Visa logo
Visa

Based in Foster City, California, Visa is a global payments technology organization. Visa was founded in 1958, coinciding with Bank of America’s launch of the

Senior Cybersecurity Engineer IAM

Location

United States

Posted

56 days ago

Salary

$145K - $232K / year

Seniority

Senior

Job Description

Senior Cybersecurity Engineer IAM

Visa

Company Description Founded by experienced entrepreneurs and engineers in 2016, Pismo is a technology company that provides a comprehensive processing platform for banking, card issuing and financial market infrastructure and helps customers innovate and build the next generation of banking and payment solutions. Pismo joined Visa in 2024. Leveraging Visa’s solutions, our core platform, and an expanding suite of capabilities, Pismo addresses the technological challenges that large banks, marketplaces, and fintech companies face in migrating from legacy systems to more advanced technology in the market. Pismo’s cloud-based platform empowers firms to build and launch financial products rapidly, scaling as they grow to have a broader audience while keeping high security and availability standards. Pismo’s 500+ employees are located in more than 10 countries around the world. Job Description The Senior Cybersecurity Engineer – IAM is responsible for designing, implementing, and operating identity and access management controls across the Pismo platform, ensuring compliance with Pismo Visa Corporate Identity & Access Technical Security Requirements. This role operates at platform and architecture level, supporting multicloud and hybrid environments, and focuses on building secure, automated, and auditable access models for human and non‑human identities. The position partners closely with Cloud Security, Platform Engineering, API, DevSecOps, and GRC teams to embed least‑privilege, zero‑trust, and automation‑first IAM practices across a regulated, multi‑tenant payments environment. In addition to traditional IAM responsibilities, this role provides security and governance oversight for AI‑enabled identity use cases, ensuring that AI systems, agents, and automation interacting with identities comply with Internal AI Governance standards, GenAI & Agentic Systems requirements, and Corporate IAM Technical and Design requirements. This is a remote position. A remote position does not require job duties be performed within proximity of a Visa office location. Remote positions may be required to be present at a Visa office with scheduled notice. Qualifications Basic Qualifications: 5+ years of relevant work experience with a Bachelor’s Degree or at least 2 years of work experience with an Advanced degree (e.g. Masters, MBA, JD, MD) or 0 years of work experience with a PhD, OR 8+ years of relevant work experience. Preferred Qualifications: 5+ years of relevant work experience with a Bachelor’s Degree or at least 2 years of work experience with an Advanced degree (e.g. Masters, MBA, JD, MD) or 0 years of work experience with a PhD, OR 8+ years of relevant work experience. 8+ years of cybersecurity experience, with deep specialization in Identity & Access Management (IAM). Proven experience operating at Senior / Consultant level, influencing IAM architecture, standards, and governance decisions. Experience supporting financial services, payments, or regulated environments Multicloud IAM Architecture (Mandatory) Strong hands‑on experience designing and operating IAM across multicloud environments, including AWS and hybrid/federated cloud models. Ability to design scalable permission models across cloud platforms, including: Cloud‑native roles and permission sets Least‑privilege and separation‑of‑duties enforcement Human and non‑human identities (workloads, service accounts) Permission Design & Access Modeling Deep understanding of permission structures, including: Role‑based (RBAC) and attribute‑based (ABAC) access models IAM‑governed access roles and entitlement cataloging Temporary, just‑in‑time, and break‑glass access patterns Ability to design access models that reduce audit scope, review volume, and operational risk. IAM Automation & Engineering (Critical Requirement) Strong experience implementing IAM automation, including: Automated provisioning and de‑provisioning (JML lifecycle) Access revalidation and certification automation Auto‑remediation of non‑compliant permissions Experience integrating IAM controls with CI/CD pipelines and Infrastructure‑as‑Code (IaC). Proven ability to codify IAM policies and controls using automation frameworks. Coding & Scripting Skills Hands‑on coding experience to support IAM automation and integrations, including: Python or equivalent scripting languages Use of APIs and SDKs to manage identities, roles, and entitlements Automation via IaC tools (e.g., Terraform‑based IAM definitions) Ability to build reusable, auditable, and scalable IAM automation components Privileged Access & Cloud Governance Experience designing and governing privileged access across cloud platforms. Ability to enforce time‑bound, auditable privileged access aligned with least‑privilege principles. Strong understanding of cloud governance roles required for vulnerability scanning, configuration Additional Information Work Hours: Varies upon the needs of the department. Travel Requirements: This position requires travel 5-10% of the time. Mental/Physical Requirements: This position will be performed in an office setting. The position will require the incumbent to sit and stand at a desk, communicate in person and by telephone, frequently operate standard office equipment, such as telephones and computers. Visa is an EEO Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status. Visa will also consider for employment qualified applicants with criminal histories in a manner consistent with EEOC guidelines and applicable local law. Visa will consider for employment qualified applicants with criminal histories in a manner consistent with applicable local law, including the requirements of Article 49 of the San Francisco Police Code. U.S. APPLICANTS ONLY: The estimated salary range for this position is 145,300.00 to 232,700.00 USD per year, which may include potential sales incentive payments (if applicable). Salary may vary depending on job-related factors which may include knowledge, skills, experience, and location. In addition, this position may be eligible for bonus and equity. Visa has a comprehensive benefits package for which this position may be eligible that includes Medical, Dental, Vision, 401 (k), FSA/HSA, Life Insurance, Paid Time Off, and Wellness Program. - Job Family Group: Engineering and Technology

