8 hours ago
Remote, CanadaSenior
Responsibilities
- Develop and lead IAM strategies aligned with cloud-native architecture and security principles.
- Build and operationalize IGA, PAM, SSO, MFA, access management, secrets management, and certificate lifecycle capabilities.
- Design IAM integrations for AWS services, SaaS platforms, third-party identity tools, CI/CD pipelines, and DevOps workflows.
- Automate identity provisioning, de-provisioning, access reviews, and policy enforcement using AI tools and infrastructure-as-code.
- Design identity and access controls for AI/ML training data, models, and inference APIs.
- Promote least-privilege and zero-trust principles through scalable access controls and policy automation.
- Mentor junior engineers and serve as technical lead for IAM-related projects.
- Collaborate with Security, DevOps, and Infrastructure teams and refine IAM strategy based on cloud threats and compliance requirements.
Requirements
- At least 8 years of related experience with a bachelor’s degree, 5 years with a master’s degree, or 3 years with a PhD, or an equivalent combination of related education and work experience.
- Strong experience with IAM tools including Okta, CyberArk, Ping, and SailPoint.
- Deep knowledge of AWS IAM, roles, policies, permissions boundaries, and federation.
- Proficiency with infrastructure-as-code tools such as Terraform and CloudFormation.
- Familiarity with SAML, OAuth2, OpenID Connect, and Kerberos.
- Experience with Active Directory, LDAP, and cloud-based directory alternatives.
- Hands-on scripting experience with Python or PowerShell.
- Understanding of NIST, SOC 2, PCI DSS, and related compliance standards.
- Experience integrating IAM into CI/CD pipelines, secrets management, and DevOps workflows.
- Strong communication skills and the ability to influence and lead cross-functional teams.
- Relevant certifications such as CISSP, CISM, CIAM/CAMS, CyberArk Certified, or Okta Certified Consultant are desirable.
- Experience with AWS Lambda, S3, DynamoDB, RDS, Aurora, SNS, SQS, CloudTrail, CloudWatch, CodePipeline, AWS Developer Tools, and IAM roles and permissions is desirable.
Benefits
- Annual bonuses for eligible employees.
- Multiple health insurance options.
- Flexible vacation time and additional floating holidays.
- Retirement savings program with company contribution.
- Equity in a publicly traded company.
- Monthly remote-work stipend.
- Annual professional development stipend.
- Family-forming benefits and generous parental leave base salary top-up.
- Full-time role performed remotely anywhere within Ontario or British Columbia, Canada.
About Marqeta
Marqeta builds an API-based card issuing and payments processing platform that lets fintechs and enterprises create virtual and physical cards, authorize transactions, and manage spend in real time. Founded in 2010 and headquartered in Oakland, California, it is a public company that generates revenue from usage-based fees and program management. Its platform powers embedded finance for brands such as Block/Cash App and Instacart, and it is listed on Nasdaq.
