Senior Security Engineer - Cloud Identity

Marqeta

Remote

Quick summary

Work type
Remote
Location
Remote
Salary
$136,800–$171,000 / yr
Posted
51 days ago

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $173k
This role $154k
$109k most similar roles pay here $226k

This role pays less than 64% of similar roles. Most pay $142,400–$202,736 — the shaded band above. At the midpoint, this role pays about $154k versus about $173k for comparable roles.

Based on 240 similar postings.

Employer

About Marqeta

Marqeta is a modern card issuing platform that provides open API technology for businesses to create, issue, and manage customized payment cards, powering payment programs for fintech companies and enterprises. Industry: Financial Technology & Card Issuing

Marqeta currently has 27 open roles on FindRole.

Listed pay typically runs $136,100–$170,100 across 17 roles with salary data.

Most-posted roles

View all roles at Marqeta

At a glance

TL;DR · Senior Security Engineer - Cloud Identity

As a Senior Security Engineer at Marqeta, you will join our dynamic security team to build and evolve robust Identity and Access Management (IAM) strategies in a 100% cloud-based environment. Your day-to-day responsibilities include designing and implementing Privileged Access Management (PAM), Certificate Lifecycle Management solutions, and integrating IAM across AWS services and SaaS platforms. You’ll also ensure secure access to AI/ML systems and mentor junior engineers while collaborating with DevOps teams to embed IAM controls throughout the engineering lifecycle. The ideal candidate has extensive experience with IAM tools like Okta and CyberArk, proficiency in infrastructure-as-code (Terraform, CloudFormation), and a deep understanding of AWS IAM and compliance standards such as NIST and SOC 2. Additional skills in scripting languages like Python or PowerShell are highly valued to automate IAM operations effectively.

What you'll do

  • Design and implement robust IAM strategies aligned with cloud-native architecture.
  • Expand and operationalize the IAM program across various tools and platforms.
  • Automate identity provisioning, de-provisioning, and access reviews using AI and IaC.
  • Design IAM integrations for AWS services, SaaS platforms, and third-party tools.
  • Promote least privilege and zero-trust principles through scalable access controls.

What we're looking for

  • Minimum 5 years of IAM experience with a Bachelor's degree or equivalent.
  • Expertise in AWS cloud-native IAM tools and technologies.
  • Proficiency in infrastructure-as-code practices (Terraform, CloudFormation).
  • Strong understanding of compliance standards like NIST, SOC 2, PCI DSS.
  • Experience integrating IAM into CI/CD pipelines and DevOps workflows.
  • Hands-on scripting skills for automating IAM operations (Python, PowerShell).

More like this

Similar roles

Senior Cloud Security Engineer

Lam Research

Fremont, CA +2 93 days ago $137,000$287,000
Azure Defender for Cloud Wiz Orca MSSentinel ServiceNow CI/CD KPI development Executive reporting Cloud security posture management Security architecture assessments Vulnerability management Microsoft Azure
Hybrid

Senior Associate, Cloud Security Engineer

Northern Trust

Chicago, IL 2 days ago $114,500$194,700
AWS Azure Terraform Python GitHub Actions CIS NIST 800-53 Wiz Microsoft Defender for Cloud Git CI/CD CSPM Infrastructure as Code DevOps

Cloud Security Engineer

Booz Allen Hamilton

Reston, VA 10 days ago $99,000$225,000
Risk Management Framework Terraform CloudFormation Bicep AWS Azure Google Cloud Platform CI/CD Agile Python JavaScript PostgreSQL MongoDB Docker Kubernetes Prometheus Grafana GitLab Jenkins

Cloud Security Engineer

Booz Allen Hamilton

Fort Belvoir, VA 9 days ago $99,000$225,000
AWS Azure Microsoft Sentinel Defender PowerShell Bash DevSecOps RMF DoD STIG CI/CD Git Red Hat Enterprise Linux RHEL Windows System Administration Agile

Lead Associate Principal, Security Engineering

The OCC

Chicago +1 115 days ago $145,200$236,700
CyberArk HashiCorp Vault ActiveDirectory OAuth2.0 OIDC AWSIAM k8s LDAPS Kerberos Terraform Ansible Jenkins CI/CD GoLang Bash Python PowerShell HSM PKI AI OpenAICodex ClaudeCode GeminiCLI
Hybrid