Related Categories

Related Job Pages

More Security Engineer Jobs

One Identity logo

Senior Information Security Engineer

One Identity

A leader in unified identity security

Full TimeRemoteTeam 501-1,000H1B Sponsor

• Design, implement, and operate cloud and infrastructure security controls across Azure‑first environments, with supporting coverage in AWS. • Implement and maintain security monitoring, detection, and response capabilities, leveraging SIEM, cloud‑native tooling, and endpoint/network telemetry. • Participate in security incident response activities, including investigation, containment, remediation, and post‑incident analysis. • Collaborate with engineering and platform teams to securely design and deploy SaaS and on‑prem solutions, including infrastructure hardening and secure configuration. • Develop, tune, and maintain security alerts and detections to improve signal quality and reduce noise. • Support vulnerability management activities, including infrastructure scanning, risk triage, remediation tracking, and validation. • Partner with compliance and GRC functions to support SOC 1, SOC 2, ISO 27001, 27017, and 27018 requirements through effective technical controls and evidence generation. • Implement and operate identity, access, and secrets management controls for cloud and infrastructure environments. • Help define and continuously improve security runbooks, operational procedures, and response playbooks. • Evaluate, implement, and support security tooling related to cloud security posture management, logging, endpoint protection, and threat detection. • Stay current on emerging threats, attacker techniques, and cloud security trends, applying this knowledge to improve defenses. • Provide mentorship and technical guidance to less‑experienced security engineers as appropriate, without direct people‑management responsibility.

Hungary
ClickHouse logo

Cloud Security Engineer

ClickHouse

ClickHouse is an open-source, column-oriented OLAP database management system.

Full TimeRemoteTeam 51-200Since 2016H1B Sponsor

• Secure cloud infrastructure supporting the ClickHouse products and services (AWS, GCP and Azure) • Collaborate with product and engineering teams to facilitate safe and secure use of public cloud infrastructure and resources • Develop and implement security systems (e.g. CSPM, infrastructure as code, secrets management) to secure and harden ClickHouse cloud infrastructure • Identify and respond to identified security issues, vulnerabilities, and incidents • Identify security gaps and vulnerabilities in ClickHouse assets • Develop processes, tooling and automation to scale security processes and mitigate risks to the business

Netherlands
Affirm logo

Senior Manager, Security Risk Management

Affirm

We create honest financial products that improve lives.

