Marqeta Inc
Senior Security Engineer - Vulnerability & Data/SaaS Security
Remote - Ontario OR British Columbia · Posted Aug 27, 2026
About the role
The Senior Security Engineer owns the day-to-day operation, integration, and continuous improvement of Marqeta's vulnerability management, cloud security posture, and data/SaaS security programs. This role sits at the center of the security tooling ecosystem, Tenable, Snyk, StackHawk, CrowdStrike, Sentra, Reco, and ArmorCode, correlating findings across platforms, driving remediation, and translating technical risk into metrics and reporting that inform both engineering teams and executive leadership. We work Flexible First https://www.marqeta.com/blog/2022/05/10/flexible-first. This role can be performed remotely anywhere within Ontario or British Columbia, Canada. We’d love for you to join us! This position is not for an existing vacancy. The Impact You’ll Have Vulnerability Management - Own the end-to-end vulnerability management lifecycle — triage, prioritization, remediation tracking, and SLA enforcement — across infrastructure, applications, and containers using findings from Tenable. - Review and act on application and code-level vulnerability findings from Snyk (SCA, SAST, container/IaC scanning) and dynamic application security testing results from StackHawk, driving remediation and SLA compliance across relevant teams. - Maintain risk-based prioritization models that weigh severity, exploitability, business criticality, and regulatory impact. AWS Infrastructure Security & Cloud Security Posture Management (CSPM) - Own and mature the CSPM program across AWS infrastructure, monitoring for misconfigurations, drift, and control violations against the Common Controls Framework (CCF). - Manage cloud misconfiguration findings identified through CrowdStrike, driving triage, reporting, SLA enforcement, and remediation follow-up across AWS compute and containers. - Partner with cloud/platform engineering to remediate misconfigurations, enforce secure baselines (IAM, networking, storage, encryption), and reduce AWS account-level risk. Data Security & SaaS Security - Own the Data Security Posture Management (DSPM) program using Sentra, sensitive data discovery, automated classification, data flow/lineage visibility, and cross-environment replication monitoring across cloud data stores - Operate and mature the SaaS Security Posture Management (SSPM) program using Reco, discovery of sanctioned/shadow SaaS, OAuth and third-party app governance, and SaaS data exposure monitoring. - Partner with data and platform engineering teams to close gaps between security policy and technical enforcement (e.g., classification, least-privilege access, cross-environment data controls). Findings Aggregation & Remediation Orchestration - Automate ticket creation and remediation workflows (e.g., Jira) with proper ownership, SLA tracking, and escalation paths. - Drive risk exception and false-positive review processes in partnership with application, platform, and business owners. API Integration & Automation - Build and maintain API integrations between security tools (Tenable, Snyk, StackHawk, CrowdStrike, Sentra, Reco, ArmorCode) and downstream systems (ticketing, SIEM, CMDB, data warehouses). - Develop automation/scripts to enrich findings with ownership and asset context, reduce manual triage, and keep dashboards current. Metrics & Executive Reporting - Define and maintain KPIs/KRIs across vulnerability management, cloud, SaaS, and data security programs (e.g., MTTD, MTTR, SLA compliance, coverage, risk reduction trends). - Build and maintain executive dashboards and periodic reporting for leadership and audit stakeholders. - Translate technical findings into business-risk narratives for non-technical audiences, including compliance mapping (PCI DSS, SOX, SOC 2, ISO 27001). Who You Are - 5+ years in security engineering, with hands-on ownership of vulnerability management, cloud security, or application/SaaS security programs. - Direct experience with vulnerability scanning platforms (e.g., Tenable)
Apply in minutes, not hours
Godspeed drafts a cover letter, tailors your resume to this role, and finds the hiring manager's email — on a curated feed of jobs worth your time.
Start for free