Get more replies from employers
Send a job-specific resume in minutes.
Workday, Inc. is seeking a Senior Delinea Cloud PAM Specialist to architect, deploy, and operationalize our cloud-native Privileged Access Management platform.
You will scale the Delinea Cloud Platform across human and machine identities, manage Delinea Secrets Server Cloud and DSV, and enforce least privilege in a complex enterprise environment. You will integrate with Entra ID, Okta, and SIEM/ITSM tools, drive automation via IaC, and provide L3 SME support for PAM incidents.
Your work days are brighter here. We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too.
About the Team Identity and Access Management team manage Identity suite including Okta, Delinea, KeyFactor, Active Directory and Entra ID environment. We manage workmate, customer and partner identities.
About the Role We are looking for a Senior Delinea Cloud PAM Specialist to architect, deploy, and operationalize our cloud-native Privileged Access Management platform. In this role, you will be responsible for scaling the Delinea Cloud Platform, extending privileged access controls across human and machine identities. You will manage Delinea Secret Server Cloud, DevOps Secrets Vault (DSV) for high-velocity non-human credentials, and Privilege Control for Servers / Cloud Suite (enforcing least privilege, host-based elevation, and AD Bridging across Unix, Linux, and Windows).
Implement and operate DSV for high-velocity machine-to-machine, containerized (Kubernetes), and CI/CD pipeline secrets (Jenkins, Terraform, GitHub Actions).
Unix/Linux/Windows Server Protection: Deploy and manage Delinea agents (Cloud Suite / Privilege Control for Servers) to enforce Zero Trust, Just-In-Time (JIT) access, and granular privilege elevation (sudo/su controls) on *NIX and Windows Server workloads.
System Integration: Integrate Delinea Cloud with Entra ID (Azure AD), Okta, Ping, SIEM systems (Splunk/Sentinel), and ITSM platforms (ServiceNow).
Ephemeral Credential Strategy: Ephemeral credential strategy should be evaluated and implemented wherever possible. Explore and implement new features, best practices in Worday PAM environment.
Secret Server Cloud Operations: Manage vaulting, custom secret templates, automated password rotation, discovery rules, SSH/RDP Web Launchers, and session recordings.
Server Privilege Administration: Manage Zone policies, Active Directory Bridging for Linux/Unix platforms, MFA enforcement at login/elevation, and local account discovery across server estates.
DevOps & Non-Human Identity Governance: Oversee dynamic secret generation, PKI/SSH short-lived certificates, API keys, and service account rotations for applications and RPA tools.
Platform Health & L3 Escalation: Monitor engine status, API rate limits, audit logs, and serve as the tier-3 subject matter expert (SME) for PAM incidents.
Infrastructure as Code (IaC) & Scripting: Write PowerShell, Python, or Bash scripts utilizing Delinea Cloud REST APIs and CLI tools to automate onboarding, vaulting, and compliance auditing.
Compliance & Auditing: Maintain forensic-level audit trails and continuous reporting to support regulatory frameworks (SOC 2, ISO 27001, PCI-DSS, HIPAA).
SOPs & Enablement: Create engineering documentation, cloud architecture diagrams, emergency break-glass procedures, and developer onboarding guides for DSV.
Our Approach to Flexible Work With Flex Work, we’re combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in‑office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.
At Workday, we value our candidates’ privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers. Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not. In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday. Workday is proud to be an equal opportunity workplace. Individuals seeking employment at Workday are considered without regards to age, ancestry, color, gender (including pregnancy, childbirth, or related medical conditions), gender identity or expression, genetic information, marital status, medical condition, mental or physical disability, national origin, protected family care or medical leave status, race, religion (including beliefs and practices or the absence thereof), sexual orientation, military or veteran status, or any other characteristic protected by federal, state, or local laws. Further, pursuant to applicable local ordinances, Workday will consider for employment qualified applicants with arrest and conviction records. We do not accept resumes from headhunters, placement agencies, or other suppliers that have not signed a formal agreement with us. You may view the Workday's Pay Transparency Policy, and Know Your Rights Notice, by clicking on their corresponding links. Workday is committed to providing reasonable accommodations for qualified individuals during our application process, in order to perform one or more essential functions of their job, as well as regarding the use of AI tools for employment decision-making to any degree. Please see below for more details including how to request an accommodation as a qualified veteran, due to a disability or for religious reasons, or as otherwise provided under applicable law. Workday prohibits taking adverse action against any candidate or employee for reporting a possible violation of this policy, requesting one or more work accommodation, exercising a privacy right, or cooperating in an investigation in accordance with applicable law. Any employee who retaliates against a candidate or employee for doing so may be subject to disciplinary action, up to and including termination of employment, to the fullest extent allowable under applicable law. If you require a reasonable accommodation, you may email accommodations@workday.com, as far in advance as possible.