Privileged Access Management (PAM) Engineer | Valencia
Location: Valencia, Spain
Work model: on-site Valencia office
Experience: 4 to 8+ years in PAM, IAM, or IT Security Engineering
⏱️ Position: Full-time
Contract: B2B / Freelance
Languages: English & Spanish
Summary:
We’re looking for a PAM Engineer to deploy, administer, and manage enterprise Privileged Access Management (PAM) solutions across on-premises and cloud environments. You’ll focus on CyberArk , privileged account onboarding, secrets management, Just-in-Time (JIT) access, automation, and governance, ensuring secure management of privileged identities and compliance with security standards.
Key Responsibilities:
Install, configure, and maintain CyberArk components including Vault, PVWA, CPM, PSM, PTA, and Conjur
Perform privileged account onboarding across Windows, Linux, Oracle, SQL, cloud, and application environments , ensuring secure vaulting and proper classification
Manage the end-to-end privileged account lifecycle , including inventory, validation, ownership mapping, approvals, and onboarding
Implement and manage Just-in-Time (JIT) privileged access and session management controls
Enforce password and credential management policies , including automated password rotation , complexity enforcement, and secure credential storage
Manage application secrets using CyberArk Conjur or equivalent secrets management solutions
Identify and manage service accounts, shared accounts, and non-rotating accounts , applying appropriate security controls and risk mitigation
Monitor password compliance and remediate accounts that do not meet defined rotation and policy standards
Provide Level 2/3 support for PAM-related incidents and service requests
Troubleshoot CyberArk integrations with Active Directory, Entra ID (Azure AD), IAM, SIEM, and ServiceNow
Perform regular health checks, system monitoring, patching, and upgrades of CyberArk infrastructure
Automate PAM processes using PowerShell, Python, REST APIs, and psPAS to reduce manual effort
Support bulk onboarding and large-scale privileged account management through automation and standardized methods
Design and support integrations between PAM and enterprise IAM systems such as SailPoint, Saviynt, and Entra ID
Maintain SOPs, onboarding procedures, runbooks, and automation scripts
Collaborate with application, infrastructure, and cloud teams to enforce least privilege and secure credential usage
Participate in audit and compliance activities , providing evidence, reporting, and demonstrating control effectiveness
Support PAM governance activities , including account recertification, ownership validation, and compliance monitoring
Required Skills:
Bachelor’s degree in Computer Science, Information Security , or related field
4–8 years of experience in IT Security, IAM, or PAM Engineering
Strong hands-on experience with CyberArk PAM Suite ( Vault, CPM, PSM, PVWA )
Experience with CyberArk Conjur or other enterprise secrets management solutions
Strong understanding of Just-in-Time (JIT) access and Privileged Session Management
Experience integrating PAM with IAM platforms (e.g., SailPoint, Saviynt, Entra ID / Azure AD )
Experience managing privileged access in cloud environments ( Azure, AWS )
Strong understanding of Windows, Linux, Active Directory , and database systems ( Oracle, SQL )
Strong scripting and automation experience ( PowerShell, Python, REST APIs )
Experience with ITSM tools such as ServiceNow and incident/change management processes
Knowledge of security controls, audit frameworks , and compliance standards
Strong analytical and troubleshooting abilities
Ability to work independently and within cross-functional teams
Excellent communication skills with both technical and non-technical stakeholders
Attention to detail and commitment to security best practices
Nice to Have :
CyberArk Defender / Sentry certification
Experience implementing Conjur in DevOps / CI-CD environments
Experience with Privileged Threat Analytics (PTA) or advanced monitoring tools
Exposure to container platforms (Kubernetes, OpenShift) and secrets management
Familiarity with Zero Trust security architecture
If you're passionate about CyberArk, Privileged Access Management, automation, and enterprise security , we'd love to hear from you.
Send your CV in English to
[email protected] with reference “MA/PAM” or just apply to this opportunity.
#CyberArk #PAM #IAM #PrivilegedAccessManagement #CyberSecurity #InformationSecurity #CloudSecurity #EntraID #ZeroTrust #Hiring
📌 Privileged Access Management (PAM) Engineer (Valencia)
🏢 Optiwisers
📍 Valencia