PAM Engineering Lead

Minneapolis, Minnesota, United States

PAM Engineering Lead

  • 202605614
  • Minneapolis, Minnesota, United States
查看收藏夹

Description

The Role

Willis Towers Watson IT is currently seeking a senior, experienced candidate for the position of PAM Engineering Lead. In this position, the successful candidate must demonstrate significant hands-on experience engineering CyberArk PAM solutions, together with the seniority to set technical direction, own and prioritise a product backlog, and mentor engineers within the team. The main focus of this position is to lead the build, operation and continuous improvement of our CyberArk (Idira) platform while acting as product owner for the privileged access platform roadmap, influencing senior stakeholders and ensuring successful delivery of service, stakeholder alignment and continuous development of the IAM Team.


 

Major Accountabilities: 

  • Lead the design, build and maintenance of CyberArk (Idira) Privileged Access Manager solutions, including Vault architecture, Safes, target platforms and session management across WTW.
  • Own and prioritise the PAM platform backlog, setting technical direction and acting as product owner for the privileged access roadmap based on business risk, compliance deadlines and stakeholder demand.
  • Oversee the build and maintenance of privileged account onboarding and credential/SSH key rotation automation via the Central Policy Manager (CPM), integrating with Active Directory/Entra ID, Windows, Unix/Linux, databases and network devices.
  • Define and govern privileged access policies, least-privilege and just-in-time access models and privileged session review campaigns across WTW.
  • Act as the senior technical authority within IAM, covering all aspects of Privileged Access Management.
  • Drive solution development through problem solving, ensuring adherence to Security Controls, Policies and Standards with a focus on automation and control.
  • Influence senior stakeholders across IT, Compliance and the business to align the privileged access roadmap with WTW's risk and regulatory priorities.
  • Lead the development of skills and capabilities within the IAM team, mentoring engineers and driving process improvements and documentation.

 

Responsibilities

 

  • Oversee configuration and troubleshooting of CyberArk connectors and platforms (PSM, CPM, PVWA) to Windows, Unix/Linux, database and network device targets, working hands-on where required.

  • Author and review custom platforms, connection components and automation scripts (CyberArk REST API, PACLI, PowerShell and Python), setting standards for the wider team.

  • Govern the operational execution of privileged session recording and review, Safe membership reviews, and privileged account discovery initiatives.

  • Oversee platform health, ensuring credential rotation and session recording failures are resolved and audit trail integrity is maintained.

  • Lead sprint planning, backlog grooming and roadmap reviews.

  • Own roadmap and status communications for leadership and stakeholders.

  • Oversee the privileged account lifecycle, including onboarding, offboarding and account updates.

  • Ensure compliance with internal policies and external regulations, escalating risks as needed.

  • Own the response to audit findings and drive remediation measures to closure.

  • Oversee resolution of escalated issues and support tickets, providing senior technical input where needed.

 

Qualifications

The Requirements

  • 5+ years in IAM/PAM SaaS engineering, including 3+ years hands-on with CyberArk (Idira) Privileged Access Manager (Vault, CPM, PSM, PVWA), with demonstrated experience leading PAM engineering teams.

  • Strong understanding of PAM concepts: privileged account lifecycle, credential/SSH key rotation, session isolation and monitoring, least-privilege and just-in-time access.

  • Experience integrating CyberArk with Active Directory/Entra ID, Windows, Unix/Linux, databases, network devices and SaaS applications.

  • Scripting proficiency with the CyberArk REST API, PACLI, PowerShell and Python for automation and integration.

  • Working knowledge of identity and secrets management standards: SAML, OAuth2/OIDC and secrets management (Conjur/AAM or equivalent).

  • Experience with access governance frameworks and compliance mapping (ISO 27001, SOC 2, GDPR or similar).

  • Demonstrated experience writing user stories, managing a backlog, or working closely with product/agile teams.

  • Strong stakeholder communication skills, able to translate technical detail for both engineers and business stakeholders.

  • Good project management skills.

  • Positive team-first attitude with strong verbal and written communication skills.

  • Must possess sound analytical and problem-solving capabilities.

Nice to have

  • CyberArk certification (CyberArk Defender/Sentry - PAM).
  • Experience with BeyondTrust, Delinea (Thycotic) or HashiCorp Vault as a comparison point.
  • Familiarity with Agile/Scrum ceremonies and tools (Jira, Azure DevOps).
  • Exposure to Zero Trust principles and NIST SP 800-53 AC/IA control families.

Note: Employment-based non-immigrant visa sponsorship and/or assistance is not offered for this specific job opportunity.

 

Compensation and Benefits

 

Base salary range and benefits information for this position are being included in accordance with requirements of various state/local pay transparency legislation. Please note that salaries may vary for different individuals in the same role based on several factors, including but not limited to location of the role, individual competencies, education/professional certifications, qualifications/experience, performance in the role and potential for revenue generation (Producer roles only).

 

Compensation 

 

The base salary compensation range being offered for this role is $130,000.00-$170,000.00 USD annually. This role is also eligible for an annual short-term incentive bonus.

 

 

Company Benefits

 

WTW provides a competitive benefit package which includes the following (eligibility requirements apply):

 

  • Health and Welfare Benefits: Mental health/emotional wellbeing (including Employee Assistance Program), medical (including prescription drug coverage and fertility benefits), dental, vision, Health Savings Account, Commuter Accounts, Health Care and Dependent Care Flexible Spending Accounts, company-paid life insurance, supplemental life insurance, AD&D, group accident, group critical illness, group legal, identify theft protection, wellbeing program, adoption assistance, surrogacy assistance, auto/home insurance, pet insurance and other work/life resources
  • Leave Benefits: Paid holidays, annual paid time off (includes state/local paid leave where required), company-paid disability (short-term and long-term disability), other leaves (e.g., bereavement, FMLA, ADA, jury duty, military leave, and Parental and Adoption Leave),  Paid Time Off (only included for Washington roles)
  • Retirement Benefits: Qualified contributory pension plan (if eligible) and 401(k) plan with annual nonelective company contribution. Non-qualified retirement plans available to senior level colleagues who satisfy the plans’ eligibility requirements.

 

Pursuant to the San Francisco Fair Chance Ordinance and Los Angeles County Fair Chance Ordinance for Employers, we will consider for employment qualified applicants with arrest and conviction records.

 

This position will remain posted for a minimum of three business days from the date posted or until sufficient/appropriate candidate slate has been identified.

 

EOE, including disability/vets

主动联系

任何未经请求主动通过我们的网站或韦莱韬悦员工的个人电子邮件帐户提交的简历/应聘者资料,均视为韦莱韬悦的财产,且无需支付代理费用。要成为韦莱韬悦的授权招聘机构/猎头公司,此类机构必须持有由韦莱韬悦授权招聘人员签署的正式书面协议,并与公司保持积极的工作关系。简历必须按照我们的应聘者提交流程进行提交,包括积极参与特定职位的搜索工作。同样,对于我们授权的招聘机构/猎头公司,如果未能遵守应聘者提交流程,韦莱韬悦将不支付任何代理费用。韦莱韬悦是提倡机会均等的雇主。如果您希望我们保存您的联系信息以便将来考虑,请发送电子邮件至:Agency.inquiries@willistowerswatson.com

我们的办事处

我们的员工为全球 140 多个国家和市场提供服务。这为我们所做的每一项工作注入了全球视野,同时也能够为您创造许多绝佳的合作机遇与成长空间。探索下面的地图,探索您的职业发展可能。