CrawlJobs Logo

IAM - Privileged Access Management Principal

https://www.hpe.com/ Logo

Hewlett Packard Enterprise

Location Icon

Location:
United States , Houston

Category Icon

Job Type Icon

Contract Type:
Employment contract

Salary Icon

Salary:

117500.00 - 270000.00 USD / Year

Job Description:

Principal PAM Architect to lead the strategy, architecture, design, and implementation of enterprise-wide Privileged Access Management (PAM) solutions. This role is critical in securing privileged access across both on-premises and cloud environments, driving adoption of Zero Trust principles, and ensuring scalable, resilient, and compliant privileged access solutions.

Job Responsibility:

  • Define PAM strategy, roadmap, and reference architectures aligned to enterprise security and compliance requirements
  • Design and implement scalable PAM solutions for large, complex environments across on-prem, hybrid, and multi-cloud infrastructures
  • Incorporate Zero Trust, Just-in-Time (JIT), and Just Enough Access (JEA) models into PAM solutions
  • Lead the enterprise rollout and lifecycle management of CyberArk Privileged Cloud and related modules
  • Implement and manage privileged session monitoring, endpoint privilege management (EPM), and application-to-application password management
  • Drive integration of PAM with identity providers, SIEM/SOAR, ITSM, and DevOps pipelines
  • Establish and enforce policies for privileged access governance, auditing, and regulatory compliance
  • Conduct regular reviews of PAM controls to prevent credential theft, lateral movement, and unauthorized access
  • Act as the PAM subject matter expert (SME), advising executives, architects, and engineering teams on privileged access security
  • Mentor and guide engineering teams on PAM best practices and secure operations

Requirements:

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience)
  • 8+ years in cybersecurity or IT with demonstrated hands-on PAM specific experience in enterprise-scale environments
  • Proven experience in architecture, design, and implementation of PAM solutions across large, complex enterprises
  • Deep technical expertise with CyberArk (Privileged Cloud and on-prem)
  • Strong knowledge of Zero Trust principles, JIT/JEA access models, and privileged identity lifecycle management
  • Experience integrating PAM with cloud platforms (Azure, AWS, GCP), DevOps pipelines, and enterprise IT ecosystems
  • Experience with secrets management platforms (CyberArk Conjur, HashiCorp Vault, AWS Secrets Manager, etc.)
  • Working knowledge of modern authentication standards (SAML, OIDC, FIDO2, MFA, passwordless)
  • Hands-on expertise with Windows, Linux, Active Directory, and cloud IAM models
  • Good understanding of the privilege access models of Active Directory, Azure/Entra ID, AWS and GCP
  • Cybersecurity certifications (CISSP, CISM, CISA, CyberArk Defender/Sentry/Guardian) highly desirable
  • Strong communication and leadership skills to influence executives and technical teams

Nice to have:

  • Cybersecurity certifications (CISSP, CISM, CISA, CyberArk Defender/Sentry/Guardian)
  • Experience with HashiCorp Vault
  • AWS Secrets Manager
What we offer:
  • Health & Wellbeing benefits
  • Personal & Professional Development programs
  • Unconditional Inclusion environment
  • Comprehensive benefits suite supporting physical, financial and emotional wellbeing

Additional Information:

Job Posted:
October 08, 2025

Employment Type:
Fulltime
Work Type:
On-site work
Job Link Share:

Looking for more opportunities? Search for other job offers that match your skills and interests.

