CyberSecurity

Senior Security Engineer - Vulnerability & Data/SaaS Security

All jobs

The Senior Security Engineer owns the day-to-day operation, integration, and continuous improvement of Marqeta's vulnerability management, cloud security posture, and data/SaaS security programs. This role sits at the center of the security tooling ecosystem, Tenable, Snyk, StackHawk, CrowdStrike, Sentra, Reco, and ArmorCode, correlating findings across platforms, driving remediation, and translating technical risk into metrics and reporting that inform both engineering teams and executive leadership.

We work Flexible First. This role can be performed remotely anywhere within Ontario or British Columbia, Canada. We’d love for you to join us!

This position is not for an existing vacancy.

The Impact You’ll Have

Vulnerability Management

  • Own the end-to-end vulnerability management lifecycle — triage, prioritization, remediation tracking, and SLA enforcement — across infrastructure, applications, and containers using findings from Tenable.

  • Review and act on application and code-level vulnerability findings from Snyk (SCA, SAST, container/IaC scanning) and dynamic application security testing results from StackHawk, driving remediation and SLA compliance across relevant teams.

  • Maintain risk-based prioritization models that weigh severity, exploitability, business criticality, and regulatory impact.

AWS Infrastructure Security & Cloud Security Posture Management (CSPM)

  • Own and mature the CSPM program across AWS infrastructure, monitoring for misconfigurations, drift, and control violations against the Common Controls Framework (CCF).

  • Manage cloud misconfiguration findings identified through CrowdStrike, driving triage, reporting, SLA enforcement, and remediation follow-up across AWS compute and containers.

  • Partner with cloud/platform engineering to remediate misconfigurations, enforce secure baselines (IAM, networking, storage, encryption), and reduce AWS account-level risk.

Data Security & SaaS Security

  • Own the Data Security Posture Management (DSPM) program using Sentra, sensitive data discovery, automated classification, data flow/lineage visibility, and cross-environment replication monitoring across cloud data stores

  • Operate and mature the SaaS Security Posture Management (SSPM) program using Reco, discovery of sanctioned/shadow SaaS, OAuth and third-party app governance, and SaaS data exposure monitoring.

  • Partner with data and platform engineering teams to close gaps between security policy and technical enforcement (e.g., classification, least-privilege access, cross-environment data controls).

Findings Aggregation & Remediation Orchestration

  • Automate ticket creation and remediation workflows (e.g., Jira) with proper ownership, SLA tracking, and escalation paths.

  • Drive risk exception and false-positive review processes in partnership with application, platform, and business owners.

API Integration & Automation

  • Build and maintain API integrations between security tools (Tenable, Snyk, StackHawk, CrowdStrike, Sentra, Reco, ArmorCode) and downstream systems (ticketing, SIEM, CMDB, data warehouses).

  • Develop automation/scripts to enrich findings with ownership and asset context, reduce manual triage, and keep dashboards current.

Metrics & Executive Reporting

  • Define and maintain KPIs/KRIs across vulnerability management, cloud, SaaS, and data security programs (e.g., MTTD, MTTR, SLA compliance, coverage, risk reduction trends).

  • Build and maintain executive dashboards and periodic reporting for leadership and audit stakeholders.

  • Translate technical findings into business-risk narratives for non-technical audiences, including compliance mapping (PCI DSS, SOX, SOC 2, ISO 27001).

Who You Are

  • 5+ years in security engineering, with hands-on ownership of vulnerability management, cloud security, or application/SaaS security programs.

  • Direct experience with vulnerability scanning platforms (e.g., Tenable) and application security tools (e.g., Snyk, StackHawk).

  • Hands-on experience with CSPM tooling and securing AWS infrastructure Experience with endpoint/cloud workload detection and response platforms (e.g., CrowdStrike Falcon).

  • Experience with DSPM tooling (Sentra or equivalent) and SSPM tooling (Reco or equivalent).

  • Experience with security findings aggregation/ASPM platforms (e.g., ArmorCode) and ticketing integration (e.g., Jira).

  • Strong scripting/API integration skills (Python, REST APIs) to build and maintain tool-to-tool data pipelines across the above stack.

  • Experience building metrics, KPIs, and executive-level reporting/dashboards from security tooling data.

  • Familiarity with compliance frameworks relevant to a regulated environment (PCI DSS, SOX, SOC 2, ISO 27001).

