Staff DevSecOps Engineer (Cryptography)
MarqetaAbout the role
Staff DevSecOps Engineer (Cryptography)
We’re seeking an experienced Staff DevSecOps Engineer with a passion for securing cloud-native applications and a strong background in AWS cloud security. In this role, you’ll drive the integration of security into our development pipelines, leveraging automation and coding expertise in Python, Go, and Java to protect our platforms.
Join us in building secure, scalable cloud environments where you’ll play a key role in:
- Cloud Security – Implementing robust security controls across AWS environments.
- DevSecOps Practices – Embedding security into CI/CD pipelines and infrastructure as code.
- Automation – Developing tools and scripts to enhance security monitoring, response, and cryptography operations.
This is a remote-first role, with the option to work from anywhere within the U.S. or from our Oakland office. If you’re excited about securing the future of cloud-native applications, we’d love to have you on our team!
What You'll Do:
- Design and implement security architectures for AWS-based applications, leveraging services like IAM, GuardDuty, and Security Hub.
- Secure AWS generative AI workloads, ensuring proper access controls, data encryption, and model security for services like Amazon Bedrock and SageMaker.
- Integrate security into CI/CD pipelines, ensuring secure code deployment using tools like AWS CodePipeline and CodeBuild.
- Develop and maintain automation scripts and tools in Python, Go, or Java to enhance security monitoring, incident response, and compliance.
- Automate cryptography-related tasks and operations using AWS Lambda functions for AWS KMS and Secrets Manager.
- Automate on-prem and off-prem HSM tasks using Java, Python, or Go to streamline key management processes.
- Collaborate with development, operations, and security teams to implement data protection, access control, and vulnerability management strategies.
- Manage and secure infrastructure as code (IaC) using Terraform or AWS CloudFormation, ensuring secure configurations.
- Monitor and respond to security incidents, utilizing AWS CloudTrail, CloudWatch, and other logging tools.
- Ensure compliance with security standards such as PCI DSS through automated controls and audits.
- Research emerging cloud security and cryptography trends and integrate best practices into our strategies.
What We're Looking For:
- A minimum of 8 years of related experience with a Bachelor’s degree; or 5 years and a Master’s degree; or a PhD with 3 years’ experience; or equivalent combination of related education and work experience.
- 5+ years of professional experience in DevSecOps, cloud security, or application security.
- 4+ years of hands-on experience with AWS security services (e.g., IAM, KMS, Secrets Manager, GuardDuty, Security Hub).
- 4+ years of coding experience in Python, Go, and/or Java, with a focus on security automation or tool development.
- 3+ years of experience with infrastructure as code (e.g., Terraform, CloudFormation) and CI/CD tools (e.g., Jenkins, GitHub Actions).
- 2+ years of experience with container security (e.g., Docker, Kubernetes) and securing microservices architectures.
- 2+ years of experience with security compliance frameworks (e.g., PCI DSS).
- Strong collaboration and communication skills, with the ability to influence cross-functional teams.
- Problem-solving skills to navigate complex security challenges with confidence and flexibility.
Nice to Have:
- Experience with AWS KMS, AWS Secrets Manager, or Google Tink.
- Working knowledge of Amazon Bedrock/SageMaker security features.
- Familiarity with HSM automation for on-prem and off-prem environments.
- Experience with Kubernetes security tools (e.g., Falco, Trivy).
- Proficiency in additional scripting languages or frameworks (e.g., Bash, Node.js).
- CISSP, CCSP, AWS Certified Security – Specialty, or other relevant certifications.
Job Expectations:
- Occasional travel (up to 10%).
- A hiring process that includes an application, recruiter call, hiring manager video call, and a virtual “onsite” interview.
Compensation and Benefits
Marqeta is a Flex First company which allows you to choose your best working environment, whether that be from home or at a company office. To support Flex First, we calibrate pay to a competitive value according to working location. Compensation is aligned according to three tiers within the United States:
- National: A baseline tier that applies to most of the geographic territory of the Unit
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s