Briefcase Icon

Similar Jobs for IAM - Privileged Access Management Principal

IAM Security Engineer

Truveta is the world’s first health provider led data platform with a vision of ...
Location
Location
United States , Seattle; Bellevue
Salary
Salary:
128000.00 - 155000.00 USD / Year
truveta.com Logo
Truveta
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor's degree or equivalent in Computer Science, Information Security, or Information Systems
  • 3-5 years of hands-on experience in an Identity and Access Management (IAM) role with a strong focus on Azure environments
  • Strong understanding of Azure Entra ID (Azure Active Directory), including Conditional Access, MFA, Identity Governance, PIM, directory services, and RBAC
  • Experience supporting SSO integrations and identity protocols such as SAML, OAuth 2.0, OpenID Connect, and SCIM provisioning
  • Ability to analyze and improve access models, workflows, and entitlements, applying least privilege and zero-trust principles
  • Proficiency with PowerShell or similar scripting tools to automate IAM tasks
  • Experience monitoring for identity-related threats, anomalous login behavior, and misconfigurations in cloud IAM environments
  • Working knowledge of IT/security governance and compliance frameworks (e.g., SOC 2, ISO 27001, NIST) and experience supporting audits or access reviews
  • Strong troubleshooting and diagnostic skills for identity issues involving authentication, authorization, directory sync, and permissions
  • Excellent written and verbal communication skills, including the ability to work cross-functionally with engineering, IT, and security teams
Job Responsibility
Job Responsibility
  • Identity Lifecycle & Access Management: Manage and improve provisioning, de-provisioning, and modification processes for user accounts and service principals across cloud and enterprise systems
  • Conduct access reviews, entitlement cleanups, and role evaluations to ensure least-privilege access
  • Identify gaps in lifecycle processes and recommend enhancements or workflow automation opportunities
  • Access Requests & Role Governance: Process and validate access requests, ensuring alignment with RBAC models, security policies, and job function requirements
  • Contribute to the development and refinement of RBAC roles, access policies, and approval workflows
  • Partner with stakeholders to analyze access patterns and propose more efficient and secure role structures
  • Application Integration & IAM Enablement: Support onboarding applications into IAM systems, including SSO configuration, SCIM provisioning, OAuth app integration, and secure authentication setup
  • Work with application and engineering teams to ensure proper identity integration and consistent enforcement of IAM standards
  • Assist with evaluating and implementing new IAM tools or capabilities as the organization evolves
  • Security Controls & Identity Governance: Implement and support IAM security controls such as MFA, Conditional Access policies, PIM, and identity governance features
What we offer
What we offer
  • Interesting and meaningful work for every career stage
  • Comprehensive benefits with strong medical, dental and vision insurance plans
  • 401K plan
  • Professional development & training opportunities for continuous learning
  • Work/life autonomy via flexible work hours and flexible paid time off
  • Generous parental leave
  • Regular team activities (virtual and in-person)
  • Additional compensation such as incentive pay and stock options for certain roles.
  • Fulltime
Read More
Arrow Right

Principal IAM Engineer

The IAM Principal Engineer is responsible for driving the development, maintenan...
Location
Location
United States , Mount Laurel
Salary
Salary:
142361.11 - 213541.67 USD / Year
comcastcorporation.com Logo
Comcast
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Over 10 years of experience implementing SailPoint IdentityIQ
  • More than 5 years of experience designing, architecting, implementing, operating, and maintaining Radiant Logic Virtual Directory Service (VDS), including Federated Identity Management (FIM) and Identity Correlation and Synchronization (ICS)
  • Skilled in integrating data sources and applications into VDS, configuring data access views and permissions, and performing identity correlation and synchronization
  • Strong knowledge of LDAP, Active Directory services, Multi-Factor Authentication (MFA), risk-based authentication, and privileged access management
  • Deep understanding of Identity and Access Management (IAM) across authentication, authorization, endpoint security, network security, and policy engines
  • Technical expertise with Microsoft MFA, SailPoint, CyberArk, ForgeRock, Okta, Ping Identity, Active Directory, Azure Active Directory, AWS, Google Cloud Platform, Microsoft Azure, and cross-domain IDM integrations
  • Solid grasp of cloud identity concepts and hands-on experience with Azure AD and other cloud environments
  • 3–5+ years of experience developing workflows, forms, connector configurations, provisioning policies, and rules within SailPoint IdentityIQ
  • Quick learner with the ability to adopt new technologies and collaborate effectively to capture and implement business system requirements
  • Proficient in source control and development tools such as GitHub and Eclipse
Job Responsibility
Job Responsibility
  • Apply your expertise in SailPoint IdentityIQ and Radiant One FID / Global Sync to enhance and expand the capabilities of the enterprise IAM platform
  • Collaborate with Agile teams to design, build, test, and support scalable IAM solutions that meet foundational enterprise needs, including identity federation, directory virtualization, and multi-source synchronization
  • Contribute innovative and efficient configuration and coding solutions in SailPoint IdentityIQ and Radiant One FID environments that differentiate the IAM platform
  • Engineer cost-effective technical solutions leveraging Radiant One FID and Global Sync to address business challenges and streamline identity and access processes
  • Develop both tactical and strategic IAM solutions aligned with evolving business requirements, including federated identity management and synchronized directory services
  • Partner with key stakeholders to gather and validate requirements, ensuring delivered solutions meet expectations across SailPoint IdentityIQ and Radiant One FID systems
  • Participate in project teams to design new system capabilities, including proof-of-concept (POC) implementations for both Radiant One FID and SailPoint IdentityIQ, and presentations that highlight their functionality
  • Deploy and manage Radiant One FID in Kubernetes environments using Helm charts, ensuring scalable, reproducible, and reliable containerized deployments
  • Support the end-to-end testing lifecycle for system changes, including integrations with Radiant One FID / Global Sync, from design through execution
  • Create proactive capacity forecasts to prevent outages and ensure system reliability for SailPoint IdentityIQ and Radiant One FID services
What we offer
What we offer
  • Paid Time off
  • Physical Wellbeing benefits
  • Financial Wellbeing benefits
  • Emotional Wellbeing benefits
  • Life Events + Family Support benefits
  • Fulltime
Read More
Arrow Right

