Senior Security Engineer, Detection and Response
As Marqeta's Senior Security Engineer on the Security Operations and Response team, you will lead incident response for North America and shape how we detect and respond to threats using AI-driven automation in a Next-Gen Agentic SOAR. You'll join a Security Operations & Response team that builds its own AI tools to speed up investigations and strengthen Marqeta's security posture. In this role, you'll serve as the lead technical responder during security events, engineer automated detections and response workflows, run advanced threat hunts, help to build a resilient and comprehensive security operations program, and mentor junior teammates on incident response best practices, while participating in a 24x7 on-call rotation.
We work Flexible First. This role can be performed remotely anywhere within the province where you reside, whether that’s Ontario, Canada or British Columbia, Canada. We’d love for you to join us!
This position is for an existing vacancy.
The Impact You’ll Have
- Serve as the lead security responder in North American timezones, triaging and investigating complex alerts and acting as a core member of the Cybersecurity Incident Response Team
- Participate in 24x7x365 on-call rotations, providing senior-level expertise and escalation support for security events and incidents
- Engineer, maintain, and continuously optimize detection logic across multiple data sources, using threat modeling to keep coverage current with the evolving attack landscape
- Design detection coverage mapping that documents capabilities and identifies blind spots in the threat landscape
- Develop and track KPIs with leadership, including detection effectiveness, false positive rates, and mean time to detect, respond, and recover
- Create and maintain incident response runbooks, SOPs, and technical documentation to ensure consistent response operations
- Mentor junior team members in security operations best practices, detection engineering, and incident response methodologies
- Build automation workflows and orchestration playbooks that improve detection engineering, threat hunting, and incident response
- Develop and use AI-driven tools for Security Operations and Incident Response
- Conduct proactive, hypothesis-driven threat hunts across corporate and production environments, and support the logging and monitoring infrastructure that enables them
Who You Are
- 5+ years of hands-on experience in security operations with emphasis on Incident Response and Detection Engineering. Additional expertise in threat hunting, cyber threat intelligence, and digital forensics is preferred.
- Industry certifications in Incident Response or related fields are strongly preferred, such as GCIH, GCFA, GIME, OSIR, or GEIR.
- Intellectual curiosity with a passion for understanding emerging threats, analyzing attack patterns, and continuously learning about evolving security landscapes and adversary tactics.
- Strong investigative instincts that compel you to dig deeper into anomalies, follow evidence trails, and reconstruct complex security incidents from fragmented data.
- Commitment to proactive learning and staying ahead of evolving threats by researching emerging attack techniques and sharing insights with the security team.
- Solid technical foundation in security concepts and technologies, with hands-on experience using enterprise security tools including EDR, NDR, CSPM, EASM, SIEM, SOAR, and Cloud Security platforms such as GuardDuty.
- Proficiency with threat intelligence frameworks such as MITRE ATT&CK and their application in assessing detection capabilities and coverage gaps.
- Expertise in developing new threat detection use cases based on security telemetry analysis, environment baselining, actionable threat intelligence, and incident response findings.
- Ability to identify detection coverage gaps across global infrastructure and collaborate with stakeholders to enhance visibility through improved logging and detection content.
- Strong understanding of AWS cloud services and containerization technologies.
Nice-To-Haves
- Experience with programming languages such as Python, JavaScript, or Go
- Experience with infrastructure as code tools such as Terraform.
- Experience with forensic tools such as KAPE, EnCase, FTK, or Volatility.
- Experience with Detections-as-Code infrastructure like Sigma, or YARA.
- Experience conducting Purple Team exercises and writing reports.
- Experience validating vulnerabilities or reported bugs.
- Experience with Observability or SRE tools and processes.
Manager:
- Gunnar Poling
Recruiter:
- Kayla Osuna
Typical Process:
- Application submission
- Recruiter phone or video call
- Hiring manager video call
- Virtual “Onsite” consisting of 3-5, 45 min interviews
- Offer!
Compensation and Benefits
Marqeta calibrates pay to a competitive value according to working location. When determining salaries, we consider several factors including, but not limited to, skills, prior experience, and work location. The new-hire base salary range for this full-time position, reflected in CAD, is: 136,800 - 171,000
We also believe in recognizing the contributions of our people. That's why we award annual bonuses to eligible employees, rewarding both individual performance and the success of the entire company.
Along with monetary compensation, Marqeta currently offers:
- Multiple health insurance options
- Flexible vacation time with additional floating holidays
- Retirement savings program with company contribution
- Equity in a publicly-traded company
- Monthly stipend to support our remote work model
- Annual development stipend to support our people growth and development
- Family-forming benefits and generous parental leave base salary top-up
About Marqeta
Marqeta is on a mission to change the way money moves. We’re one of the earliest enablers of embedded finance, a market opportunity sized up in the trillions. Our card issuing platform provides unprecedented flexibility and control for companies to issue cards, authorize transactions, and manage payment operations in real time. Marqeta is powering the most well known brands in the new economy (Block, Cash App, Affirm, Instacart, Doordash, Uber, Walmart, etc). You don’t need to be a Payments expert to join the Marqeta Team, let us help you with that. This is the opportunity of a lifetime to work with innovators around the world and unlock equitable financial access for all.
Marqeta’s Values
– Solve for the Customer: With a deep understanding of our customers' business and empathy for their needs, we deliver products and services that drive their success. Earning and keeping their trust guides everything we do.
– Do What's Right: Knowing businesses and livelihoods depend on us, we pursue solutions that disrupt responsibly and deliver high-quality results that our customers count on. We own our work from start to finish.
– Simplify and Innovate: We approach challenges with curiosity and take smart risks. Innovation comes from finding better, simpler ways to achieve extraordinary outcomes.
– Win as a Team: We succeed together by embracing diverse perspectives and pushing each other to raise the bar. We lead with humility and set aside hierarchy to work as a team.
– Make it Count: We drive forward with focus and agility. With a sense of urgency and purpose, we get the job done, and done right.
Equal Employment Opportunity, Accommodations and Privacy
Marqeta is an equal opportunity employer committed to an inclusive workplace that fosters belonging. We do not discriminate based on race, color, religion, sex (including pregnancy, lactation, childbirth, or related medical conditions), veteran status or uniformed service member status, age, national origin or ancestry, citizenship or immigration status, physical or mental disability, gender identity, gender expression, sexual orientation, genetic information (including testing or characteristics) or any other characteristic protected by applicable law. We also consider qualified applicants with criminal histories, consistent with legal requirements.
Marqeta endeavors to make reasonable accommodations for applicants with disabilities. If you are an individual with a disability and require a reasonable accommodation to submit this application, complete any pre-employment testing, or otherwise participate in the employee selection process, please submit this form with your specific accommodation request.
Marqeta cares about your privacy. Personal data that is provided as part of the application and recruitment process is processed in accordance with the Applicant Privacy Notice. Additional information for California residents can be found here.
To keep our interview process fair and consistent, we ask that all candidates join video interviews with their camera on.
Notice on Use of AI in Recruitment
We may use artificial intelligence (AI) tools in our recruitment processing consistent with the requirements of applicable laws. For more information, review our AI notice here.

