Marqeta

Senior Security Engineer - Vulnerability & Data/SaaS Security

Marqeta$136K — $171K *
US-Anywhere
+ 2 other locationsRemote
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in security engineering with hands-on expertise in vulnerability management, cloud security, or application/SaaS security programs.
  • Direct experience with tools like Tenable, Snyk, StackHawk for vulnerability and application security.
  • Proficient with CSPM tools, particularly for securing AWS infrastructure and managing misconfigurations.
  • Knowledge of DSPM and SSPM tools such as Sentra and Reco for data and SaaS security governance.
  • Strong scripting skills in Python and experience with REST APIs to integrate security tools and automate workflows.
  • Familiarity with compliance frameworks relevant to regulated environments, including PCI DSS and SOC 2.
  • Excellent communication skills to translate technical findings into business terms for various stakeholders.

Responsibilities

  • Oversee the entire vulnerability management lifecycle, ensuring prompt remediation and compliance with SLAs.
  • Implement and manage cloud security posture monitoring for AWS infrastructure, addressing misconfigurations and control violations.
  • Lead the Data Security Posture Management (DSPM) program for sensitive data monitoring and classification.
  • Automate ticketing and remediation workflows to streamline incident response across the security landscape.
  • Develop and maintain API integrations between security tools and other systems to enhance operational efficiency.
  • Define and track key performance indicators (KPIs) for all security programs, presenting metrics to executive leadership.
  • Create executive dashboards that translate technical findings into business-relevant narratives.

Benefits

  • Multiple health insurance options to suit diverse needs.
  • Flexible vacation policy with additional floating holidays enhancing work-life balance.
  • Retirement savings plan with company contributions to support future financial goals.
  • Equity offerings in a publicly-traded company, aligning employee interests with the company's success.
  • Monthly stipend for remote work-related expenses to support a productive work environment.
  • Annual development stipend to foster personal and professional growth opportunities.
  • Comprehensive parental leave benefits, including up to 20 weeks of leave for new parents.
Full Job Description
The Senior Security Engineer owns the day-to-day operation, integration, and continuous improvement of Marqeta's vulnerability management, cloud security posture, and data/SaaS security programs. This role sits at the center of the security tooling ecosystem, Tenable, Snyk, StackHawk, CrowdStrike, Sentra, Reco, and ArmorCode, correlating findings across platforms, driving remediation, and translating technical risk into metrics and reporting that inform both engineering teams and executive leadership.

We work Flexible First. This role can be performed remotely anywhere within Ontario or British Columbia, Canada. We'd love for you to join us!

This position is not for an existing vacancy.

The Impact You'll Have

Vulnerability Management
  • Own the end-to-end vulnerability management lifecycle - triage, prioritization, remediation tracking, and SLA enforcement - across infrastructure, applications, and containers using findings from Tenable.
  • Review and act on application and code-level vulnerability findings from Snyk (SCA, SAST, container/IaC scanning) and dynamic application security testing results from StackHawk, driving remediation and SLA compliance across relevant teams.
  • Maintain risk-based prioritization models that weigh severity, exploitability, business criticality, and regulatory impact.

AWS Infrastructure Security & Cloud Security Posture Management (CSPM)
  • Own and mature the CSPM program across AWS infrastructure, monitoring for misconfigurations, drift, and control violations against the Common Controls Framework (CCF).
  • Manage cloud misconfiguration findings identified through CrowdStrike, driving triage, reporting, SLA enforcement, and remediation follow-up across AWS compute and containers.
  • Partner with cloud/platform engineering to remediate misconfigurations, enforce secure baselines (IAM, networking, storage, encryption), and reduce AWS account-level risk.

Data Security & SaaS Security
  • Own the Data Security Posture Management (DSPM) program using Sentra, sensitive data discovery, automated classification, data flow/lineage visibility, and cross-environment replication monitoring across cloud data stores
  • Operate and mature the SaaS Security Posture Management (SSPM) program using Reco, discovery of sanctioned/shadow SaaS, OAuth and third-party app governance, and SaaS data exposure monitoring.
  • Partner with data and platform engineering teams to close gaps between security policy and technical enforcement (e.g., classification, least-privilege access, cross-environment data controls).

Findings Aggregation & Remediation Orchestration
  • Automate ticket creation and remediation workflows (e.g., Jira) with proper ownership, SLA tracking, and escalation paths.
  • Drive risk exception and false-positive review processes in partnership with application, platform, and business owners.