Security Engineer II

PagerDuty is seeking an Enterprise Security Engineer to join its global IT Opera...
Location
Location
Canada , Toronto
Salary
Salary:
122000.00 - 185000.00 CAD / Year
https://www.pagerduty.com Logo
PagerDuty
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • At least 3 years of experience in the information security industry, with 2+ years in network security or zero-trust, and 2+ years in security architecture or solution experience
  • Knowledge of Information Security concepts, especially in the areas of security threats, analyzing security logs and driving Incident response
  • Knowledge and practical experience in network security and zero-trust
  • Understanding of the IAM cybersecurity landscape, including identity stores, authentication/authorization, strong authentication, and privileged access management capabilities and methodologies
  • Understanding of security technologies and concepts, including SIEM, MDR/XDR, EDR and vulnerability management
  • Understanding of security best practices and frameworks (e.g., MITRE ATT&CK, NIST Cybersecurity Framework)
  • Knowledge of incident response processes
Job Responsibility
Job Responsibility
  • Partner closely with CISO organization to design and implement enterprise IT security architectures and solutions
  • Tracking the evolution of cutting-edge security technologies, and keeping up to date of the latest security threats and trends
  • Focus on enterprise security and zero-trust technology, serving as the principal technical expert in this area within the Enterprise Security department
  • Monitors security alerts and leads the team in identifying and responding to security threats
  • Monitors systems for vulnerabilities, provides prioritization, and drives remediation efforts
  • Working cross-functionally to triage suspicious activity and drive remediation (performing L2-L3 duties as needed)
  • Analyzing threat intelligence feeds to develop metrics, alerts, and techniques to protect against new and emerging attack vectors
  • Develop metrics, thresholds, alerts, dashboards, and incident response playbooks
  • Drive the design and development of automated security response and maintenance solutions
  • Oversee our workstation vulnerability management & endpoint compliance program
What we offer
What we offer
  • Competitive salary
  • Comprehensive benefits package
  • Flexible work arrangements
  • Company equity
  • ESPP (Employee Stock Purchase Program)
  • Retirement or pension plan
  • Generous paid vacation time
  • Paid holidays and sick leave
  • Dutonian Wellness Days & HibernationDuty - companywide paid days off in addition to PTO
  • Paid parental leave: 22 weeks for pregnant parent, 12 weeks for non-pregnant parent
  • Fulltime
Read More
Arrow Right

Principal Consultant, Zero Trust Advisory, Proactive Services (Unit 42)

