PAM Lead — Privileged Access Management

Hybrid in New York, NY, US • Posted 2 days ago • Updated 2 days ago
Contract W2
Contract Independent
6 Months
75% Travel Required
Hybrid
Depends on Experience
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Asset Management
  • Cloud Computing
  • CyberArk
  • Information Security
  • Identity Management
  • Financial Services
  • Linux
  • CISSP
  • CISM
  • Banking
  • SAFE
  • Auditing
  • EPM
  • Communication
  • Accountability
  • Active Directory
  • Amazon Web Services
  • Sustainability
  • Reporting
  • Microsoft Windows
  • Microsoft Windows Server
  • Microsoft Operating Systems

Summary

Key Responsibilities
  • Serve as a senior point of accountability for privileged access operations and delivery, providing direction and coordination across PAM team activities and workstreams.
  • Own the administration, operation, and health of the CyberArk platform (vault, PSM, CPM, PVWA, and related components), including onboarding, policy management, session monitoring, and platform upgrades/patching.
  • Drive privileged account remediation programs: discovery of unmanaged and orphaned privileged accounts, vaulting and rotation of credentials, elimination of standing privileges, and cleanup of legacy access across Linux, Windows, and Active Directory environments.
  • Maintain and strengthen PAM governance: access certification and recertification campaigns, policy and standards ownership, exception management, and reporting to risk, audit, and compliance stakeholders.
  • Manage privileged access across Windows Server and Linux/UNIX estates, including local administrator accounts, root/sudo access, service accounts, and break-glass procedures.
  • Oversee Active Directory privileged access, including tiered administration, domain admin and privileged group hygiene, and integration of AD accounts into the PAM platform.
  • Partner with Identity & Access Management, Information Security, Infrastructure, and Audit teams to align PAM controls with regulatory and internal policy requirements.
  • Respond to audit findings and regulatory inquiries related to privileged access; own remediation plans through to closure with evidence.
  • Provide metrics, KPIs, and executive reporting on PAM program health, remediation progress, and risk reduction.
  • Document processes and support knowledge transfer to ensure sustainability of PAM operations beyond the engagement.
Required Qualifications
  • 8+ years of experience in identity and access management or information security, with 4+ years focused on privileged access management, including experience leading programs, workstreams, or teams.
  • Deep, hands-on expertise with CyberArk (Privilege Cloud and/or self-hosted PAS): vault administration, CPM/PSM configuration, safe and platform design, account onboarding, and troubleshooting.
  • Strong working knowledge of both Linux/UNIX and Windows Server environments as they relate to privileged access (root/sudo models, local admin management, service accounts) — this is a must.
  • Solid Active Directory expertise: privileged groups, delegation models, tiered admin architecture, GPOs relevant to privileged access, and AD integration with PAM tooling.
  • Demonstrated experience leading privileged account remediation efforts at scale (discovery, vaulting, rotation, decommissioning) in a large or regulated enterprise.
  • Experience with PAM governance: certification campaigns, policy development, audit response, and control evidence in a regulated (preferably financial services) environment.
  • Strong stakeholder management and communication skills; able to operate at both executive and engineering levels.
  • Ability to work a hybrid schedule from the client’s New York City office (3 days onsite / 2 days remote).
Preferred Qualifications
  • Prior experience in banking, capital markets, asset management, or another regulated financial services environment.
  • CyberArk certifications (Defender, Sentry, or Guardian) and/or security certifications such as CISSP or CISM.
  • Familiarity with adjacent IAM tooling (e.g., SailPoint, Okta/Entra ID) and endpoint privilege management (CyberArk EPM or similar).
  • Scripting skills (PowerShell, Bash, Python) for automation of onboarding, reporting, and remediation tasks.
  • Experience managing PAM in hybrid environments (on-prem and cloud — AWS/Azure privileged access).
 
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 90929707
  • Position Id: 9042787
  • Posted 2 days ago
Contact the job poster
KK

Kshitiz Kumar

Recruiter @ Synapse Business Systems
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

New York, New York

Today

Full-time

USD 128,041.00 - 174,177.00 per year

Morristown, New Jersey

Today

Full-time

USD 127,000.00 - 160,550.00 per year

New York, New York

Today

Contract

80-95/hr

New York, New York

30+d ago

Full-time

Search all similar jobs