Staff Security Engineer - Pen Testing

Remote, USA

Marqeta

Marqeta is the world's first modern card issuing platform. Our open API platform allows businesses to instantly issue cards and process payments.

View all jobs at Marqeta

Apply now Apply later

Marqeta is on a mission to change the way money moves. We’re one of the earliest enablers of embedded finance, a market opportunity sized up in the trillions. Our card issuing platform provides unprecedented flexibility and control for companies to issue cards, authorize transactions, and manage payment operations in real time.   Marqeta is powering the most well known brands in the new economy (Block, Cash App, Affirm, Instacart, Doordash, Uber, Walmart, etc). Today nearly 8 out of 10 Americans use a product powered by Marqeta every week. This is the opportunity of a lifetime to work with innovators around the world and unlock equitable financial access for all.

We are looking for a Staff Security Engineer with a passion for Product Security and a deep expertise in Penetration Testing. The ideal candidate will be excited about an opportunity to heavily contribute to the penetration testing, security architecture reviews and security best practices in cloud

We work Flexible First. This role can be performed remotely anywhere within the United States or from our Oakland office. We’d love for you to join us!

What You’ll Do

  • Initiate and lead all phases of penetration tests and red team activities, including Scoping, Planning, Communications, and Execution of key activities (Reconnaissance, Vulnerability identification, Exploitation, and Reporting)
  • Conduct penetration tests across Web applications, APIs, Mobile applications, infrastructure, cloud environments, and devices
  • Conduct red team engagements across complex environments (including operational technologies)
  • Experience in Supply Chain Security Risks identification and management
  • Liaison compliance driven web application penetration tests with external vendors
  • Triage vulnerability reports submitted to our Bug Bounty program – includes tracking and responding to submissions, coordinating with teams to triage and resolve issues, and providing feedback to security researchers
  • Engagement with Core Engineering leads to ensure timely risk remediation
  • Work closely with development teams to design and implement strategies for enhanced shift-left security within the SSDLC
  • Take a role in the definition of relevant product security architecture strategies, roadmaps, policies, standards, and procedures
  • Maintain and update relevant solutions and tooling to support new business requirements while ensuring a consistent, compliant, and central service delivery
  • Document operational procedures (such as those for deployments, breakglass plans etc.) as well as current state architecture and configurations
  • Provide on-call rotation support to relevant services and tooling
  • Provide subject matter expertise to project teams, and other audiences as needed

What We’re Looking For

  • You have at least 5+ years of experience as an engineer with a Bachelor’s degree; or 3 years of experience with an advanced degree. Instead of a degree, 8+ years of relevant experience may suffice.
  • Experience in Red/Blue teaming teaming activities and automation
  • Prior experience managing security tooling infrastructure and configuration
  • Industry standard certifications like OSCP/OSCE/CEH, CISSP, CWAD
  • Experience or knowledge about Payments or Financial Services and associated compliance requirements
  • Understanding of cloud computing architecture
  • Demonstrated experience creating positive team and cross-team dynamics
  • Strong analytical and problem-solving skills that enable navigation of complexity, uncertainty, risks and issues
  • Expert-level knowledge in threat modeling methodologies such as STRIDE or PASTA and their applied use in fast-moving, iterative development lifecycles
  • Experience in working with static analysis (SAST), dynamic analysis (DAST), and software composition analysis (SCA) security tools
  • Knowledge of cloud native technologies including containers, Kubernetes, and services provided by AWS, GCP, and Azure
  • Knowledge of OWASP ASVS, SCVS, and related verification standards
  • Ability to work independently or with a team, under minimum supervision
  • Proven ability to apply technical concepts to solve complex business challenges
  • Ability to network with key stakeholders across multiple teams to influence outcomes through well-articulated thoughts, strong presentation skills, and pragmatic solutions
  • Understand ownership and support positive outcomes
  • Remain constructive under pressure, with a flexible working style

Nice-To-Haves

  • Experience with Java, Go, Rust, Python, C, C++, or Ruby
  • Experience with AWS cloud services, containerization technologies such as Kubernetes, and IaaC tooling such as Terraform or Helm
  • Knowledge of automated secure code Reviews

Your Manager

  • Krantikishor Bora - Senior Manager, Product Security

Recruiter For This Role

  • Steve Pestorich - Senior Staff Recruiter

Typical Process

  • Application submission
  • Recruiter phone call
  • Hiring manager video call
  • Virtual “Onsite” consisting of 4-5, 45 min calls
  • Offer!

Compensation and Benefits

Marqeta is a Flex First company which allows you to choose your best working environment, whether that be from home or at a company office. To support Flex First, we calibrate pay to a competitive value according to working location. Compensation is aligned according to three tiers within the United States:

  • National: A baseline tier that applies to most of the geographic territory of the United States.
  • Premium: Slightly elevated from the National tier, and oriented toward a narrower set of higher cost-of-living areas, such as Los Angeles CA and Seattle WA
  • Premium Plus: A tier for the most expensive working areas, like the San Francisco Bay area and New York City.

Visit salaryzones">this page or consult with a Recruiter to determine which tier would be applicable to you.

When determining salaries, we consider several factors including, but not limited to, skills, prior experience, and work location. The new-hire base salary range for this position is:

  • National:  $121,000 - $162,000
  • Premium: $137,000 - $183,000
  • Premium Plus: $152,000 - $203,000

We also believe in recognizing the contributions of our people. That's why we award annual bonuses to eligible employees, rewarding both individual performance and the success of the entire company.

Along with monetary compensation, Marqeta offers

  • Multiple health insurance options
  • Flexible time off – take what you need
  • Retirement savings program with company contribution
  • Equity in a publicly-traded company and an Employee Stock Purchase Program
  • Family-forming benefits, fertility support, and up to 20 weeks of Parental Leave
  • Free therapy sessions, financial and professional coaching, and legal advice
  • Monthly stipend to support our remote work model
  • Annual “development dollars” to support our people growth and development

Equal Employment Opportunity, Accommodations and Privacy 

Marqeta is proud to be an equal opportunity employer that gives consideration to all qualified applicants regardless of race, ancestry, national  origin, color, Indigenous, citizenship, religion/creed, sex, sexual orientation, gender identity, gender expression marital status, family status, disability, veteran status, criminal histories consistent with legal requirements, or any other characteristic protected by applicable law. 

Our dedication to diversity and inclusion extends beyond the categories above. Review Marqeta’s ESG Report to see that dedication in action. Fostering an environment where everyone feels valued and respected creates a stronger and more innovative team at Marqeta. We celebrate the unique contributions of each individual and empower all members of our organization. Join us in building a company where diversity thrives and everyone can be their authentic selves.

If you require reasonable accommodation for the application process and beyond (including due to a disability), please submit this form and we will be more than happy to assist you. Marqeta will make reasonable accommodations for candidates when needed in accordance with applicable law. The Applicant and Candidate Privacy Notice applies to the personal data that you directly provide to us or that we collect during the application and candidate recruitment process.

Apply now Apply later
  • Share this job via
  • or
Job stats:  3  2  0

Tags: APIs Automation AWS Azure C CEH CISSP Cloud Compliance DAST Finance GCP Helm Java Kubernetes OSCE OSCP OWASP Pentesting Privacy Product security Python Red team Ruby Rust SAST Terraform

Perks/benefits: Career development Competitive pay Equity / stock options Fertility benefits Flex hours Flex vacation Health care Home office stipend Insurance Parental leave Team events

Regions: Remote/Anywhere North America
Country: United States

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.