In this client-facing role, the Principal Consultant will lead complex Zero Trus...
Location
Location
Canada , Toronto
Salary
Salary:
151000.00 - 208000.00 USD / Year
paloaltonetworks.it Logo
Palo Alto Networks Italia
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 6+ years leading high-stakes cybersecurity advisory and risk management engagements for enterprise clients
  • Former professional services and consulting experience required
  • 3+ years of consulting experience architecting and deploying Zero Trust, SASE, or Identity-centric security models for large, multinational organizations
  • Strong track record in strengthening existing and developing net-new client relationships
  • Lead enterprise Zero Trust advisory engagements, translating business risk into actionable architectures aligned with NIST SP 800-207, NIST NCCoE Zero Trust use cases, and CISA Zero Trust Maturity Model
  • Design and deliver end-to-end Zero Trust architectures across IAM, network, endpoint, cloud, application, and security operations domains for large, complex enterprises
  • Perform enterprise security and architecture assessments to identify gaps, dependencies, and maturity levels, producing clear roadmaps toward an optimized Zero Trust posture
  • Serve as a trusted advisor to C-suite executives, board members, and senior leadership, while also engaging deeply with engineers, architects, and security operations teams
  • Create high-quality client-ready deliverables including reference architectures, target-state designs, migration roadmaps, executive presentations, and technical runbooks
  • Demonstrate solution architecture leadership, maintaining technical vision from strategy through detailed design and implementation
Job Responsibility
Job Responsibility
  • Drive high-value, billable Zero Trust transformation engagements that convert complex security challenges into resilient architectural outcomes
  • Simultaneously deliver elite advisory services to our clients and assist in scaling Unit 42’s Zero Trust practice through technical innovation and business development
  • Assess enterprise architectures to expose hidden zones of implicit trust and high-risk lateral movement paths
  • Analyze enterprise telemetry and policy logs to identify visibility gaps across identity, device, and network layers
  • Execute Zero Trust risk assessments grounded in best practices such as NIST SP 800-207, the CISA ZT Maturity Model, and MITRE ATT&CK to quantify architectural vulnerabilities
  • Devise strategic security transformation recommendations and solutions, to include Unit 42 services and Palo Alto Networks technology, to assist customers in reducing risks
  • Design risk-based control sets that prioritize identity-centric protection and least-privilege access
  • Audit the technical integration of SASE, Identity, EDR/XDR, and Cloud Security to ensure they function as a unified, automated fabric rather than a collection of disconnected silos
  • Develop ZT Roadmaps that provide clients with a realistic, phased path to retiring legacy perimeter defenses
  • Scope new opportunities with prospective clients, including drafting statements of work and responding to Requests for Proposals (RFPs)
What we offer
What we offer
  • restricted stock units
  • bonus
  • employee benefits
  • Fulltime
Read More
Arrow Right
New

HR Business Partner

Meta is seeking an HR Business Partner to support our tech and/or business organ...
Location
Location
United States
Salary
Salary:
152000.00 - 220000.00 USD / Year
meta.com Logo
Meta
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 10+ years experience in an HR Business Partner or equivalent role
  • Experience helping global and/or highly matrixed organizations scale
  • Demonstrates solid judgment and experience assessing risk relative to the business
  • Consulting, coaching and facilitation skills
  • Effective communication and critical thinking skills
  • Demonstrates empathy and experience driving community-building work
  • Demonstrates project management and change management experience
  • Experience using data to identify insights that drive action
  • Demonstrated experience learning and thriving in a constantly changing environment and to cultivate relationships across teams
  • Demonstrated experience in influencing and strategically solve problems
Job Responsibility
Job Responsibility
  • Design and deliver targeted solutions with a high degree of focus on scale and growth, including strategic planning, visioning, talent assessment, change management and team building
  • Provide strategic business partnership, thought partnership, and coaching to all levels of the organization
  • Proactively assess team, manager, organizational development needs, make recommendations, and implement appropriate solutions
  • Provide rigorous data analysis and reporting solutions based on business needs
  • Drive talent management strategies to support a team’s growth and individual development plans
  • Manage and facilitate the overall Performance Summary Cycle and employee engagement survey throughout the year
  • Integrate and partner with HR colleagues in the Recruiting, Learning & Development, Compensation, Legal, and HR Programs teams to implement solutions and help scale the business
  • Partner closely with regional HR partners on global strategy and execution
  • Work closely with our Employee Relations Partners, supporting employee relations issues as needed
  • Design and facilitate team and offsite meetings as needed
What we offer
What we offer
  • bonus
  • equity
  • benefits
  • Fulltime
Read More
Arrow Right
New

Criminal justice social worker

The Criminal Justice Social Work team in Edonburgh is seeking a dedicated and mo...
Location
Location
United Kingdom , Edinburgh
Salary
Salary:
Not provided
https://www.randstad.com Logo
Randstad
Expiration Date
March 09, 2026
Flip Icon
Requirements
Requirements
  • Qualified Social Worker
  • SSSC registered in the Social Work part of the register
  • LSCMI trained
Job Responsibility
Job Responsibility
  • Conduct comprehensive assessments and develop tailored support plans for individuals referred by the courts
  • Manage a caseload of individuals on probation or community sentences, providing one-on-one support and facilitating group work
  • Work collaboratively with law enforcement, health services, and community organisations to support individuals in achieving their goals
  • Prepare written reports for the courts, parole boards, and other relevant agencies
  • Provide advice, advocacy, and emotional support to clients, promoting their well-being and addressing any issues or barriers
  • Maintain accurate and up-to-date records in line with Edinburgh City Council's policies and data protection standards
What we offer
What we offer
  • Flexible hours
  • Competitive rate of pay
  • Free training to keep up to date with your Continuous Professional Development
  • Contributory pension
  • Referral scheme - receive £300 in vouchers (subject to Ts and Cs)
  • Help with sourcing accommodation and travel, if required
  • Dedicated Randstad consultant - one point of contact
  • Weekly payroll
  • Support with finding accommodation
  • Fulltime
Read More
Arrow Right
New

