PAM Lead — Privileged Access Management
Quick Overview
Job Description
New York City — hybrid: 3 days per week onsite at client office, 2 days remote
Position Overview
Our client, a financial services firm based in New York City, is seeking an experienced senior Privileged Access Management professional for a six-month engagement. The role carries broad ownership of day-to-day PAM operations and delivery, driving in-flight privileged account remediation initiatives and maintaining the governance and compliance posture of the privileged access program. The successful candidate will be a hands-on senior practitioner, equally comfortable coordinating team activities, engaging senior stakeholders, and working directly in the CyberArk platform. For the right individual, there is significant opportunity to shape the direction of the PAM program and take on greater responsibility over time.
Key Responsibilities
- Serve as a senior point of accountability for privileged access operations and delivery, providing direction and coordination across PAM team activities and workstreams.
- Own the administration, operation, and health of the CyberArk platform (vault, PSM, CPM, PVWA, and related components), including onboarding, policy management, session monitoring, and platform upgrades/patching.
- Drive privileged account remediation programs: discovery of unmanaged and orphaned privileged accounts, vaulting and rotation of credentials, elimination of standing privileges, and cleanup of legacy access across Linux, Windows, and Active Directory environments.
- Maintain and strengthen PAM governance: access certification and recertification campaigns, policy and standards ownership, exception management, and reporting to risk, audit, and compliance stakeholders.
- Manage privileged access across Windows Server and Linux/UNIX estates, including local administrator accounts, root/sudo access, service accounts, and break-glass procedures.
- Oversee Active Directory privileged access, including tiered administration, domain admin and privileged group hygiene, and integration of AD accounts into the PAM platform.
- Partner with Identity & Access Management, Information Security, Infrastructure, and Audit teams to align PAM controls with regulatory and internal policy requirements.
- Respond to audit findings and regulatory inquiries related to privileged access; own remediation plans through to closure with evidence.
- Provide metrics, KPIs, and executive reporting on PAM program health, remediation progress, and risk reduction.
- Document processes and support knowledge transfer to ensure sustainability of PAM operations beyond the engagement.
Required Qualifications
- 8+ years of experience in identity and access management or information security, with 4+ years focused on privileged access management, including experience leading programs, workstreams, or teams.
- Deep, hands-on expertise with CyberArk (Privilege Cloud and/or self-hosted PAS): vault administration, CPM/PSM configuration, safe and platform design, account onboarding, and troubleshooting.
- Strong working knowledge of both Linux/UNIX and Windows Server environments as they relate to privileged access (root/sudo models, local admin management, service accounts) — this is a must.
- Solid Active Directory expertise: privileged groups, delegation models, tiered admin architecture, GPOs relevant to privileged access, and AD integration with PAM tooling.
- Demonstrated experience leading privileged account remediation efforts at scale (discovery, vaulting, rotation, decommissioning) in a large or regulated enterprise.
- Experience with PAM governance: certification campaigns, policy development, audit response, and control evidence in a regulated (preferably financial services) environment.
- Strong stakeholder management and communication skills; able to operate at both executive and engineering levels.
- Ability to work a hybrid schedule from the client’s New York City office (3 days onsite / 2 days remote).
Preferred Qualifications
- Prior experience in banking, capital markets, asset management, or another regulated financial services environment.
- CyberArk certifications (Defender, Sentry, or Guardian) and/or security certifications such as CISSP or CISM.
- Familiarity with adjacent IAM tooling (e.g., SailPoint, Okta/Entra ID) and endpoint privilege management (CyberArk EPM or similar).
- Scripting skills (PowerShell, Bash, Python) for automation of onboarding, reporting, and remediation tasks.
- Experience managing PAM in hybrid environments (on-prem and cloud — AWS/Azure privileged access).
Work Arrangement
This is a hybrid role based at the client’s office in New York City: 3 days per week onsite and 2 days remote. Candidates must be able to reliably commute to the NYC office for the onsite days and be available for in-person meetings as required.
Skills
Similar jobs
ScienceLogic SME
Cloud Destinations LLC · United States
2 minutes agoFacilities Analyst Advanced
Chenega MIOS · Huntsville, United States
2 minutes agoPlanner
Atlas Copco Group · Rock Hill, United States
2 minutes agoField / Site Readiness Consultant
Kforce Technology Staffing · Juno Beach, United States
3 minutes agoCognos Admin Johnson Corner - GA - Georgia
Sierra Business Solution LLC · United States
3 minutes agoMachine Operator
Kforce Technology Staffing · Tewksbury, United States
3 minutes ago