Senior Security Engineer - Identity and Access Management @Marqeta
All Others
Salary cad 136,800 - 1..
Remote Location
Employment Type full-time
Posted 2wks ago

[Hiring] Senior Security Engineer - Identity and Access Management @Marqeta

2wks ago - Marqeta is hiring a remote Senior Security Engineer - Identity and Access Management. 💸 Salary: cad 136,800 - 171,000 per year 📍Location: Canada

Role Description

We’re seeking an experienced Senior Security Engineer with a strong passion for Identity and Access Management (IAM) and proven expertise in cloud-native environments, particularly AWS. In this role, you’ll help shape and implement modern identity strategies to secure access across all of Marqeta’s systems and services—100% cloud-based, with no data center footprint.

This role can be performed remotely anywhere within Ontario or British Columbia, Canada. Join us in building a secure, scalable, and frictionless IAM program where you’ll play a crucial part in:

  • Building and evolving our Identity Governance and Administration (IGA) capabilities.
  • Implementing & Operating Privileged Access Management (PAM) in a cloud-first (AWS-focused) environment.
  • Designing and architecting a Certificate Lifecycle Management solution that supports cloud-native workloads.
  • Driving integration of IAM across AWS services, SaaS platforms, and developer/DevOps pipelines.
  • Designing identity and access controls to protect AI/ML systems—ensuring secure access to training data, models, and inference APIs.

The Impact You’ll Have:

  • Develop and lead implementation of robust IAM strategies aligned with cloud-native architecture and security principles.
  • Expand and operationalize the IAM program across IGA, PAM, SSO, MFA, access management, secrets management, and certificate lifecycle.
  • Automate identity provisioning, de-provisioning, and access reviews using AI tools and infrastructure-as-code.
  • Design IAM integrations for AWS-native services (Lambda, EC2, S3, IAM, etc.), SaaS platforms, and third-party identity tools (e.g., Okta, CyberArk).
  • Promote and enforce least privilege and zero-trust principles through scalable access controls and policy automation.
  • Mentor junior engineers and serve as a technical lead for IAM-related projects.
  • Collaborate with Security, DevOps, and Infrastructure teams to embed IAM controls across the engineering lifecycle.
  • Stay ahead of emerging trends and continuously refine IAM strategy based on evolving cloud threats and compliance requirements.

Qualifications

  • A minimum of 8 years related experience with a Bachelor’s degree; or 5 years and a Master’s degree; or a PhD with 3 years’ experience; or equivalent combination of related education and work experience.
  • Strong experience with IAM tools (e.g., Okta, CyberArk, Ping, SailPoint).
  • Deep knowledge of IAM in cloud-native environments, especially AWS IAM, roles, policies, permissions boundaries, and federation.
  • Proficiency in infrastructure-as-code (e.g., Terraform, CloudFormation).
  • Familiarity with authentication and authorization protocols (SAML, OAuth2, OpenID Connect, Kerberos).
  • Strong grasp of directory services like Active Directory, LDAP, and cloud-based alternatives.
  • Hands-on skills in scripting (e.g., Python, PowerShell) to automate IAM operations.
  • Solid understanding of compliance standards: NIST, SOC 2, PCI DSS, etc.
  • Proven experience integrating IAM into CI/CD pipelines, secrets management, and DevOps workflows.
  • Excellent communication skills and ability to influence and lead cross-functional teams.

Requirements

  • Relevant certifications such as CISSP, CISM, or IAM-specific credentials (e.g., CIAM/CAMS, CyberArk Certified, Okta Certified Consultant).
  • Experience with AWS technologies such as Lambda, S3, DynamoDB, RDS, Aurora, SNS, SQS, CloudTrail, CloudWatch, Code Pipeline, AWS Developer Tools, and IAM roles and permissions.
  • Experience with DevOps tools and practices, including secrets management and CICD pipelines.

Benefits

  • Multiple health insurance options.
  • Flexible vacation time with additional floating holidays.
  • Retirement savings program with company contribution.
  • Equity in a publicly-traded company.
  • Monthly stipend to support our remote work model.
  • Annual development stipend to support our people growth and development.
  • Family-forming benefits and generous parental leave base salary top-up.
Before You Apply
️
remote Be aware of the location restriction for this remote position: Canada
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Security Engineer - Identity and Access Management @Marqeta
All Others
Salary cad 136,800 - 1..
Remote Location
Employment Type full-time
Posted 2wks ago
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 120,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Canada
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 120,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 120,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 124,612+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first, direct to employer

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later