We're fast learners, hard workers, natural collaborators... and we Make Modern Happen !
Our ambition is to unlock the potential of our digital world so that organisations everywhere can innovate and thrive securely.
We aim to achieve this goal by bringing together the world’s most talented people and the most powerful technologies, combining them to address our customers' challenges and to build something stronger together.
Right now,we are looking for aIdentity Security Engineer to integrate our internal team, based in Lisbon/Porto.
Your responsibilities include:
- Administer,configure and operate the CyberArk Privileged Access Management (PAM) suiteend-to-end (Vault, CPM, PVWA, PSM, PTA/Privilege Cloud), ensuring availability,performance and security of the platform.
- Design,implement and maintain IAM/PAM policies, safes, platforms and access workflowsaligned with least-privilege and Zero Trust principles.
- Architectand implement CyberArk components focused on protecting domain credentials,service accounts and administrative access to Active Directory.
- Manage thefull lifecycle of privileged accounts (onboarding, rotation, reconciliation,discovery) and continuously tune credential management policies.
- Develop andexecute Active Directory Vulnerability Remediation plans to strengthen clients'AD security posture, in articulation with the PAM strategy.
- Lead ActiveDirectory and IAM/PAM Assessment projects, using specialized tools such asPurple Knight or similar to identify and prioritise critical identity risks.
- Design andvalidate resilience and disaster recovery strategies for AD and for theCyberArk environment (backup, HA/DR).
- Act astechnical reference and advisor on CyberArk architecture, IAM/PAM bestpractices, Kerberos, NTLM, GPOs and AD topology security.
You must have:
- Bachelor'sdegree in Cybersecurity, Computer Science, Computer Engineering or a relatedfield.
- 3 to 5years of experience in cybersecurity, with proven, hands‑on focus on IAM/PAMand Identity/Active Directory security.
- Demonstrable,recognised experience administering and managing CyberArk in productionenvironments (Vault, CPM, PVWA, PSM, and ideally Privilege Cloud).
- Solidpractical knowledge of IAM/PAM concepts and lifecycle management (privilegedaccount onboarding, rotation, reconciliation, session monitoring).
- Hands‑onexperience using AD security assessment tools such as Purple Knight, NetwrixPingCastle or similar.
We value:
- CyberArkcertifications (e.g., CyberArk Defender, CyberArk Sentry) are highly valued andconsidered a significant differentiator for this role.
- BroaderIAM/PAM experience beyond CyberArk (e.g., other PAM/IAM platforms) ascomplementary knowledge.
- Stronganalytical and problem‑solving skills.
- Ameticulous and detail‑oriented mindset.