
Technical Architect – Privileged Access Management
Posted Jul 18

Posted Jul 18
This is a fully remote position, open to applicants in Florida.
• Take ownership of the global CyberArk PAM Suite, including vault configuration, safe structure, session recording, JIT workflows, rotation schedules, and CyberArk for OT session gating.
• Create and maintain the PAM roadmap, ensuring alignment with the overall cybersecurity strategy and business objectives.
• Design and implement Just-In-Time privileged access for all Tier 0, Tier 1, and Tier 2 accounts—ensuring no standing privilege, with all sessions vaulted and recorded.
• Manage the Non-Human Identity governance program, which encompasses service account vaulting, rotation automation, NHI inventory, and governance framework.
• Govern PAM for OT in partnership with the OT Architect, focusing on vendor session gating, session recordings, and OT privileged account management.
• Establish and enforce PAM design standards, including vault structure, safe naming conventions, rotation schedules, and session recording retention policies.
• Lead the Privileged Access Management technical roadmap and manage vendor relationships, including product roadmap briefings, TAM interactions, and upgrade schedules.
• Integrate CyberArk Threat Analytics with MSSP and SIEM for detecting anomalies in privileged accounts.
• Spearhead the design, architecture, and implementation of complex Privileged Access Management (PAM) solutions.
• Convert business requirements and security policies into effective technical PAM solutions and configurations.
• Collaborate with various IT teams (such as infrastructure, applications, and network) to ensure the seamless integration of PAM solutions.
• Provide technical expertise and guidance on PAM best practices, security controls, and compliance requirements (e.g., NIST, ISO 27001, GDPR).
• Conduct security assessments, vulnerability analyses, and penetration tests related to privileged access.
• Develop and implement automation scripts and tools to optimize PAM operations and improve security posture.
• Create and maintain thorough documentation, including architectural designs, solution configurations, and operational procedures.
• Support incident response efforts related to breaches or anomalies involving privileged access.
• Mentor junior security engineers and provide technical leadership within the cybersecurity team.
• Stay updated on emerging PAM technologies, threats, and industry trends.
• Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
• A minimum of 8 years of experience in cybersecurity, with at least 5 years dedicated to Privileged Access Management (PAM) architecture and engineering.
• Demonstrated expertise in designing, implementing, and managing enterprise-grade PAM solutions (e.g., Delinea Secret Server, CyberArk, BeyondTrust).
• Strong comprehension of identity and access management (IAM) concepts, including directory services (Active Directory, LDAP), SSO, MFA, and federation.
• Extensive knowledge of security protocols (e.g., Kerberos, OAuth, SAML, OpenID Connect) and cryptographic principles.
• Experience with scripting languages (e.g., Python, PowerShell) for automation and integration purposes.
• Familiarity with cloud security principles and PAM in cloud environments (AWS, Azure, GCP).
• Solid understanding of network security, operating systems (Windows, Linux), and database security.
• Exceptional analytical, problem-solving, and decision-making abilities.
• Strong communication and interpersonal skills, capable of articulating complex technical concepts to both technical and non-technical audiences.
• Relevant industry certifications such as CISSP, CISM, or vendor-specific PAM certifications are advantageous.
• Medical, dental, and vision insurance plans.
• Paid time off accruing at a rate of 3.07 hours during your first year of employment.
• Four weeks of paid parental leave.
• In 2026, enjoy 11 company-paid holidays (9 fixed holidays and 2 optional floating holidays), subject to annual changes.
• 401(k) retirement plan.
• Employee stock purchase plan.
OneDome
Dev.Pro
Blue Water Thinking
Verity Group
Get handpicked remote jobs straight to your inbox weekly.