
Senior Cybersecurity Engineer IAM
Visa, Austin, TX, United States
Company Overview
Founded by experienced entrepreneurs and engineers in 2016, Pismo is a technology company that provides a comprehensive processing platform for banking, card issuing and financial market infrastructure and helps customers innovate and build the next generation of banking and payment solutions. Pismo joined Visa in 2024.
Leveraging Visa's solutions, our core platform, and an expanding suite of capabilities, Pismo addresses the technological challenges that large banks, marketplaces, and fintech companies face in migrating from legacy systems to more advanced technology in the market. Pismo's cloud-based platform empowers firms to build and launch financial products rapidly, scaling as they grow to have a broader audience while keeping high security and availability standards.
Job Description The Senior Cybersecurity Engineer - IAM is responsible for designing, implementing, and operating identity and access management controls across the Pismo platform, ensuring compliance with Pismo Visa Corporate Identity & Access Technical Security Requirements.
This role operates at platform and architecture level, supporting multicloud and hybrid environments, and focuses on building secure, automated, and auditable access models for human and nonhuman identities. The position partners closely with Cloud Security, Platform Engineering, API, DevSecOps, and GRC teams to embed least‑privilege, zero‑trust, and automation‑first IAM practices across a regulated, multitenant payments environment.
In addition to traditional IAM responsibilities, this role provides security and governance oversight for AI‑enabled identity use cases, ensuring that AI systems, agents, and automation interacting with identities comply with Internal AI Governance standards, GenAI & Agentic Systems requirements, and Corporate IAM Technical and Design requirements.
This is a remote position. A remote position does not require job duties to be performed within proximity of a Visa office location. Remote positions may be required to be present at a Visa office with scheduled notice.
Qualifications Basic Qualifications:
5+ years of relevant work experience with a Bachelor's Degree or at least 2 years of work experience with an Advanced degree (e.g., Masters, MBA, JD, MD) or 0 years of work experience with a PhD, OR 8+ years of relevant work experience.
Preferred Qualifications:
8+ years cybersecurity experience, with deep specialization in Identity & Access Management (IAM).
Proven experience operating at Senior / Consultant level, influencing IAM architecture, standards, and governance decisions.
Experience supporting financial services, payments, or regulated environments.
Multicloud IAM Architecture (Mandatory).
Strong hands‑on experience designing and operating IAM across multicloud environments, including AWS and hybrid/federated cloud models.
Ability to design scalable permission models across cloud platforms, including cloud‑native roles and permission sets, least‑privilege and separation of duties enforcement, human and non‑human identities (workloads, service accounts), permission design & access modeling, and deep understanding of permission structures (role‑based and attribute‑based access models, IAM‑governed access roles and entitlement cataloging, temporary, just‑in‑time, and break‑glass access patterns).
Ability to design access models that reduce audit scope, review volume, and operational risk.
IAM Automation & Engineering (Critical Requirement).
Strong experience implementing IAM automation, including automated provisioning and deprovisioning (JML lifecycle), access revalidation and certification automation, auto‑remediation of noncompliant permissions, and integration of IAM controls with CI/CD pipelines and Infrastructure as Code (IaC).
Proven ability to codify IAM policies and controls using automation frameworks.
Coding & Scripting Skills: Hands‑on coding experience to support IAM automation and integrations, including Python or equivalent scripting languages, use of APIs and SDKs to manage identities, roles, and entitlements, automation via IaC tools (e.g., Terraform‑based IAM definitions), and ability to build reusable, auditable, scalable IAM automation components.
Privileged Access & Cloud Governance: Experience designing and governing privileged access across cloud platforms, enforcing time‑bound, auditable privileged access aligned with least‑privilege principles, and strong understanding of cloud governance roles required for vulnerability scanning, configuration, etc.
Additional Information Work Hours:
Varies upon the needs of the department.
Travel Requirements:
This position requires travel 5-10% of the time.
Mental/Physical Requirements:
This position will be performed in an office setting. The position will require the incumbent to sit and stand at a desk, communicate in person and by telephone, frequently operate standard office equipment, such as telephones and computers.
Compensation & Benefits U.S. Applicants only: The estimated salary range for this position is 145,300.00 to 232,700.00 USD per year, which may include potential sales incentive payments (if applicable). Salary may vary depending on job‑related factors which may include knowledge, skills, experience, and location. In addition, this position may be eligible for bonus and equity. Visa has a comprehensive benefits package for which this position may be eligible that includes Medical, Dental, Vision, 401(k), FSA/HSA, Life Insurance, Paid Time Off, and Wellness Program.
EEO Statement Visa is an EEO Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status. Visa will also consider for employment qualified applicants with criminal histories in a manner consistent with EEOC guidelines and applicable local law. Visa will consider for employment qualified applicants with criminal histories in a manner consistent with applicable local law, including the requirements of Article 49 of the San Francisco Police Code.
