Privileged Access Management Architect

Jaguar Land Rover
Tadworth, UK
1 day ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
£80,000.0 - £85,000.0
Working hours
Regular working hours

Tech stack

Active Directory Application Programming Interfaces (APIs) Amazon Web Services Microsoft Azure Software as a Service Cloud Computing Cloud Engineering Key Management Windows PowerShell Azure Active Directory Zero Trust Network Access Cyberark
+4 more
Sentry Hardware Infrastructure Cloud Migration Terraform

Job description

  • Define our privileged access target architecture, including principles, standards, reference designs, and the roadmap to achieve them
  • Embed privileged access controls consistently across our on-premises infrastructure, AWS, Azure, and SaaS environments
  • Oversee implementations and provide design assurance without owning day-to-day operations
  • Align privileged access with Zero Trust and our wider enterprise identity strategy
  • Balance security and usability so our administrators can work effectively while remaining protected
  • Influence Security, Cloud, Infrastructure, and Risk stakeholders to adopt our designs without relying on positional authority

Technologies:

  • AWS
  • Active Directory
  • Architect
  • Azure
  • Cloud
  • PowerShell
  • Security
  • Sentry
  • Terraform

More:

We are a growing global financial services business offering an exciting opportunity for a Privileged Access Management Architect or Lead Cyber Engineer to step up and shape our privileged access strategy across a hybrid estate. In this role, we focus on reducing the risk associated with privileged human, administrative, and service identities while working across Security, Cloud, Infrastructure, and Risk to deliver practical, secure, and usable designs.

Requirements

  • Enterprise PAM architecture ownership, with direct experience defining a target state rather than only operating a platform
  • CyberArk architecture and deployment experience, including self-hosted or Privilege Cloud, with implementation oversight
  • CyberArk Sentry certification or higher, supported by hands-on deployment evidence
  • Strong Active Directory and Microsoft Entra ID foundations, with practical AWS and Azure exposure
  • Experience in regulated or high-consequence environments, including risk, audit, and evidence management
  • Strong senior stakeholder influence and the ability to get designs adopted, not just approved
  • Financial services background
  • CyberArk Guardian, CISSP, CCSP, or SC-300 certification desirable
  • Privilege Cloud migration experience desirable
  • Experience with secrets management and non-human identity desirable
  • Experience with endpoint privilege management desirable
  • Experience with cloud-native just-in-time access desirable
  • Automation experience using PowerShell, APIs, or Terraform desirable

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.co.uk

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · WWC 2024

1:22 min

Overview of the Sentry error and performance monitoring platform

Priscila Oliveira · WWC 2023

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · WWC 2023

3:21 min

Installing and configuring the Sentry JavaScript SDK for applications

Priscila Oliveira · WWC 2023

2:32 min

Overview of Terraform and Terraform Cloud features

Devlin Duldulao · LIVE

Videos

See all

Related articles

See all