure.
Key facts
Location: Toronto, Canada or Vancouver, Canada Engagement: Full-time, Flex First (remote or office) Salary: CAD 136,800 - 171,000 base Manager: Sandeep Chotwani Recruiter: Kayla Osuna
What you'll do
- Develop and enhance Identity Governance and Administration capabilities throughout the organization.
- Implement and manage Privileged Access Management solutions in an AWS-centric environment.
- Design a Certificate Lifecycle Management system specifically suited for cloud-native applications.
- Integrate IAM systems with AWS services, SaaS platforms, and developer/DevOps pipelines.
- Establish identity and access controls for AI and machine learning systems, encompassing training datasets, models, and inference APIs.
- Automate user provisioning, de-provisioning, and access audits utilizing AI technologies and infrastructure-as-code methodologies.
- Apply and uphold principles of least privilege and zero-trust through automated policy enforcement.
- Mentor junior engineers and serve as the technical lead on IAM projects.
- Collaborate with Security, DevOps, and Infrastructure teams to incorporate IAM controls seamlessly into engineering workflows.
- Stay informed about emerging threats and regulatory changes to continuously refine IAM strategies.
Requirements
- A minimum of 8 years of relevant experience with a Bachelor's degree, or 5 years with a Master's degree, or 3 years with a PhD, or an equivalent combination of education and experience.
- Practical experience with IAM solutions such as Okta, CyberArk, Ping, or SailPoint.
- Comprehensive knowledge of AWS IAM, including roles, policies, permission boundaries, and federation concepts.
- Proficiency in infrastructure-as-code tools like Terraform or CloudFormation.
- Familiarity with protocols such as SAML, OAuth2, OpenID Connect, and Kerberos.
- Understanding of directory services like Active Directory, LDAP, and their cloud-based alternatives.
- Scripting skills in Python or PowerShell for automating IAM-related tasks.
- Knowledge of compliance standards such as NIST, SOC 2, and PCI DSS.
- Proven experience in integrating IAM within CI/CD pipelines, secrets management, and DevOps practices.
- Excellent communication skills with the ability to lead cross-functional teams effectively.
Nice to have
- Professional certifications such as CISSP, CISM, CIAM/CAMS, CyberArk Certified, or Okta Certified Consultant.
- Experience with AWS services including Lambda, S3, DynamoDB, RDS, Aurora, SNS,
SQS, CloudTrail, CloudWatch, CodePipeline, and AWS Developer Tools.
- Familiarity with DevOps tools, secrets management solutions, and CI/CD pipeline methodologies.
Skills & tools
- IAM platforms: Okta, CyberArk, Ping, SailPoint
- AWS services: IAM, Lambda, EC2, S3, DynamoDB, RDS, Aurora, SNS, SQS, CloudTrail, CloudWatch, CodePipeline
- Infrastructure-as-code tools: Terraform, CloudFormation
- Protocols: SAML, OAuth2, OpenID Connect, Kerberos
- Directory services: Active Directory, LDAP
- Scripting languages: Python, PowerShell
- Security concepts: SSO, MFA, PAM, IGA, secrets management, certificate lifecycle management
Practical notes
- The Flex First policy allows employees to work either from home or in a company office, with compensation adjusted according to location.
- An annual bonus is available based on individual and company performance metrics.
- Employees will receive equity in a publicly traded company.
- A variety of health insurance plans are offered to cater to different needs.
- Flexible vacation policies are in place to support work-life balance.
- Retirement savings plans with company contributions are available.
- A monthly stipend for work from home expenses is provided.
- Annual development funds are allocated for professional growth and learning opportunities.
- Family-forming advantages and up to 20 weeks of parental leave are included.
Marqeta is committed to being an equal opportunity employer and offers reasonable accommodations for applicants with disabilities.
#J-18808-Ljbffr
📌 Senior Security Engineer (Toronto)
🏢 Marqeta
📍 Toronto