Loading jobs…
Loading jobs…
MiQ — Toronto, Ontario
We’re seeking an experienced Senior Security Engineer with a strong passion for Identity and Access Management(IAM) and proven expertise in cloud-native environments , particularly AWS . In this role, you’ll help shape and implement modern identity strategies to secure access across all of Marqeta’s systems and services—100% cloud-based, with no data center footprint. Join us in building a secure, scalable, and frictionless IAM program where you’ll play a crucial part in: Building and evolving our Identity Governance and Administration (IGA) capabilities.
Implementing Operating Privileged Access Management (PAM) in a cloud-first (AWS-focused) environment. Designing and architecting a Certificate Lifecycle Management solution that supports cloud-native workloads. Driving integration of IAM across AWS services, SaaS platforms, and developer/DevOps pipelines.
Designing identity and access controls to protect AI/ML systems—ensuring secure access to training data, models, and inference APIs. The Impact You’ll Have Develop and lead implementation of robust IAM strategies aligned with cloud-native architecture and security principles. Expand and operationalize the IAM program across IGA, PAM, SSO, MFA, access management, secrets management, and certificate lifecycle.
Automate identity provisioning, de-provisioning, and access reviews using AI tools and infrastructure-as-code. , Okta, CyberArk). Promote and enforce least privilege and zero-trust principles through scalable access controls and policy automation.
Mentor junior engineers and serve as a technical lead for IAM-related projects. Collaborate with Security, DevOps, and Infrastructure teams to embed IAM controls across the engineering lifecycle.
Requirements
.
Who You Are
A minimum of 8 years related experience with a Bachelor’s degree; or 5 years and a Master’s degree; or a PhD with 3 years’ experience; or equivalent combination of related education and work experience. , Okta, CyberArk, Ping, SailPoint). Deep knowledge of IAM in cloud-native environments, especially AWS IAM, roles, policies, permissions boundaries, and federation.
, Terraform, CloudFormation). Familiarity with authentication and authorization protocols (SAML, OAuth2, OpenID Connect, Kerberos). Strong grasp of directory services like Active Directory, LDAP, and cloud-based alternatives.
, Python, PowerShell) to automate IAM operations. Solid understanding of compliance standards: NIST, SOC 2, PCI DSS, etc. Proven experience integrating IAM into CI/CD pipelines, secrets management, and DevOps workflows.
Excellent communication skills and ability to influence and lead cross-functional teams.
Nice To Have
, CIAM/CAMS, CyberArk Certified, Okta Certified Consultant).
Compensation
and
Benefits
Marqeta is a Flex First company which allows you to choose your best working environment, whether that be from home or at a company office. To support Flex First, we calibrate pay to a competitive value according to working location. When determining salaries, we consider several factors including, but not limited to, skills, prior experience, and work location.