Identity Security · Posted yesterday
Idira (formerly CyberArk) PAM Engineer
Design, deploy and run privileged access management on Idira (the platform Palo Alto Networks formed from CyberArk) for businesses that have never had PAM — and prove it to their cyber-insurance carriers.
A Tuesday in this role
Onboarding a client's 40 Windows admin accounts into the vault, writing the session-isolation policy, and drafting the evidence their broker asked for.
What you will do
- 1Lead Idira PAM implementations end to end: discovery, tiering model, vault and session architecture, deployment, handover
- 2Onboard privileged accounts across Windows, Linux, databases and cloud consoles; configure credential rotation and just-in-time elevation
- 3Migrate existing CyberArk estates to Idira and consolidate standing privilege
- 4Integrate with Okta, Microsoft Entra, SailPoint and SIEM tooling
- 5Produce the evidence packs cyber-insurance underwriters and CMMC, SOC 2 and HIPAA auditors ask for
- 6Run managed identity operations for retained clients: health, upgrades, access certifications
What you bring
- 3+ years hands-on with CyberArk PAM or Idira (PVWA, CPM, PSM, Conjur or equivalents)
- Working knowledge of Active Directory, Windows and Linux administration and networking
- Comfortable writing PowerShell or Python for onboarding and automation
- Can explain least privilege to a business owner and a session-isolation design to an engineer
- Authorized to work in the United States without sponsorship
Nice to have
Nicky and Andre Technology Services LLC is an equal opportunity employer. We hire on skills and character, and we welcome applicants of every background, age, race, religion, gender identity, sexual orientation, disability and veteran status. If you need an accommodation at any point in the process, tell us and we will provide it.