Lead PAM Engineer - (Havant/Reading/Glasgow/Hybrid) - Inside IR35
Day Rate - up to £760
Duration - 12 months
Harvey Nash's Client have a requirement for a Lead PAM Engineer. Our Client has already implemented SIA, SCA, PCloud and Conjur across their environment, with further expansion planned. The role will initially focus on reviewing the security posture, configuration, hygiene and operational maturity of the current PAM deployment as well as working on future MVPs.
Key Responsibilities:
-
Design, documentation and Implementation: Develop, document and implement identity solutions using Idira (CyberArk) tools.
-
Leadership: Proactively lead end-to-end execution of technical and handover activities related to our PAM project.
-
Management and Maintenance: Advise and update the day-to-day operations of Idira tools, ensuring optimal performance, security, and compliance.
-
Security and Compliance: Ensure that identity solutions meet security and compliance standards, implementing and enforcing security policies and procedures.
-
Documentation: Create and maintain comprehensive documentation of configurations, processes, and best practices.
-
Collaboration: Work closely with cross-functional teams, including IT, security, and business units, to achieve project goals and deliverables. It is essential to be able to communicate clearly to senior stakeholders and technical teams alike.
-
Innovation: Drive technical innovation and excellence within the identity management environment, evaluating and recommending tools and technologies to enhance efficiency and security.
-
Operational process creation and handover: Define operational processes and work with operational handover teams to deploy changes into a production environment in a fully supported manner.
Required experience:
- Proven experience with Idira (CyberArk) implementation and management. Other PAM experience beneficial.
- Strong understanding of Privilege Access Management and security principles.
- Strong understanding of Azure and AWS platforms within large-scale enterprise environments, including core infrastructure, networking, compute and identity.
- Solid understanding of cloud networking concepts with a proven ability to troubleshoot and resolve cloud connectivity issues, including by querying Firewall logs, debugging NSG/Security Group rules and validating DNS resolution.
- Understanding of enterprise identity and access management within Azure and AWS, including Entra ID and IAM Identity Centre, and solid understanding of role-based access control (RBAC) in both.
- Experience deploying, configuring, and managing cloud infrastructure across Azure and AWS using Infrastructure as Code (Terraform).
- Familiarity with testing and validation of IaC using tools such as Terraform Test and automated quality checks within CI/CD pipelines.
- Experience developing and maintaining GitHub Action workflows to automate infrastructure provisioning, testing and operational tasks.
- Proficiency in Scripting (Python and PowerShell) for automation and experience securely integrating them within automation workflows.
- Experience consuming REST APIs, including authentication, making API requests, handling pagination, error handling and processing responses.
- Excellent troubleshooting and analytical skills.
- Strong verbal and written communication skills.
Preferred Experience:
- Familiarity with hybrid identity environments and cloud-based identity solutions.
- Knowledge of regulatory security requirements and best practices.
- Experience working with Cloud based technology, subscriptions, infrastructure as a service and how cloud platforms are configured.
- Previous experience working with the CyberArk API's