Visa
Senior Cybersecurity Engineer IAM
Company
Role
Senior Cybersecurity Engineer IAM
Location
Job type
Full-time
Posted
1 hour ago
Salary
Job description
The Senior Cybersecurity Engineer – IAM is responsible for designing, implementing, and operating identity and access management controls across the Pismo platform, ensuring compliance with Pismo Visa Corporate Identity & Access Technical Security Requirements.
This role operates at platform and architecture level, supporting multicloud and hybrid environments, and focuses on building secure, automated, and auditable access models for human and non‑human identities. The position partners closely with Cloud Security, Platform Engineering, API, DevSecOps, and GRC teams to embed least‑privilege, zero‑trust, and automation‑first IAM practices across a regulated, multi‑tenant payments environment.
In addition to traditional IAM responsibilities, this role provides security and governance oversight for AI‑enabled identity use cases, ensuring that AI systems, agents, and automation interacting with identities comply with Internal AI Governance standards, GenAI & Agentic Systems requirements, and Corporate IAM Technical and Design requirements.
This is a remote position. A remote position does not require job duties be performed within proximity of a Visa office location. Remote positions may be required to be present at a Visa office with scheduled notice.
Basic Qualifications
5+ years of relevant work experience with a Bachelor’s Degree or at least 2 years of work experience with an Advanced degree (e.g. Masters, MBA, JD, MD) or 0 years of work experience with a PhD, OR 8+ years of relevant work experience.
Preferred Qualifications
5+ years of relevant work experience with a Bachelor’s Degree or at least 2 years of work experience with an Advanced degree (e.g. Masters, MBA, JD, MD) or 0 years of work experience with a PhD, OR 8+ years of relevant work experience.
8+ years of cybersecurity experience, with deep specialization in Identity & Access Management (IAM).
Proven experience operating at Senior / Consultant level, influencing IAM architecture, standards, and governance decisions.
Experience supporting financial services, payments, or regulated environments
Multicloud IAM Architecture (Mandatory)
Strong hands‑on experience designing and operating IAM across multicloud environments, including AWS and hybrid/federated cloud models.
Ability to design scalable permission models across cloud platforms, including:
Cloud‑native roles and permission sets
Least‑privilege and separation‑of‑duties enforcement
Human and non‑human identities (workloads, service accounts)
Permission Design & Access Modeling
Deep understanding of permission structures, including
Role‑based (RBAC) and attribute‑based (ABAC) access models
IAM‑governed access roles and entitlement cataloging
Temporary, just‑in‑time, and break‑glass access patterns
Ability to design access models that reduce audit scope, review volume, and operational risk.
IAM Automation & Engineering (Critical Requirement)
Strong experience implementing IAM automation, including
Automated provisioning and de‑provisioning (JML lifecycle)
Access revalidation and certification automation
Auto‑remediation of non‑compliant permissions
Experience integrating IAM controls with CI/CD pipelines and Infrastructure‑as‑Code (IaC).
Proven ability to codify IAM policies and controls using automation frameworks.
Coding & Scripting Skills
Hands‑on coding experience to support IAM automation and integrations, including:
Python or equivalent scripting languages
Use of APIs and SDKs to manage identities, roles, and entitlements
Automation via IaC tools (e.g., Terraform‑based IAM definitions)
Ability to build reusable, auditable, and scalable IAM automation components
Privileged Access & Cloud Governance
Experience designing and governing privileged access across cloud platforms.
Ability to enforce time‑bound, auditable privileged access aligned with least‑privilege principles.
Strong understanding of cloud governance roles required for vulnerability scanning, configuration
Work Hours: Varies upon the needs of the department.
Travel Requirements: This position requires travel 5-10% of the time.
Mental/Physical Requirements: This position will be performed in an office setting. The position will require the incumbent to sit and stand at a desk, communicate in person and by telephone, frequently operate standard office equipment, such as telephones and computers.
Visa is an EEO Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status. Visa will also consider for employment qualified applicants with criminal histories in a manner consistent with EEOC guidelines and applicable local law.
Visa will consider for employment qualified applicants with criminal histories in a manner consistent with applicable local law, including the requirements of Article 49 of the San Francisco Police Code.
U.S. APPLICANTS ONLY: The estimated salary range for this position is 145,300.00 to 232,700.00 USD per year, which may include potential sales incentive payments (if applicable). Salary may vary depending on job-related factors which may include knowledge, skills, experience, and location. In addition, this position may be eligible for bonus and equity. Visa has a comprehensive benefits package for which this position may be eligible that includes Medical, Dental, Vision, 401 (k), FSA/HSA, Life Insurance, Paid Time Off, and Wellness Program.
Explore more
Similar jobs
Cybersecurity Engineer
Visa
Staff Product Security Engineer
Digitalocean98
Cybersecurity Engineer- Local Candidates Only
Visa
Sr. Cybersecurity Engineer - Multi Cloud (AWS/Azure)
Visa
Cybersecurity Engineer - Sr. Consultant Level - Enterprise Security Architecture
Visa
Information Security Engineer
Taketwo