Privileged Access Management (PAM) Engineer (Santander)

Privileged Access Management (PAM) Engineer (Santander)

15 ago
|
Optiwisers
|
Santander

15 ago

Optiwisers

Santander

Privileged Access Management (PAM) Engineer | Valencia

Location: Valencia, Spain

Work model: on-site Valencia office

Experience: 4 to 8+ years in PAM, IAM, or IT Security Engineering

Position: Full-time

Contract: B2B / Freelance

Languages: English & Spanish

Summary:

We're looking for a PAM Engineer to deploy, administer, and manage enterprise Privileged Access Management (PAM) solutions across on-premises and cloud environments. You'll focus on CyberArk, privileged account onboarding, secrets management, Just-in-Time (JIT) access, automation, and governance, ensuring secure management of privileged identities and compliance with security standards.

Key Responsibilities:

- Install, configure, and maintain CyberArk components including Vault, PVWA, CPM, PSM, PTA, and Conjur
- Perform privileged account onboarding across Windows, Linux, Oracle, SQL, cloud, and application environments, ensuring secure vaulting and proper classification
- Manage the end-to-end privileged account lifecycle, including inventory, validation, ownership mapping, approvals, and onboarding
- Implement and manage Just-in-Time (JIT) privileged access and session management controls
- Enforce password and credential management policies, including automated password rotation, complexity enforcement, and secure credential storage
- Manage application secrets using CyberArk Conjur or equivalent secrets management solutions
- Identify and manage service accounts, shared accounts, and non-rotating accounts, applying appropriate security controls and risk mitigation
- Monitor password compliance and remediate accounts that do not meet defined rotation and policy standards




- Provide Level 2/3 support for PAM-related incidents and service requests
- Troubleshoot CyberArk integrations with Active Directory, Entra ID (Azure AD), IAM, SIEM, and ServiceNow
- Perform regular health checks, system monitoring, patching, and upgrades of CyberArk infrastructure
- Automate PAM processes using PowerShell, Python, REST APIs, and psPAS to reduce manual effort
- Support bulk onboarding and large-scale privileged account management through automation and standardized methods
- Design and support integrations between PAM and enterprise IAM systems such as SailPoint, Saviynt, and Entra ID
- Maintain SOPs, onboarding procedures, runbooks, and automation scripts
- Collaborate with application, infrastructure, and cloud teams to enforce least privilege and secure credential usage
- Participate in audit and compliance activities, providing evidence, reporting, and demonstrating control effectiveness
- Support PAM governance activities, including account recertification, ownership validation, and compliance monitoring

Required Skills:

- Bachelor's degree in Computer Science, Information Security, or related field
- 4–8 years of experience in IT Security, IAM, or PAM Engineering
- Strong hands-on experience with CyberArk PAM Suite (Vault, CPM, PSM, PVWA)




- Experience with CyberArk Conjur or other enterprise secrets management solutions
- Strong understanding of Just-in-Time (JIT) access and Privileged Session Management
- Experience integrating PAM with IAM platforms (e.g., SailPoint, Saviynt, Entra ID / Azure AD)
- Experience managing privileged access in cloud environments (Azure, AWS)
- Strong understanding of Windows, Linux, Active Directory, and database systems (Oracle, SQL)
- Strong scripting and automation experience (PowerShell, Python, REST APIs)
- Experience with ITSM tools such as ServiceNow and incident/change management processes
- Knowledge of security controls, audit frameworks, and compliance standards
- Strong analytical and troubleshooting abilities
- Ability to work independently and within cross-functional teams
- Excellent communication skills with both technical and non-technical stakeholders
- Attention to detail and commitment to security best practices

Nice to Have:

- CyberArk Defender / Sentry certification
- Experience implementing Conjur in DevOps / CI-CD environments
- Experience with Privileged Threat Analytics (PTA) or advanced monitoring tools
- Exposure to container platforms (Kubernetes, OpenShift) and secrets management
- Familiarity with Zero Trust security architecture

If you're passionate about CyberArk, Privileged Access Management, automation, and enterprise security, we'd love to hear from you.

Send your CV in English to with reference "MA/PAM" or just apply to this opportunity.

#CyberArk #PAM #IAM #PrivilegedAccessManagement #CyberSecurity #InformationSecurity #CloudSecurity #EntraID #ZeroTrust #Hiring

📌 Privileged Access Management (PAM) Engineer (Santander)
🏢 Optiwisers
📍 Santander

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: privileged access management (pam) engineer (santander) / santander