#J-18808-Ljbffr
Leveraging Visa's solutions, our core platform, and an expanding suite of capabilities, Pismo addresses the technological challenges that large banks, marketplaces, and fintech companies face in migrating from legacy systems to more advanced technology in the market. Pismo's cloud-based platform empowers firms to build and launch financial products rapidly, scaling as they grow to have a broader audience while keeping high security and availability standards.
Job Description The Senior Cybersecurity Engineer - IAM is responsible for designing, implementing, and operating identity and access management controls across the Pismo platform, ensuring compliance with Pismo Visa Corporate Identity & Access Technical Security Requirements.
This role operates at platform and architecture level, supporting multicloud and hybrid environments, and focuses on building secure, automated, and auditable access models for human and nonhuman identities. The position partners closely with Cloud Security, Platform Engineering, API, DevSecOps, and GRC teams to embed least‑privilege, zero‑trust, and automation‑first IAM practices across a regulated, multitenant payments environment.
In addition to traditional IAM responsibilities, this role provides security and governance oversight for AI‑enabled identity use cases, ensuring that AI systems, agents, and automation interacting with identities comply with Internal AI Governance standards, GenAI & Agentic Systems requirements, and Corporate IAM Technical and Design requirements.
This is a remote position. A remote position does not require job duties to be performed within proximity of a Visa office location. Remote positions may be required to be present at a Visa office with scheduled notice.
Qualifications Basic Qualifications:
5+ years of relevant work experience with a Bachelor's Degree or at least 2 years of work experience with an Advanced degree (e.g., Masters, MBA, JD, MD) or 0 years of work experience with a PhD, OR 8+ years of relevant work experience.
Preferred Qualifications:
8+ years cybersecurity experience, with deep specialization in Identity & Access Management (IAM).
Proven experience operating at Senior / Consultant level, influencing IAM architecture, standards, and governance decisions.
Experience supporting financial services, payments, or regulated environments.
Multicloud IAM Architecture (Mandatory).
Strong hands‑on experience designing and operating IAM across multicloud environments, including AWS and hybrid/federated cloud models.
Ability to design scalable permission models across cloud platforms, including cloud‑native roles and permission sets, least‑privilege and separation of duties enforcement, human and non‑human identities (workloads, service accounts), permission design & access modeling, and deep understanding of permission structures (role‑based and attribute‑based access models, IAM‑governed access roles and entitlement cataloging, temporary, just‑in‑time, and break‑glass access patterns).
Ability to design access models that reduce audit scope, review volume, and operational risk.
IAM Automation & Engineering (Critical Requirement).
Strong experience implementing IAM automation, including automated provisioning and deprovisioning (JML lifecycle), access revalidation and certification automation, auto‑remediation of noncompliant permissions, and integration of IAM controls with CI/CD pipelines and Infrastructure as Code (IaC).
Proven ability to codify IAM policies and controls using automation frameworks.
Coding & Scripting Skills: Hands‑on coding experience to support IAM automation and integrations, including Python or equivalent scripting languages, use of APIs and SDKs to manage identities, roles, and entitlements, automation via IaC tools (e.g., Terraform‑based IAM definitions), and ability to build reusable, auditable, scalable IAM automation components.
Privileged Access & Cloud Governance: Experience designing and governing privileged access across cloud platforms, enforcing time‑bound, auditable privileged access aligned with least‑privilege principles, and strong understanding of cloud governance roles required for vulnerability scanning, configuration, etc.
Additional Information Work Hours:
Varies upon the needs of the department.
Travel Requirements:
This position requires travel 5-10% of the time.
Mental/Physical Requirements:
This position will be performed in an office setting. The position will require the incumbent to sit and stand at a desk, communicate in person and by telephone, frequently operate standard office equipment, such as telephones and computers.
Compensation & Benefits U.S. Applicants only: The estimated salary range for this position is 145,300.00 to 232,700.00 USD per year, which may include potential sales incentive payments (if applicable). Salary may vary depending on job‑related factors which may include knowledge, skills, experience, and location. In addition, this position may be eligible for bonus and equity. Visa has a comprehensive benefits package for which this position may be eligible that includes Medical, Dental, Vision, 401(k), FSA/HSA, Life Insurance, Paid Time Off, and Wellness Program.
EEO Statement Visa is an EEO Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status. Visa will also consider for employment qualified applicants with criminal histories in a manner consistent with EEOC guidelines and applicable local law. Visa will consider for employment qualified applicants with criminal histories in a manner consistent with applicable local law, including the requirements of Article 49 of the San Francisco Police Code.
#J-18808-Ljbffr