More jobs:
Manager, Vulnerability & Data Security
Remote / Online - Candidates ideally in
Toronto, Ontario, M5A, Canada
Listed on 2026-03-01
Toronto, Ontario, M5A, Canada
Listing for:
Marqeta, Inc.
Remote/Work from Home
position Listed on 2026-03-01
Job specializations:
-
IT/Tech
Cybersecurity, Data Security, Information Security
Job Description & How to Apply Below
We work Flexible First . This role can be performed remotely anywhere within the United States. We’d love for you to join us!
Impact You'll Have
Vulnerability Management
Lead program strategy and operations: asset coverage, scanning cadence, prioritization, and measurable risk reduction using Tenable (Nessus/SC/IO) and Snyk.
Integrate Tenable and Snyk findings into engineering backlogs with clear SLAs; partner with SRE, platform, and application teams to drive remediation.
Establish risk-based prioritization (CVSS, KEV, EPSS, exploitability, business criticality) and publish dashboards for transparency to leadership.
Mature patching and configuration baselines; build preventative controls and secure-by-default guardrails.
Coordinate vulnerability disclosure, pen test intake, and threat-driven campaigns for actively exploited CVEs.
Report program health, trends, and exceptions to security leadership and auditors.
Data Security (Program Build & Ownership)
Establish clear data ownership and stewardship across critical datasets; define roles, responsibilities, and decision rights.
Define and enforce data classification, access, and usage policies; drive best practices and guard rails for least privilege and segregation of duties.
Operationalize Sentra (DSPM) and Google DLP to monitor data exposure and access risks; drive timely remediation with accountable teams.
Build data lifecycle controls (creation, storage, use, sharing, archival, destruction) and technical guardrails embedded in platforms and workflows.
Ensure compliance with data protection regulations (e.g., PCI, SOX); partner on control design, testing, and evidence collection.
Collaborate with Security, Legal, Privacy, and Data teams to protect data across its lifecycle and enable safe analytics/product use cases.
Develop metrics (DLP incidents, misconfigurations, toxic combinations, stale sensitive datasets, policy violations) and report to leadership.
Who You Are
7–10+ years in information security with 3+ years leading programs or teams; regulated/fintech experience preferred.
Hands‑on depth managing vulnerabilities at scale with Tenable and Snyk across cloud‑native, containers, endpoints, and CI/CD.
Practical experience building/maturing data security programs with Sentra (DSPM) and Google DLP; strong policy design and enforcement.
Partner management across engineering, data, and compliance; able to translate risk into actionable plans and measurable outcomes.
Familiarity with PCI and SOX; knowledge of SDLC, Dev Sec Ops , and cloud security architectures (AWS/GCP/Azure).
Comfort with IAM/IGA, SIEM, CNAPP, and ticketing/workflow integrations; solid grasp of data governance concepts (stewardship, lineage).
Excellent communication and reporting—clear narratives, crisp metrics, executive‑ready updates.
Certifications such as CISSP or CISM are a plus.
How you’ll measure success
Reduction in high-risk vulnerabilities and time‑to‑remediation across prioritized asset classes.
Complete inventory coverage and adherence to patch/configuration SLAs via Tenable/Snyk dashboards.
Implemented and adopted data classification and access policies with defined ownership.
Sentra and Google DLP coverage with declining exposure trends and timely remediation.
Successful PCI/SOX audits for relevant controls; fewer exceptions and faster closure.
Clear metrics and dashboards used by leadership for decision‑making.
Nice to Have
Experience automating Tenable/Snyk workflows into CI/CD and GRC/Risk registers.
Background in data governance (stewardship councils, RACI) and analytics platform security (e.g., Snowflake, Databricks, Big Query).
Exposure to SaaS Security Posture Management and third‑party data controls at scale.
Compensation and Benefits
Marqeta is a Flex First company which allows you to choose your best working environment,…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×