> Markdown version of [/jobs/ext/2026666-pam-lead-iam](https://www.wearedevelopers.com/jobs/ext/2026666-pam-lead-iam). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # PAM Lead (IAM) - **Company:** Datum Software - **Location:** New York, NY, United States - **Experience:** Expert - **Contract:** Temporary to permanent - **Skills:** Microsoft Windows, Active Directory, Linux, Identity and Access Management, Key Management, Cyberark, SailPoint - **Published:** August 11, 2026 - **Apply:** https://www.dice.com/job-detail/f1d119f3-8e19-4c2c-93b6-e13a2f3f0849 ## About the Role * Identity and Access Management (IAM) experience, including focus on Privileged Access Management. * Proven success leading enterprise PAM initiatives within large, complex, and regulated environments. * Strong hands-on experience with CyberArk, including privileged account management, service account onboarding, vaulting, and remediation activities. * Deep knowledge of Active Directory, privileged groups, secondary administrator accounts, nested groups, and Windows access controls. * Working knowledge of Linux privileged access management, sudo administration, service accounts, and SSH controls. * Experience with SailPoint IdentityIQ and/or IdentityNow, including entitlement governance, ownership management, certifications, and application onboarding. * Experience collaborating with Internal Audit, Risk, Compliance, Infrastructure, and Application teams. * Demonstrated ability to drive remediation efforts across multiple stakeholders without direct authority. * Strong communication and executive reporting skills. Preferred * Experience in financial services or other highly regulated environments. * Background supporting audit, compliance, and risk management initiatives. * Familiarity with enterprise secrets management and privileged account governance best practices. ## Description * We are seeking a highly experienced Senior Privileged Access Management (PAM) Lead to drive key PAM governance, risk reduction, and remediation initiatives across the enterprise. * This is a hands-on, delivery-focused role responsible for improving privileged access controls, reducing security risk, and partnering with stakeholders across Technology, Risk, Compliance, and Internal Audit. * The ideal candidate will quickly assess the current environment, independently lead remediation efforts, and deliver measurable outcomes across multiple workstreams. * This role requires strong expertise in CyberArk, and privileged access governance. * This is not a CyberArk administration-only position; it is a strategic and execution-focused leadership role., * Lead and execute enterprise-wide PAM governance, risk reduction, and remediation initiatives. * Partner with Governance, Risk, Compliance, Infrastructure, and Application teams to improve privileged access controls and address audit findings. * Review privileged access requests, policy exceptions, service account access, and Active Directory group structures to identify risks and recommend appropriate controls. * Drive efforts to reduce standing administrative privileges and migrate users to secondary administrative accounts across Windows, Linux, and endpoint environments. * Monitor PAM Key Risk Indicators (KRIs), investigate trends, determine root causes, and coordinate remediation activities. * Support Internal Audit engagements, including evidence collection, issue remediation, and control validation. * Provide clear executive-level status reporting, highlighting progress, risks, dependencies, and remediation plans. * Coordinate cross-functional teams to ensure remediation initiatives are completed on schedule. Priority Focus Areas * CyberArk privileged and service account onboarding. * Reduction of global and standing administrator access. * Remediation of clear-text credential exposure through CyberArk and approved secrets management solutions. * Active Directory nested group and file share permission cleanup. * SailPoint entitlement governance, ownership validation, and application onboarding improvements. * Delivery of audit and risk-driven remediation activities. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)