Pam (Cyberark) Engineer--Bulgaria/ Spain (Remote)

Ampstek
Sarria, Spain
12 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
4 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Access Microsoft Windows Active Directory Application Programming Interfaces (APIs) Amazon Web Services Data Analysis Microsoft Azure Cloud Computing Cyber Security Databases Continuous Integration Linux
+25 more
DevOps Monitoring of Systems Identity and Access Management Python (Programming Language) Key Management OpenShift Oracle (Applications) Windows PowerShell Azure Active Directory Zero Trust Network Access Runbook Session Management Security Information and Event Management SQL Databases Systems Integration Scripting Cloud Platform System Cyberark Containerization Kubernetes Information Technology Sentry SailPoint Restful APIs Servicenow

Job description

Title: PAM (CyberArk) EngineerLocation: Bulgaria and Spain (Remote)Employment Contract. (C2H)Job Description:The PAM Engineer is responsible for the deployment, administration, and operational management of Privileged Access Management (PAM) solutions, ensuring secure onboarding, governance, and lifecycle management of privileged accounts and secrets across on-premises and cloud environments. The engineer implements strong credential management controls, Just-in-Time (JIT) access, secrets management, and automation of PAM processes while maintaining compliance with organizational security and audit requirements.KEY RESPONSIBILITIESNo deje pasar esta oportunidad, inscríbase rápidamente si su experiencia y habilidades coinciden con lo que se indica en la siguiente descripción.- Install, configure, and maintain CyberArk components including Vault, PVWA, CPM, PSM, PTA, and Conjur- Perform onboarding of privileged accounts across platforms such as Windows, Linux, databases (Oracle, SQL), cloud, and application environments, ensuring proper classification and secure vaulting- Manage end-to-end privileged account lifecycle including inventory collection, validation, ownership mapping, approval coordination, and onboarding- Implement and manage Just-in-Time (JIT) privileged access and session management controls- Enforce password and credential management policies including automated password rotation, password complexity enforcement, and secure credential storage- Manage secrets for applications using Conjur or equivalent secrets management solutions- Identify and manage accounts requiring special handling (e.G., service accounts, shared accounts, non-rotating accounts), ensuring appropriate controls and risk mitigation- Monitor password compliance and remediate accounts not adhering to defined rotation or policy standards- Provide Level 2/3 support for PAM-related incidents and service requests- Troubleshoot issues related to CyberArk and integrations with Active Directory, Entra ID (Azure AD), IAM tools, SIEM platforms, and ServiceNow- Perform regular health checks, system monitoring, patching, and upgrades of CyberArk infrastructure- Automate PAM processes using scripting and APIs (PowerShell, Python, REST APIs, psPAS) to reduce manual effort- Support bulk onboarding and large-scale privileged account management through automation and standardized methods- Design and support integrations between PAM and enterprise IAM systems (e.G., SailPoint, Saviynt, Entra ID) for identity lifecycle and access governance alignment- Maintain documentation including SOPs, onboarding procedures, runbooks, and automation scripts- Collaborate with application, infrastructure, and cloud teams to enforce least privilege access and secure credential usage- Participate in audit and compliance activities by providing evidence, reporting, and demonstrating control effectiveness- Support governance activities including account recertification, ownership validation, and compliance monitoringREQUIRED SKILLS & QUALIFICATIONS- Bachelor’s degree in Computer Science, Information Security, or related field- 4-8 years of experience in IT security, IAM, or PAM engineering- Strong hands-on experience with CyberArk PAM suite (Vault, CPM, PSM, PVWA)- Experience with CyberArk Conjur or other enterprise secrets management solutions- Strong understanding of Just-in-Time (JIT) access and privileged session management- Experience integrating PAM with IAM platforms (e.G., SailPoint, Saviynt, Entra ID / Azure AD)- Experience managing privileged access in cloud environments (Azure, xbhjioe AWS)- Strong understanding of Windows, Linux, Active Directory, and database systems (Oracle, SQL)- Strong scripting and automation experience (PowerShell, Python, REST APIs)- Experience with ITSM tools such as ServiceNow and incident/change management processes- Knowledge of security controls, audit frameworks, and compliance standards- Strong analytical and problem-solving skillsPREFERRED QUALIFICATIONS:- CyberArk Defender / Sentry certification- Experience implementing Conjur in DevOps / CI-CD environments- Experience with Privileged Threat Analytics (PTA) or advanced monitoring tools- Exposure to container platforms (Kubernetes, OpenShift) and secrets management- Familiarity with Zero Trust security architectureSOFT SKILLS :- Strong analytical and troubleshooting abilities- Ability to work independently and within cross-functional teams- Excellent communication skills with both technical and non-technical stakeholders- Attention to detail and commitment to security best practicesHay opciones de teletrabajo/trabajo desde casa disponibles para este puesto.

Requirements

Bachelor’s degree in Computer Science, Information Security, or related fie ld

  • 4-8 years of experience in IT security, IAM, or PAM engineeri ng

  • Strong hands-on experience with CyberArk PAM suite (Vault, CPM, PSM, PVW A)

  • Experience with CyberArk Conjur or other enterprise secrets management solutio ns

  • Strong understanding of Just-in-Time (JIT) access and privileged session manageme nt

  • Experience integrating PAM with IAM platforms (e.G., SailPoint, Saviynt, Entra ID / Azure A D)

  • Experience managing privileged access in cloud environments (Azure, xbhjioe AW S)

  • Strong understanding of Windows, Linux, Active Directory, and database systems (Oracle, SQ L)

  • Strong scripting and automation experience (PowerShell, Python, REST API s)

  • Experience with ITSM tools such as ServiceNow and incident/change management process es

  • Knowledge of security controls, audit frameworks, and compliance standar ds

  • Strong analytical and problem-solving skil ls PREFERRED QUALIFICATIO NS:

  • CyberArk Defender / Sentry certificat ion

  • Experience implementing Conjur in DevOps / CI-CD environme nts

  • Experience with Privileged Threat Analytics (PTA) or advanced monitoring to ols

  • Exposure to container platforms (Kubernetes, OpenShift) and secrets managem ent

  • Familiarity with Zero Trust security architect ure SOFT SKIL LS :

  • Strong analytical and troubleshooting abili ties

  • Ability to work independently and within cross-functional t eams

  • Excellent communication skills with both technical and non-technical stakehol ders

  • Attention to detail and commitment to security best pract

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

1:22 min

Overview of the Sentry error and performance monitoring platform

Priscila Oliveira · WWC 2023

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all