Social worker / mental health officer

Are you a Social Worker looking for a rewarding opportunity in the vibrant commu...
Location
Location
United Kingdom , Denny, Falkirk
Salary
Salary:
Not provided
https://www.randstad.com Logo
Randstad
Expiration Date
March 09, 2026
Flip Icon
Requirements
Requirements
  • Qualified and registered Social Worker - SSSC registered
  • Significant post-qualification experience working within a mental health setting
  • Demonstrable understanding of the Adults with Incapacity (Scotland) Act 2000 and experience of working with Local Authority Guardianship Orders
  • Full driving license and access to a vehicle is desirable due to the rural nature
Job Responsibility
Job Responsibility
  • Conducting thorough and timely reviews of Local Authority Guardianship Orders in accordance with relevant legislation and local policies
  • Gathering information from a variety of sources, including the individual, family members, carers, medical professionals, and other relevant agencies
  • Assessing the individual's current needs, capacity, and best interests in relation to the continuation or variation of the Guardianship Order
  • Preparing high-quality, evidence-based reports for the relevant authorities, clearly articulating findings and recommendations
  • Managing the process for the renewal of Guardianship Orders, ensuring all necessary documentation and procedures are followed within statutory timescales
  • Working collaboratively with the individual, their named person, and other stakeholders to ensure their views and wishes are central to the review and renewal process
  • Providing information and support to individuals subject to Guardianship Orders and their families
What we offer
What we offer
  • Flexible Hours: Control your work hours and choose assignments that fit your lifestyle
  • Competitive Pay Rates: We offer highly competitive remuneration for each placement
  • Professional Development: Opportunities to work across various departments, enhancing your skills and broadening your expertise
  • Free training: Keep up to date with your Continuous Professional Development
  • Pension Scheme: Contributory pension
  • Referral Bonus: Receive £300 in vouchers (subject to Ts and Cs)
  • Weekly payroll: Randstad runs a twice weekly payroll, enabling you to control your finances by receiving weekly pay
  • Dedicated Support: Our team is here to assist you at every step, from onboarding through the entirety of your placement. We can even help with sourcing accommodation and travel, if required
Read More
Arrow Right
New

Social worker - children and families

Are you a passionate and dedicated Social Worker looking to make a real differen...
Location
Location
United Kingdom , Dalkeith
Salary
Salary:
Not provided
https://www.randstad.com Logo
Randstad
Expiration Date
March 09, 2026
Flip Icon
Requirements
Requirements
  • A recognised Social Work qualification (e.g., BA/MA in Social Work, DipSW)
  • Registration with the Scottish Social Services Council (SSSC) as a Social Worker
  • A full driving licence and access to a vehicle
  • be able to manage challenging situations
  • be person centred
  • can work as an individual or part of a team
  • caring
  • competent at dealing with all stakeholders
  • critical thinking
  • emotional intelligence
Job Responsibility
Job Responsibility
  • Undertaking comprehensive assessments of children's needs and risks
  • Developing and reviewing robust care plans that promote the safety, well-being, and development of children
  • Providing direct support and intervention to children and families, including therapeutic work where appropriate
  • Working in partnership with parents, carers, and other agencies to achieve positive change
  • Preparing reports and presenting evidence in court as required
  • Maintaining accurate and up-to-date records in line with professional standards and organizational policies
  • Participating in regular supervision and continuous professional development
What we offer
What we offer
  • Flexible Hours: Control your work hours and choose assignments that fit your lifestyle
  • Competitive Pay Rates: We offer highly competitive remuneration for each placement
  • Professional Development: Opportunities to work across various departments, enhancing your skills and broadening your expertise
  • Free training: Keep up to date with your Continuous Professional Development
  • Pension Scheme: Contributory pension
  • Referral Bonus: Receive £300 in vouchers (subject to Ts and Cs)
  • Weekly payroll: Randstad runs a twice weekly payroll, enabling you to control your finances by receiving weekly pay
  • Dedicated Support: Our team is here to assist you at every step, from onboarding through the entirety of your placement. We can even help with sourcing accommodation and travel, if required
  • Fulltime
Read More
Arrow Right