Senior PAM Engineer
Job Description
[Up to c. $250k Comp Package | Hybrid Working - 3 Days in Office]
Role Overview
We’re representing a highly sophisticated global investment organisation operating at the intersection of financial markets and advanced technology. The firm continues to invest heavily in its security and engineering capabilities, with identity becoming increasingly important as its infrastructure, cloud platforms, applications and automated technology estate expand. This is a high-calibre environment where security controls need to be robust enough for a heavily regulated business without creating unnecessary friction for engineering teams The Senior Privileged Access Management Engineer will take meaningful ownership of how privileged access is designed, implemented, governed and continuously improved across the organisation. Sitting within the wider security and technology function, you’ll work closely with infrastructure, cloud, application and identity teams to strengthen privileged-user and non-human identity controls, improve platform adoption, automate operational processes and ensure the PAM environment remains scalable, measurable and audit-ready...
Key Responsibilities
- Lead the implementation, adoption and ongoing enhancement of enterprise PAM capabilities across infrastructure, applications, cloud platforms and critical technology services
- Own the onboarding of privileged users, administrator accounts, service accounts, non-human identities and applications into the PAM platform, ensuring appropriate vaulting, rotation and access-control policies
- Design and improve controls covering credential management, privileged session monitoring, just-in-time access, elevation, least privilege and segregation of duties
- Develop and maintain PAM standards, technical procedures, governance processes and operating models that support both security requirements and practical engineering workflows
- Run privileged-access reviews and certification activity, investigate inappropriate or excessive permissions, coordinate remediation and provide clear evidence for internal and external audit
- Integrate PAM capabilities with identity governance platforms, Active Directory, Microsoft Entra ID, cloud services, authentication technologies and wider security tooling
- Build automation using scripting, APIs and workflow technologies to reduce manual administration, improve onboarding efficiency and strengthen consistency of privileged-access controls
- Monitor platform health, adoption, control effectiveness and operational risk through dashboards, metrics and trend analysis, while helping mentor colleagues and evaluate emerging PAM capabilities
What You’ll Bring…
- Around 7–11 years of experience across information security, identity engineering or access management, including substantial hands-on responsibility for enterprise PAM environments
- Strong practical experience with CyberArk, BeyondTrust, Delinea, Microsoft Entra PIM or another enterprise-grade privileged-access platform, including implementation, onboarding and operational troubleshooting
- Deep understanding of privileged-account lifecycle management, credential vaulting and rotation, privileged session controls, elevation, least privilege and secrets-management principles
- Experience integrating PAM with identity governance technologies such as SailPoint Identity Security Cloud, IdentityIQ, Saviynt or comparable IGA platforms
- Strong knowledge of Active Directory, Microsoft Entra ID and Windows/Linux environments, alongside authentication and authorisation technologies such as LDAP, Kerberos, SAML, OAuth, OpenID Connect and MFA
- Ability to automate identity or security workflows using PowerShell, Python, APIs or comparable scripting and integration approaches
- Experience operating in a regulated, audited or security-sensitive enterprise environment, with exposure to access certification, control remediation and frameworks such as NIST, ISO 27001, SOX or PCI DSS
- (Preferred) Experience using operational metrics, dashboards and approved AI tooling to improve analysis, documentation, troubleshooting or decision-making while maintaining appropriate validation and control
...
Apply for this role
All fields marked with * are required.