5 hours ago
Remote, CanadaSenior
Responsibilities
- Develop and lead cloud-native IAM strategies aligned with security principles.
- Build and operationalize IGA, PAM, SSO, MFA, access management, secrets management, and certificate lifecycle capabilities.
- Integrate IAM with AWS services, SaaS platforms, third-party identity tools, CI/CD pipelines, and DevOps workflows.
- Automate identity provisioning, de-provisioning, access reviews, and policy enforcement using scripting, AI tools, and infrastructure-as-code.
- Design identity controls for AI/ML training data, models, and inference APIs.
- Promote least privilege and zero-trust principles through scalable access controls and policy automation.
- Mentor junior engineers and serve as a technical lead for IAM-related projects.
- Collaborate with Security, DevOps, and Infrastructure teams and refine IAM strategy based on cloud threats and compliance requirements.
Requirements
- Bachelor’s degree with 8 years of related experience, or a master’s degree with 5 years, or a PhD with 3 years, or an equivalent combination of education and work experience.
- Strong experience with IAM tools including Okta, CyberArk, Ping, and SailPoint.
- Deep knowledge of AWS IAM, roles, policies, permissions boundaries, and federation.
- Proficiency with infrastructure-as-code tools such as Terraform and CloudFormation.
- Familiarity with SAML, OAuth2, OpenID Connect, and Kerberos.
- Knowledge of Active Directory, LDAP, and cloud-based directory alternatives.
- Hands-on scripting experience with Python and PowerShell.
- Understanding of NIST, SOC 2, PCI DSS, and related compliance standards.
- Experience integrating IAM with CI/CD pipelines, secrets management, and DevOps workflows.
- Relevant certifications such as CISSP, CISM, CIAM/CAMS, CyberArk Certified, or Okta Certified Consultant are preferred.
- Experience with AWS Lambda, S3, DynamoDB, RDS, Aurora, SNS, SQS, CloudTrail, CloudWatch, CodePipeline, AWS Developer Tools, and IAM roles and permissions is preferred.
Benefits
- Remote work anywhere within Ontario or British Columbia under Marqeta’s Flexible First model.
- Full-time position with a CAD 136,800–171,000 base salary range and eligibility for annual bonuses.
- Multiple health insurance options, flexible vacation time, and additional floating holidays.
- Retirement savings program with company contribution and equity in a publicly traded company.
- Monthly remote-work stipend and annual professional development stipend.
- Family-forming benefits and generous parental leave base salary top-up.
About Marqeta
Marqeta builds an API-based card issuing and payments processing platform that lets fintechs and enterprises create virtual and physical cards, authorize transactions, and manage spend in real time. Founded in 2010 and headquartered in Oakland, California, it is a public company that generates revenue from usage-based fees and program management. Its platform powers embedded finance for brands such as Block/Cash App and Instacart, and it is listed on Nasdaq.
