The Senior Security Engineer owns the day-to-day operation, integration, and continuous improvement of Marqeta's vulnerability management, cloud security posture, and data/SaaS security programs. This role sits at the center of the security tooling ecosystem, Tenable, Snyk, StackHawk, CrowdStrike, Sentra, Reco, and ArmorCode, correlating findings across platforms, driving remediation, and translating technical risk into metrics and reporting that inform both engineering teams and executive leadership.
We work Flexible First. This role can be performed remotely anywhere within Ontario or British Columbia, Canada. We'd love for you to join us!
This position is not for an existing vacancy.
The Impact You'll HaveVulnerability Management- Own the end-to-end vulnerability management lifecycle - triage, prioritization, remediation tracking, and SLA enforcement - across infrastructure, applications, and containers using findings from Tenable.
- Review and act on application and code-level vulnerability findings from Snyk (SCA, SAST, container/IaC scanning) and dynamic application security testing results from StackHawk, driving remediation and SLA compliance across relevant teams.
- Maintain risk-based prioritization models that weigh severity, exploitability, business criticality, and regulatory impact.
AWS Infrastructure Security & Cloud Security Posture Management (CSPM)- Own and mature the CSPM program across AWS infrastructure, monitoring for misconfigurations, drift, and control violations against the Common Controls Framework (CCF).
- Manage cloud misconfiguration findings identified through CrowdStrike, driving triage, reporting, SLA enforcement, and remediation follow-up across AWS compute and containers.
- Partner with cloud/platform engineering to remediate misconfigurations, enforce secure baselines (IAM, networking, storage, encryption), and reduce AWS account-level risk.
Data Security & SaaS Security- Own the Data Security Posture Management (DSPM) program using Sentra, sensitive data discovery, automated classification, data flow/lineage visibility, and cross-environment replication monitoring across cloud data stores
- Operate and mature the SaaS Security Posture Management (SSPM) program using Reco, discovery of sanctioned/shadow SaaS, OAuth and third-party app governance, and SaaS data exposure monitoring.
- Partner with data and platform engineering teams to close gaps between security policy and technical enforcement (e.g., classification, least-privilege access, cross-environment data controls).
Findings Aggregation & Remediation Orchestration- Automate ticket creation and remediation workflows (e.g., Jira) with proper ownership, SLA tracking, and escalation paths.
- Drive risk exception and false-positive review processes in partnership with application, platform, and business owners.
API Integration & Automation- Build and maintain API integrations between security tools (Tenable, Snyk, StackHawk, CrowdStrike, Sentra, Reco, ArmorCode) and downstream systems (ticketing, SIEM, CMDB, data warehouses).
- Develop automation/scripts to enrich findings with ownership and asset context, reduce manual triage, and keep dashboards current.
Metrics & Executive Reporting- Define and maintain KPIs/KRIs across vulnerability management, cloud, SaaS, and data security programs (e.g., MTTD, MTTR, SLA compliance, coverage, risk reduction trends).
- Build and maintain executive dashboards and periodic reporting for leadership and audit stakeholders.
- Translate technical findings into business-risk narratives for non-technical audiences, including compliance mapping (PCI DSS, SOX, SOC 2, ISO 27001).
Who You Are- 5+ years in security engineering, with hands-on ownership of vulnerability management, cloud security, or application/SaaS security programs.
- Direct experience with vulnerability scanning platforms (e.g., Tenable) and application security tools (e.g., Snyk, StackHawk).
- Hands-on experience with CSPM tooling and securing AWS infrastructure Experience with endpoint/cloud workload detection and response platforms (e.g., CrowdStrike Falcon).
- Experience with DSPM tooling (Sentra or equivalent) and SSPM tooling (Reco or equivalent).
- Experience with security findings aggregation/ASPM platforms (e.g., ArmorCode) and ticketing integration (e.g., Jira).
- Strong scripting/API integration skills (Python, REST APIs) to build and maintain tool-to-tool data pipelines across the above stack.
- Experience building metrics, KPIs, and executive-level reporting/dashboards from security tooling data.
- Familiarity with compliance frameworks relevant to a regulated environment (PCI DSS, SOX, SOC 2, ISO 27001).
- Strong written and verbal communication skills, the ability to translate technical risk into business terms for non-technical and executive stakeholders.
Nice-To-Haves- Experience in a fintech, payments, or other highly regulated industry.
- Prior experience owning a vulnerability/risk exception process and SLA governance model.
- Familiarity with SIEM integration and security automation/orchestration (SOAR).
Success Metrics for This Role- Reduction in Mean Time to Detect (MTTD) and Mean Time to Remediate (MTTR) across all programs.
- SLA compliance rate for critical/high findings.
- AWS account/resource coverage under continuous CSPM monitoring, reduction in critical misconfigurations and CrowdStrike-detected threats over time.
- Coverage rate of data stores and SaaS applications onboarded into DSPM/SSPM monitoring.
- Reliability and uptime of tool integrations (Tenable, Snyk, StackHawk, CrowdStrike, Sentra, Reco, ArmorCode).
- Quality and consistency of executive reporting (on-time delivery, accuracy, stakeholder satisfaction).
Compensation and BenefitsMarqeta calibrates pay to a competitive value according to working location. When determining salaries, we consider several factors including, but not limited to, skills, prior experience, and work location. The new-hire
base salary range for this full-time position, reflected in CAD, is: 136,800 - 171,000
We also believe in recognizing the contributions of our people. That's why we award annual bonuses to eligible employees, rewarding both individual performance and the success of the entire company.
Along with monetary compensation, Marqeta currently offers:
- Multiple health insurance options
- Flexible vacation time with additional floating holidays
- Retirement savings program with company contribution
- Equity in a publicly-traded company
- Monthly stipend to support our remote work model
- Annual development stipend to support our people growth and development
- Family-forming benefits and up to 20 weeks of Parental Leave