API Integration & Automation
  • Build and maintain API integrations between security tools (Tenable, Snyk, StackHawk, CrowdStrike, Sentra, Reco, ArmorCode) and downstream systems (ticketing, SIEM, CMDB, data warehouses).
  • Develop automation/scripts to enrich findings with ownership and asset context, reduce manual triage, and keep dashboards current.

Metrics & Executive Reporting
  • Define and maintain KPIs/KRIs across vulnerability management, cloud, SaaS, and data security programs (e.g., MTTD, MTTR, SLA compliance, coverage, risk reduction trends).
  • Build and maintain executive dashboards and periodic reporting for leadership and audit stakeholders.
  • Translate technical findings into business-risk narratives for non-technical audiences, including compliance mapping (PCI DSS, SOX, SOC 2, ISO 27001).

Who You Are
  • 5+ years in security engineering, with hands-on ownership of vulnerability management, cloud security, or application/SaaS security programs.
  • Direct experience with vulnerability scanning platforms (e.g., Tenable) and application security tools (e.g., Snyk, StackHawk).
  • Hands-on experience with CSPM tooling and securing AWS infrastructure Experience with endpoint/cloud workload detection and response platforms (e.g., CrowdStrike Falcon).
  • Experience with DSPM tooling (Sentra or equivalent) and SSPM tooling (Reco or equivalent).
  • Experience with security findings aggregation/ASPM platforms (e.g., ArmorCode) and ticketing integration (e.g., Jira).
  • Strong scripting/API integration skills (Python, REST APIs) to build and maintain tool-to-tool data pipelines across the above stack.
  • Experience building metrics, KPIs, and executive-level reporting/dashboards from security tooling data.
  • Familiarity with compliance frameworks relevant to a regulated environment (PCI DSS, SOX, SOC 2, ISO 27001).
  • Strong written and verbal communication skills, the ability to translate technical risk into business terms for non-technical and executive stakeholders.

Nice-To-Haves
  • Experience in a fintech, payments, or other highly regulated industry.
  • Prior experience owning a vulnerability/risk exception process and SLA governance model.
  • Familiarity with SIEM integration and security automation/orchestration (SOAR).

Success Metrics for This Role
  • Reduction in Mean Time to Detect (MTTD) and Mean Time to Remediate (MTTR) across all programs.
  • SLA compliance rate for critical/high findings.
  • AWS account/resource coverage under continuous CSPM monitoring, reduction in critical misconfigurations and CrowdStrike-detected threats over time.
  • Coverage rate of data stores and SaaS applications onboarded into DSPM/SSPM monitoring.
  • Reliability and uptime of tool integrations (Tenable, Snyk, StackHawk, CrowdStrike, Sentra, Reco, ArmorCode).
  • Quality and consistency of executive reporting (on-time delivery, accuracy, stakeholder satisfaction).

Compensation and Benefits

Marqeta calibrates pay to a competitive value according to working location. When determining salaries, we consider several factors including, but not limited to, skills, prior experience, and work location. The new-hire base salary range for this full-time position, reflected in CAD, is: 136,800 - 171,000

We also believe in recognizing the contributions of our people. That's why we award annual bonuses to eligible employees, rewarding both individual performance and the success of the entire company.

Along with monetary compensation, Marqeta currently offers:
  • Multiple health insurance options
  • Flexible vacation time with additional floating holidays
  • Retirement savings program with company contribution
  • Equity in a publicly-traded company
  • Monthly stipend to support our remote work model
  • Annual development stipend to support our people growth and development
  • Family-forming benefits and up to 20 weeks of Parental Leave

About Marqeta

Marqeta is a financial technology company that provides payment solutions for businesses. The company offers a modern card issuing platform that enables businesses to build and manage their own payment programs. Marqeta's platform provides a range of features, including real-time authorization controls, instant card issuance, and transaction data analytics. The company's customers include leading brands in the technology, retail, and financial services industries. Marqeta was founded in 2010 and is headquartered in Oakland, California.
Learn more about Marqeta
Size
500 employees
Market Cap
$3.1 billion
Industry
Founded
2010
NASDAQ

Similar Jobs

More Jobs at Marqeta

More Information Technology Jobs

Find similar Senior Security Engineer - Vulnerability & Data/SaaS Security jobs: