Security Engineer II - Identity and Access Management

New
M
MarqetaIdentity and access management
Remote - Canada; this role can be performed remotely anywhere within Ontario or British Columbia, Canada.Full-TimeMiddle
SalaryThe new-hire base salary range for this full-time position, reflected in CAD, is: 104,000 - 130,000.
Apply NowOpens the employer's application page

Job Details

Experience
A minimum of 3 years related experience with a Bachelor’s degree; or 2 years and a Master’s degree; or equivalent combination of related education and work experience.
Required Skills
PythonLDAP

Requirements

  • Have at least 3 years of related experience with a Bachelor’s degree, or 2 years with a Master’s degree, or an equivalent combination of related education and work experience.
  • Have hands-on experience with IAM tools such as Okta, Entra ID, CyberArk, Ping, or SailPoint.
  • Have working knowledge of SAML, OAuth2/OIDC, and SCIM.
  • Understand AWS IAM concepts, including roles, policies, and federation, as well as least privilege and RBAC.
  • Have hands-on scripting skills, such as Python or PowerShell, to automate IAM operations through APIs.
  • Be familiar with directory services such as Active Directory, LDAP, and cloud-based alternatives.
  • Be familiar with compliance frameworks such as NIST, SOC 2, and PCI DSS.
  • Be able to collaborate with engineers and non-technical stakeholders.
  • Relevant certifications or IAM-specific credentials are a nice-to-have.

Responsibilities

  • Configure and maintain Okta SSO, MFA, lifecycle management, policies, SAML/OIDC integrations, and SCIM provisioning.
  • Manage just-in-time access profiles and policies in PAM platforms for cloud and privileged resources.
  • Work with engineering teams to reduce standing privileges.
  • Build and improve access request, approval, and review workflows in IGA platforms.
  • Automate joiner, mover, and leaver processes and access reviews using scripting, APIs, and infrastructure-as-code.
  • Partner with Security, DevOps, and Infrastructure teams to onboard applications and cloud accounts and troubleshoot access issues.
  • Support SOC 2, PCI DSS, and other audit activities by producing access evidence and improving control design.
  • Document processes, contribute to team runbooks, and take part in the on-call rotation if applicable.
View Full Description & ApplyYou'll be redirected to the employer's site
The new-hire base salary range for this full-time position, reflected in CAD, is: 104,000 - 130,000.
Apply Now