Search...

Senior Security Engineer Cloud Identity

Marqeta, Inc. logo
Marqeta, Inc.

Marqeta is a card-issuing and payment-processing technology company. Its platform helps fintechs, financial institutions, and technology companies build and manage debit, credit, prepaid, and virtual card programs.

Oakland, USA
About Marqeta, Inc.

Marqeta provides a modern, API-driven card issuing platform for embedded payment and financial-service experiences. It offers card issuing and processing, virtual cards, Just-in-Time funding, dynamic spend controls, PCI-compliant widgets, fraud and risk tools, tokenization, data insights, and program management. Its customers use the platform for consumer and commercial payments, digital banking, credit, supplier payments, expense management, and commercial banking solutions.

View jobs by Marqeta, Inc.

Skills

About the Role

You will develop and implement cloud-native identity and access management strategies. You will build and operate Identity Governance and Administration and Privileged Access Management capabilities, design certificate lifecycle management, and integrate IAM across AWS, SaaS platforms, and DevOps pipelines. You will automate provisioning and access reviews, enforce least-privilege and zero-trust controls, protect AI and ML systems, mentor junior engineers, and lead IAM-related projects.

Requirements

  • Minimum of 8 years of related experience with a Bachelor's degree, or 5 years with a Master's degree, or 3 years with a PhD, or an equivalent combination of education and experience.
  • Experience with IAM tools such as Okta, CyberArk, Ping, and SailPoint.
  • Deep knowledge of IAM in cloud-native environments, especially AWS IAM, roles, policies, permissions boundaries, and federation.
  • Proficiency with infrastructure as code, including Terraform and CloudFormation.
  • Familiarity with SAML, OAuth2, OpenID Connect, and Kerberos.
  • Knowledge of Active Directory, LDAP, and cloud-based directory alternatives.
  • Scripting skills in Python or PowerShell for IAM automation.
  • Understanding of NIST, SOC 2, and PCI DSS.
  • Experience integrating IAM into CI/CD pipelines, secrets management, and DevOps workflows.
  • Communication skills and ability to lead cross-functional teams.

Responsibilities

  • Develop and lead implementation of IAM strategies aligned with cloud-native architecture and security principles.
  • Expand and operationalize IAM across IGA, PAM, SSO, MFA, access management, secrets management, and certificate lifecycle management.
  • Automate identity provisioning, de-provisioning, and access reviews using AI tools and infrastructure as code.
  • Design IAM integrations for AWS-native services, SaaS platforms, and third-party identity tools.
  • Promote and enforce least-privilege and zero-trust principles through access controls and policy automation.
  • Mentor junior engineers and lead IAM-related projects.
  • Collaborate with Security, DevOps, and Infrastructure teams to embed IAM controls across the engineering lifecycle.
  • Refine IAM strategy based on cloud threats and compliance requirements.

Benefits

  • Annual bonuses for eligible employees.
  • Multiple health insurance options.
  • Flexible vacation time.
  • Retirement savings program with company contribution.
  • Equity in a publicly traded company.
  • Monthly remote-work stipend.
  • Annual development stipend.
  • Family-forming benefits.
  • Up to 20 weeks of parental leave.