  • Strong written and verbal communication skills, the ability to translate technical risk into business terms for non-technical and executive stakeholders.

Nice-To-Haves

  • Experience in a fintech, payments, or other highly regulated industry.

  • Prior experience owning a vulnerability/risk exception process and SLA governance model.

  • Familiarity with SIEM integration and security automation/orchestration (SOAR).

Success Metrics for This Role

  • Reduction in Mean Time to Detect (MTTD) and Mean Time to Remediate (MTTR) across all programs.

  • SLA compliance rate for critical/high findings.

  • AWS account/resource coverage under continuous CSPM monitoring, reduction in critical misconfigurations and CrowdStrike-detected threats over time.

  • Coverage rate of data stores and SaaS applications onboarded into DSPM/SSPM monitoring.

  • Reliability and uptime of tool integrations (Tenable, Snyk, StackHawk, CrowdStrike, Sentra, Reco, ArmorCode).

  • Quality and consistency of executive reporting (on-time delivery, accuracy, stakeholder satisfaction).

Compensation and Benefits

Marqeta calibrates pay to a competitive value according to working location. When determining salaries, we consider several factors including, but not limited to, skills, prior experience, and work location. The new-hire base salary range for this full-time position, reflected in CAD, is: 136,800 - 171,000

We also believe in recognizing the contributions of our people. That's why we award annual bonuses to eligible employees, rewarding both individual performance and the success of the entire company.

Along with monetary compensation, Marqeta currently offers:

  • Multiple health insurance options

  • Flexible vacation time with additional floating holidays

  • Retirement savings program with company contribution

  • Equity in a publicly-traded company

  • Monthly stipend to support our remote work model

  • Annual development stipend to support our people growth and development

  • Family-forming benefits and up to 20 weeks of Parental Leave

About Marqeta

Marqeta is on a mission to change the way money moves. We’re one of the earliest enablers of embedded finance, a market opportunity sized up in the trillions. Our card issuing platform provides unprecedented flexibility and control for companies to issue cards, authorize transactions, and manage payment operations in real time. Marqeta is powering the most well known brands in the new economy (Block, Cash App, Affirm, Instacart, Doordash, Uber, Walmart, etc). You don’t need to be a Payments expert to join the Marqeta Team, let us help you with that. This is the opportunity of a lifetime to work with innovators around the world and unlock equitable financial access for all.

Marqeta’s Values

– Solve for the Customer: With a deep understanding of our customers' business and empathy for their needs, we deliver products and services that drive their success. Earning and keeping their trust guides everything we do.

– Do What's Right: Knowing businesses and livelihoods depend on us, we pursue solutions that disrupt responsibly and deliver high-quality results that our customers count on. We own our work from start to finish.

– Simplify and Innovate: We approach challenges with curiosity and take smart risks. Innovation comes from finding better, simpler ways to achieve extraordinary outcomes.

– Win as a Team: We succeed together by embracing diverse perspectives and pushing each other to raise the bar. We lead with humility and set aside hierarchy to work as a team.

– Make it Count: We drive forward with focus and agility. With a sense of urgency and purpose, we get the job done, and done right.

Equal Employment Opportunity, Accommodations and Privacy

Marqeta is an equal opportunity employer committed to an inclusive workplace that fosters belonging. We do not discriminate based on race, color, religion, sex (including pregnancy, lactation, childbirth, or related medical conditions), veteran status or uniformed service member status, age, national origin or ancestry, citizenship or immigration status, physical or mental disability, gender identity, gender expression, sexual orientation, genetic information (including testing or characteristics) or any other characteristic protected by applicable law. We also consider qualified applicants with criminal histories, consistent with legal requirements.

Marqeta endeavors to make reasonable accommodations for applicants with disabilities. If you are an individual with a disability and require a reasonable accommodation to submit this application, complete any pre-employment testing, or otherwise participate in the employee selection process, please submit this form with your specific accommodation request.

Marqeta cares about your privacy. Personal data that is provided as part of the application and recruitment process is processed in accordance with the Applicant Privacy Notice. Additional information for California residents can be found here.

Notice on Use of AI in Recruitment
We may use artificial intelligence (AI) tools in our recruitment processing consistent with the requirements of applicable laws. For more information, review our AI notice here.