Security Engineer II - Identity and Access Management
New
M
MarqetaIdentity and access management
Remote - Canada; this role can be performed remotely anywhere within Ontario or British Columbia, Canada.Full-TimeMiddle
SalaryThe new-hire base salary range for this full-time position, reflected in CAD, is: 104,000 - 130,000.
Apply NowOpens the employer's application page
Job Details
- Experience
- A minimum of 3 years related experience with a Bachelor’s degree; or 2 years and a Master’s degree; or equivalent combination of related education and work experience.
- Required Skills
- PythonLDAP
Requirements
- Have at least 3 years of related experience with a Bachelor’s degree, or 2 years with a Master’s degree, or an equivalent combination of related education and work experience.
- Have hands-on experience with IAM tools such as Okta, Entra ID, CyberArk, Ping, or SailPoint.
- Have working knowledge of SAML, OAuth2/OIDC, and SCIM.
- Understand AWS IAM concepts, including roles, policies, and federation, as well as least privilege and RBAC.
- Have hands-on scripting skills, such as Python or PowerShell, to automate IAM operations through APIs.
- Be familiar with directory services such as Active Directory, LDAP, and cloud-based alternatives.
- Be familiar with compliance frameworks such as NIST, SOC 2, and PCI DSS.
- Be able to collaborate with engineers and non-technical stakeholders.
- Relevant certifications or IAM-specific credentials are a nice-to-have.
Responsibilities
- Configure and maintain Okta SSO, MFA, lifecycle management, policies, SAML/OIDC integrations, and SCIM provisioning.
- Manage just-in-time access profiles and policies in PAM platforms for cloud and privileged resources.
- Work with engineering teams to reduce standing privileges.
- Build and improve access request, approval, and review workflows in IGA platforms.
- Automate joiner, mover, and leaver processes and access reviews using scripting, APIs, and infrastructure-as-code.
- Partner with Security, DevOps, and Infrastructure teams to onboard applications and cloud accounts and troubleshoot access issues.
- Support SOC 2, PCI DSS, and other audit activities by producing access evidence and improving control design.
- Document processes, contribute to team runbooks, and take part in the on-call rotation if applicable.
View Full Description & ApplyYou'll be redirected to the employer's site