PAM Lead (IAM)
Datum Software
New York, NY, United States
8 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.dice.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source
Tech stack
Microsoft Windows
Active Directory
Linux
Identity and Access Management
Key Management
Cyberark
SailPoint
Job description
- We are seeking a highly experienced Senior Privileged Access Management (PAM) Lead to drive key PAM governance, risk reduction, and remediation initiatives across the enterprise.
- This is a hands-on, delivery-focused role responsible for improving privileged access controls, reducing security risk, and partnering with stakeholders across Technology, Risk, Compliance, and Internal Audit.
- The ideal candidate will quickly assess the current environment, independently lead remediation efforts, and deliver measurable outcomes across multiple workstreams.
- This role requires strong expertise in CyberArk, and privileged access governance.
- This is not a CyberArk administration-only position; it is a strategic and execution-focused leadership role., * Lead and execute enterprise-wide PAM governance, risk reduction, and remediation initiatives.
- Partner with Governance, Risk, Compliance, Infrastructure, and Application teams to improve privileged access controls and address audit findings.
- Review privileged access requests, policy exceptions, service account access, and Active Directory group structures to identify risks and recommend appropriate controls.
- Drive efforts to reduce standing administrative privileges and migrate users to secondary administrative accounts across Windows, Linux, and endpoint environments.
- Monitor PAM Key Risk Indicators (KRIs), investigate trends, determine root causes, and coordinate remediation activities.
- Support Internal Audit engagements, including evidence collection, issue remediation, and control validation.
- Provide clear executive-level status reporting, highlighting progress, risks, dependencies, and remediation plans.
- Coordinate cross-functional teams to ensure remediation initiatives are completed on schedule.
Priority Focus Areas
- CyberArk privileged and service account onboarding.
- Reduction of global and standing administrator access.
- Remediation of clear-text credential exposure through CyberArk and approved secrets management solutions.
- Active Directory nested group and file share permission cleanup.
- SailPoint entitlement governance, ownership validation, and application onboarding improvements.
- Delivery of audit and risk-driven remediation activities.
Requirements
- Identity and Access Management (IAM) experience, including focus on Privileged Access Management.
- Proven success leading enterprise PAM initiatives within large, complex, and regulated environments.
- Strong hands-on experience with CyberArk, including privileged account management, service account onboarding, vaulting, and remediation activities.
- Deep knowledge of Active Directory, privileged groups, secondary administrator accounts, nested groups, and Windows access controls.
- Working knowledge of Linux privileged access management, sudo administration, service accounts, and SSH controls.
- Experience with SailPoint IdentityIQ and/or IdentityNow, including entitlement governance, ownership management, certifications, and application onboarding.
- Experience collaborating with Internal Audit, Risk, Compliance, Infrastructure, and Application teams.
- Demonstrated ability to drive remediation efforts across multiple stakeholders without direct authority.
- Strong communication and executive reporting skills.
Preferred
- Experience in financial services or other highly regulated environments.
- Background supporting audit, compliance, and risk management initiatives.
- Familiarity with enterprise secrets management and privileged account governance best practices.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.dice.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
DC
Daniel Cranney
6 months ago
MH
Michael Hunger
Everything a Developer Needs to Know About MCP with Neo4j
about 1 year ago
IK
Igor Khokhriakov
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
6 days ago
DC
Daniel Cranney
Dev Digest 164: AI Agents, AI Blindspots and MCP security problems
over 1 year ago
DC
Daniel Cranney
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents
10 months ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago