Privileged Access Management (PAM) Engineer - valència
1 day ago
Valencia
🚀 Privileged Access Management (PAM) Engineer | Valencia 📍 Location: Valencia, Spain 🏢 Work model: on-site Valencia office 💼 Experience: 4 to 8+ years in PAM, IAM, or IT Security Engineering ⏱️ Position: Full-time 🤝 Contract: B2B / Freelance 🌍 Languages: English & Spanish Summary: We’re looking for a PAM Engineer to deploy, administer, and manage enterprise Privileged Access Management (PAM) solutions across on-premises and cloud environments. You’ll focus on CyberArk, privileged account onboarding, secrets management, Just-in-Time (JIT) access, automation, and governance, ensuring secure management of privileged identities and compliance with security standards. Key Responsibilities: • Install, configure, and maintain CyberArk components including Vault, PVWA, CPM, PSM, PTA, and Conjur, • Perform privileged account onboarding across Windows, Linux, Oracle, SQL, cloud, and application environments, ensuring secure vaulting and proper classification, • Manage the end-to-end privileged account lifecycle, including inventory, validation, ownership mapping, approvals, and onboarding, • Implement and manage Just-in-Time (JIT) privileged access and session management controls, • Enforce password and credential management policies, including automated password rotation, complexity enforcement, and secure credential storage, • Manage application secrets using CyberArk Conjur or equivalent secrets management solutions, • Identify and manage service accounts, shared accounts, and non-rotating accounts, applying appropriate security controls and risk mitigation, • Monitor password compliance and remediate accounts that do not meet defined rotation and policy standards, • Provide Level 2/3 support for PAM-related incidents and service requests, • Troubleshoot CyberArk integrations with Active Directory, Entra ID (Azure AD), IAM, SIEM, and ServiceNow, • Perform regular health checks, system monitoring, patching, and upgrades of CyberArk infrastructure, • Automate PAM processes using PowerShell, Python, REST APIs, and psPAS to reduce manual effort, • Support bulk onboarding and large-scale privileged account management through automation and standardized methods, • Design and support integrations between PAM and enterprise IAM systems such as SailPoint, Saviynt, and Entra ID, • Maintain SOPs, onboarding procedures, runbooks, and automation scripts, • Collaborate with application, infrastructure, and cloud teams to enforce least privilege and secure credential usage, • Participate in audit and compliance activities, providing evidence, reporting, and demonstrating control effectiveness, • Support PAM governance activities, including account recertification, ownership validation, and compliance monitoring Required Skills: • Bachelor’s degree in Computer Science, Information Security, or related field, • 4–8 years of experience in IT Security, IAM, or PAM Engineering, • Strong hands-on experience with CyberArk PAM Suite (Vault, CPM, PSM, PVWA), • Experience with CyberArk Conjur or other enterprise secrets management solutions, • Strong understanding of Just-in-Time (JIT) access and Privileged Session Management, • Experience integrating PAM with IAM platforms (e.g., SailPoint, Saviynt, Entra ID / Azure AD), • Experience managing privileged access in cloud environments (Azure, AWS), • Strong understanding of Windows, Linux, Active Directory, and database systems (Oracle, SQL), • Strong scripting and automation experience (PowerShell, Python, REST APIs), • Experience with ITSM tools such as ServiceNow and incident/change management processes, • Knowledge of security controls, audit frameworks, and compliance standards, • Strong analytical and troubleshooting abilities, • Ability to work independently and within cross-functional teams, • Excellent communication skills with both technical and non-technical stakeholders, • Attention to detail and commitment to security best practices Nice to Have: • CyberArk Defender / Sentry certification, • Experience implementing Conjur in DevOps / CI-CD environments, • Experience with Privileged Threat Analytics (PTA) or advanced monitoring tools, • Exposure to container platforms (Kubernetes, OpenShift) and secrets management, • Familiarity with Zero Trust security architecture If you're passionate about CyberArk, Privileged Access Management, automation, and enterprise security, we'd love to hear from you. 📩 Send your CV in English to with reference “MA/PAM” or just apply to this opportunity. #CyberArk #PAM #IAM #PrivilegedAccessManagement #CyberSecurity #InformationSecurity #CloudSecurity #EntraID #ZeroTrust #Hiring