PAM Lead (IAM)

Datum Software
New York, NY, United States
8 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Active Directory Linux Identity and Access Management Key Management Cyberark SailPoint

Job description

  • We are seeking a highly experienced Senior Privileged Access Management (PAM) Lead to drive key PAM governance, risk reduction, and remediation initiatives across the enterprise.
  • This is a hands-on, delivery-focused role responsible for improving privileged access controls, reducing security risk, and partnering with stakeholders across Technology, Risk, Compliance, and Internal Audit.
  • The ideal candidate will quickly assess the current environment, independently lead remediation efforts, and deliver measurable outcomes across multiple workstreams.
  • This role requires strong expertise in CyberArk, and privileged access governance.
  • This is not a CyberArk administration-only position; it is a strategic and execution-focused leadership role., * Lead and execute enterprise-wide PAM governance, risk reduction, and remediation initiatives.
  • Partner with Governance, Risk, Compliance, Infrastructure, and Application teams to improve privileged access controls and address audit findings.
  • Review privileged access requests, policy exceptions, service account access, and Active Directory group structures to identify risks and recommend appropriate controls.
  • Drive efforts to reduce standing administrative privileges and migrate users to secondary administrative accounts across Windows, Linux, and endpoint environments.
  • Monitor PAM Key Risk Indicators (KRIs), investigate trends, determine root causes, and coordinate remediation activities.
  • Support Internal Audit engagements, including evidence collection, issue remediation, and control validation.
  • Provide clear executive-level status reporting, highlighting progress, risks, dependencies, and remediation plans.
  • Coordinate cross-functional teams to ensure remediation initiatives are completed on schedule.

Priority Focus Areas

  • CyberArk privileged and service account onboarding.
  • Reduction of global and standing administrator access.
  • Remediation of clear-text credential exposure through CyberArk and approved secrets management solutions.
  • Active Directory nested group and file share permission cleanup.
  • SailPoint entitlement governance, ownership validation, and application onboarding improvements.
  • Delivery of audit and risk-driven remediation activities.

Requirements

  • Identity and Access Management (IAM) experience, including focus on Privileged Access Management.
  • Proven success leading enterprise PAM initiatives within large, complex, and regulated environments.
  • Strong hands-on experience with CyberArk, including privileged account management, service account onboarding, vaulting, and remediation activities.
  • Deep knowledge of Active Directory, privileged groups, secondary administrator accounts, nested groups, and Windows access controls.
  • Working knowledge of Linux privileged access management, sudo administration, service accounts, and SSH controls.
  • Experience with SailPoint IdentityIQ and/or IdentityNow, including entitlement governance, ownership management, certifications, and application onboarding.
  • Experience collaborating with Internal Audit, Risk, Compliance, Infrastructure, and Application teams.
  • Demonstrated ability to drive remediation efforts across multiple stakeholders without direct authority.
  • Strong communication and executive reporting skills.

Preferred

  • Experience in financial services or other highly regulated environments.
  • Background supporting audit, compliance, and risk management initiatives.
  • Familiarity with enterprise secrets management and privileged account governance best practices.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:08 min

Managing complex structures and corporate guidelines

Alexandra Petri · World Congress 2023

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

1:30 min

Operating developer-friendly identity infrastructure using Affinity Elements

Adam Larter Adam Larter · World Congress 2024

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · World Congress 2023

8:22 min

Simulating a Linux terminal and running Spring Boot

Jakov Semenski · LIVE

Videos

See all

Related articles

See all