Full TimeRemoteTeam 1,001-5,000Since 2012H1B Sponsor

• Own Security Governance: maintain and evolve security policies, standards, and control frameworks (e.g., NIST CSF, ISO 27001), including mapping to controls and compliance requirements (SOC2, PCI, applicable regulations). • Lead program maturity planning, roadmaps, and cross-functional governance forums (e.g., security steering committee, risk council). • Define and enforce security risk appetite and decision criteria for third-party relationships and integrations. • Lead the Security TPRM function across vendor lifecycle: intake/onboarding, due diligence (IRQ/DDQ/SME reviews), contracting handoffs, ongoing monitoring, periodic reviews, and offboarding. • Ensure robust fourth-party oversight, including subprocessors, and manage remediation/QA cycles driven by Internal Audit and regulators. • Oversee high-risk vendor decisions and escalations; establish clear RACI for partnership contracts and security acceptance criteria. • Own program KPIs, dashboards, and reporting (Jira STPRM Ops, AuditBoard, Sigma/BI, MetricStream). Drive improvements in throughput, turnaround, backlog age, and remediation velocity. • Partner with Automation/TPRM Ops to operationalize threat-modeling outputs, integration inventories, pre-integration gates, and CI/CD checks; prioritize automations that reduce manual work and surface strategic escalations. • Implement and maintain QA processes (quarterly QA), runbooks, SOPs for ticket ownership, and evidence standards. • Build, coach, and scale the Governance and TPRM teams: hiring, performance management, career development, and team morale. • Act as the primary security contact for Legal, Procurement, Privacy, Product, and Engineering on vendor risk and governance matters. • Represent Security in executive forums, audit meetings, and regulatory engagements; own remediation commitments and timelines. • Serve as the security liaison for Internal Audit and external assessments; ensure timely remediation of findings and demonstrable progress. • Produce regular program health reporting for senior leadership and Board-level stakeholders.

United States
$223K - $300K / year
Job Closed
Affirm logo

Senior Manager, Security Risk Management

Affirm

We create honest financial products that improve lives.

Full TimeRemoteTeam 1,001-5,000Since 2012H1B Sponsor

• Own Security Governance: maintain and evolve security policies, standards, and control frameworks (e.g., NIST CSF, ISO 27001), including mapping to controls and compliance requirements (SOC2, PCI, applicable regulations). • Lead program maturity planning, roadmaps, and cross-functional governance forums (e.g., security steering committee, risk council). • Define and enforce security risk appetite and decision criteria for third-party relationships and integrations. • Lead the Security TPRM function across vendor lifecycle: intake/onboarding, due diligence (IRQ/DDQ/SME reviews), contracting handoffs, ongoing monitoring, periodic reviews, and offboarding. • Ensure robust fourth-party oversight, including subprocessors, and manage remediation/QA cycles driven by Internal Audit and regulators. • Oversee high-risk vendor decisions and escalations; establish clear RACI for partnership contracts and security acceptance criteria. • Own program KPIs, dashboards, and reporting (Jira STPRM Ops, AuditBoard, Sigma/BI, MetricStream). Drive improvements in throughput, turnaround, backlog age, and remediation velocity. • Partner with Automation/TPRM Ops to operationalize threat-modeling outputs, integration inventories, pre-integration gates, and CI/CD checks; prioritize automations that reduce manual work and surface strategic escalations. • Implement and maintain QA processes (quarterly QA), runbooks, SOPs for ticket ownership, and evidence standards. • Build, coach, and scale the Governance and TPRM teams: hiring, performance management, career development, and team morale. • Act as the primary security contact for Legal, Procurement, Privacy, Product, and Engineering on vendor risk and governance matters. • Represent Security in executive forums, audit meetings, and regulatory engagements; own remediation commitments and timelines. • Serve as the security liaison for Internal Audit and external assessments; ensure timely remediation of findings and demonstrable progress. • Produce regular program health reporting for senior leadership and Board-level stakeholders.

Canada
$198K - $248K / year
Job Closed