Privileged Access Management (PAM) Engineer - Optiwisers (Pamplona)

Privileged Access Management (PAM) Engineer - Optiwisers (Pamplona)

15 ago
|
Optiwisers
|
Pamplona

15 ago

Optiwisers

Pamplona

? Privileged Access Management (PAM) Engineer | Valencia

? Location: Valencia, Spain

? Work model: on-site Valencia office

? Experience: 4 to 8+ years in PAM, IAM, or IT Security Engineering

⏱️ Position: Full-time

? Contract: B2B / Freelance

? Languages: English & Spanish

Summary:

We’re looking for a PAM Engineer to deploy, administer, and manage enterprise Privileged Access Management (PAM) solutions across on-premises and cloud environments. You’ll focus on CyberArk, privileged account onboarding, secrets management, Just-in-Time (JIT) access, automation, and governance, ensuring secure management of privileged identities and compliance with security standards.

Key Responsibilities:

- Install, configure, and maintain CyberArk components including Vault, PVWA, CPM, PSM, PTA, and Conjur
- Perform privileged account onboarding across Windows, Linux, Oracle, SQL, cloud, and application environments, ensuring secure vaulting and proper classification
- Manage the end-to-end privileged account lifecycle, including inventory, validation, ownership mapping, approvals, and onboarding
- Implement and manage Just-in-Time (JIT) privileged access and session management controls
- Enforce password and credential management policies, including automated password rotation, complexity enforcement, and secure credential storage
- Manage application secrets using CyberArk Conjur or equivalent secrets management solutions
- Identify and manage service accounts, shared accounts, and non-rotating accounts, applying appropriate security controls and risk mitigation
- Monitor password compliance and remediate accounts that do not meet defined rotation and policy standards




- Provide Level 2/3 support for PAM-related incidents and service requests
- Troubleshoot CyberArk integrations with Active Directory, Entra ID (Azure AD), IAM, SIEM, and ServiceNow
- Perform regular health checks, system monitoring, patching, and upgrades of CyberArk infrastructure
- Automate PAM processes using PowerShell, Python, REST APIs, and psPAS to reduce manual effort
- Support bulk onboarding and large-scale privileged account management through automation and standardized methods
- Design and support integrations between PAM and enterprise IAM systems such as SailPoint, Saviynt, and Entra ID
- Maintain SOPs, onboarding procedures, runbooks, and automation scripts
- Collaborate with application, infrastructure, and cloud teams to enforce least privilege and secure credential usage
- Participate in audit and compliance activities, providing evidence, reporting, and demonstrating control effectiveness
- Support PAM governance activities, including account recertification, ownership validation, and compliance monitoring

Required Skills:

- Bachelor’s degree in Computer Science, Information Security, or related field
- 4–8 years of experience in IT Security, IAM, or PAM Engineering
- Strong hands-on experience with CyberArk PAM Suite (Vault, CPM, PSM, PVWA)




- Experience with CyberArk Conjur or other enterprise secrets management solutions
- Strong understanding of Just-in-Time (JIT) access and Privileged Session Management
- Experience integrating PAM with IAM platforms (e.g., SailPoint, Saviynt, Entra ID / Azure AD)
- Experience managing privileged access in cloud environments (Azure, AWS)
- Strong understanding of Windows, Linux, Active Directory, and database systems (Oracle, SQL)
- Strong scripting and automation experience (PowerShell, Python, REST APIs)
- Experience with ITSM tools such as ServiceNow and incident/change management processes
- Knowledge of security controls, audit frameworks, and compliance standards
- Strong analytical and troubleshooting abilities
- Ability to work independently and within cross-functional teams
- Excellent communication skills with both technical and non-technical stakeholders
- Attention to detail and commitment to security best practices

Nice to Have:

- CyberArk Defender / Sentry certification
- Experience implementing Conjur in DevOps / CI-CD environments
- Experience with Privileged Threat Analytics (PTA) or advanced monitoring tools
- Exposure to container platforms (Kubernetes, OpenShift) and secrets management
- Familiarity with Zero Trust security architecture

If you're passionate about CyberArk, Privileged Access Management, automation, and enterprise security, we'd love to hear from you.

? Send your CV in English to with reference “MA/PAM” or just apply to this opportunity.

#CyberArk #PAM #IAM #PrivilegedAccessManagement #CyberSecurity #InformationSecurity #CloudSecurity #EntraID #ZeroTrust #Hiring

📌 Privileged Access Management (PAM) Engineer - Optiwisers (Pamplona)
🏢 Optiwisers
📍 Pamplona

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: privileged access management (pam) engineer - optiwisers (pamplona) / pamplona