Senior Identity & Access Management Engineer
Job Description
Summary
We are seeking a highly skilled and motivated Senior Identity and Access Management (IAM) Engineer to join our Information Security team. The ideal candidate will primarily be responsible for managing and optimizing our Privileged Access Management (PAM) solution to ensure the security and integrity of our organizations privileged accounts.
This role will also involve a secondary focus on IAM and Identity Governance and Administration (IGA). Key responsibilities include the daily administration and continuous improvement of our PAM environment, as well as collaboration with the IAM team for identity management through the IGA tool. Additionally, this role requires collaboration with the broader Security Engineering team, which oversees all security platforms across the organization.
Key Responsibilities
CyberArk Administration : Manage the deployment, configuration, and maintenance of CyberArk Privilege Cloud, including the Central Policy Manager (CPM), Password Vault, and Privileged Session Manager (PSM). CyberArk Engineering : Build and maintain integrations between CyberArk and third-party applications to enable remote access (RDP, SSH, etc.) and credential rotation. Identity and Access Management : Administer accounts, groups and services related to identity and access in Active Directory, Microsoft Azure/Entra, and Cisco Duo. Identity Governance : Assist with configuration and management of SailPoint for mover/joiner/leaver scenarios and governance of all applications and associates. Policy Implementation : Implement and enforce policies and procedures for IAM to align with corporate guidelines, industry best practices and regulatory requirements. Documentation : Maintain documentation for IAM configurations and procedures. Training and Support : Provide training and support to other IT staff and business units on best practices for IAM and PAM. Continuous Improvement : Stay up to date with the latest security trends and product updates. Identify opportunities for process improvements and implement enhancements.
Required Qualifications
Education : Bachelors degree in Computer Science, Information Technology, Cybersecurity, or a related field. Experience : 7+ years of experience with CyberArk Privilege Cloud, SailPoint, Microsoft Azure/Entra, Active Directory, or similar IAM/PAM tools. Certifications : CISSP, CISM or other relevant industry certifications are a plus.
Technical Skills
In-depth knowledge of CyberArk solutions and components. In-depth knowledge of Active Directory. Experience with privileged access management, identity management, identity governance and security controls. Experience with Single Sign On (SSO) and related protocols. Familiarity with scripting languages (e.g., PowerShell, Python), REST APIs and API based authentication.
Desired Skills
Analytical Skills : Strong problem-solving abilities and attention to detail. Communication Skills : Excellent verbal and written communication skills, with the ability to convey technical concepts to non-technical stakeholders. Project Management : Ability to manage multiple tasks and projects simultaneously, prioritize effectively, and meet deadlines.
