Technical Architect - Privileged Access Management
Core
Designing, implementing, and maintaining enterprise-grade Privileged Access Management (PAM) solutions to protect critical assets and data across a global manufacturing enterprise.
Role type
Senior IC Cybersecurity Technical Architect (PAM)
Builds
Global PAM strategy, Just-In-Time privileged access workflows, Non-Human Identity governance programs, and OT session gating solutions.
Domain
Cybersecurity, Identity and Access Management (IAM), Operational Technology (OT)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Enterprise PAM architecture (CyberArk, Delinea, BeyondTrust), Identity and Access Management (IAM), Directory services (Active Directory, LDAP), Security protocols (Kerberos, OAuth, SAML, OpenID Connect), Cryptography, Python/PowerShell scripting, Cloud security (AWS, Azure, GCP), Network security, OS security (Windows, Linux), Database security, Security assessment and penetration testing, Incident response, Technical roadmap planning, Vendor relationship management, Automation scripting, Architectural design, Compliance frameworks (NIST, ISO 27001, GDPR), Mentorship
Preferred skills
Master's degree in CS/IT/Cybersecurity, CISSP/CISM certifications, Vendor-specific PAM certifications
Technologies
CyberArk, Delinea Secret Server, BeyondTrust, Python, PowerShell, AWS, Azure, GCP, Active Directory, LDAP, Kerberos, OAuth, SAML, OpenID Connect
Responsibilities
Own and operate CyberArk PAM Suite globally including vault configuration, session recording, JIT workflows, and rotation schedules. Develop and maintain the PAM roadmap aligned with cybersecurity strategy. Design and implement Just-In-Time privileged access for Tier 0, 1, and 2 accounts. Own the Non-Human Identity governance program including service account vaulting and automation. Govern PAM for OT alongside the OT Architect for vendor session gating. Define and enforce PAM design standards and retention policies. Integrate CyberArk Threat Analytics with MSSP and SIEM for anomaly detection. Lead the design and implementation of complex PAM solutions. Translate business requirements into technical PAM configurations. Collaborate with IT teams for seamless PAM integration. Provide technical expertise on PAM best practices and compliance. Conduct security assessments and penetration testing. Develop automation scripts to streamline PAM operations. Create and maintain comprehensive architectural documentation. Support incident response activities related to privileged access breaches. Mentor junior security engineers.
Seniority
Senior, hands-on IC with mentorship responsibilities