IAM/PAM PKI Engineer (mPass, CyberArk)

CBT

Riyadh

On-site

SAR 120,000 - 150,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

A leading cybersecurity firm based in Riyadh is hiring an IAM/PAM PKI Engineer. This role involves the design and support of MFA policies, integration of enterprise systems, and operation of privileged access management tools like CyberArk. The ideal candidate should have over 5 years of IAM experience, hands-on knowledge of MFA and PAM, and skills in PowerShell and Python scripting. This position offers a standard working schedule with occasional after hours for critical operations.

Qualifications

  • Typically 5+ years of experience in IAM.
  • Strong experience with MFA and PAM operations.
  • Solid understanding of SAML, OAuth 2.0, OpenID Connect, AD, and LDAP.

Responsibilities

  • Design, configure, and support Cerebra mPass MFA policies.
  • Integrate MFA with enterprise systems and monitor authentication flows.
  • Operate and scale CyberArk safes and platforms.

Skills

Hands on experience in MFA and PAM operations
Strong troubleshooting skills
Stakeholder communication
PowerShell scripting
Python scripting

Tools

Cerebra mPass
CyberArk
REST APIs

Job description

About the job IAM/PAM PKI Engineer (mPass, CyberArk)

Department: Cybersecurity. Identity & Access Management

Nationality: Saudi nationals only

Overview

DXC is hiring an engineer to operate and improve enterprise Identity security capabilities with focus on Cerebra mPass (MFA) and CyberArk (PAM). You will stabilize day to day operations, drive onboarding and policy improvements, and prepare the roadmap for Windows Hello for Business migration and future adoption of SailPoint (IGA), BeyondTrust (PAM), and Thales HSM for PKI. Strong troubleshooting, documentation, and audit evidence discipline are essential.

Responsibilities
  • Design, configure, and support Cerebra mPass MFA policies, integrations, and user onboarding.
  • Integrate MFA with enterprise systems (VPN, remote access, cloud apps, internal networks) and monitor authentication flows, troubleshoot access issues, and improve reliability and user experience.
  • Prepare and execute the migration roadmap from mPass to Windows Hello for Business, including pilot planning, risk management, and cutover support.
  • Operate and scale CyberArk (safes, platforms, CPM/PSM health, onboarding, rotations, access workflows).
  • Drive privileged account onboarding and operational hygiene (break glass, vault policies, RBAC, session controls).
  • Support evaluation and future rollout of BeyondTrust as needed (requirements, migration planning, operational model).
  • Support readiness for IGA adoption (joiner mover leaver flows, SoD concepts, connector requirements, campaign approach, reporting needs) and contribute to implementation planning and operational runbooks once adopted.
  • Coordinate certificate lifecycle processes and integrations with the AD and PKI stakeholders.
  • Support discovery, inventory, renewal tracking, and certificate operational processes.
  • Participate in planning for HSM-backed PKI with Thales (key ceremony concepts, dual control, CRL/OCSP operational readiness). Note: day to day AD CS administration is owned by the AD team.
  • Ensure IAM, MFA, and PAM events are visible in SIEM. Maintain health KPIs and execute changes via ITSM with clear testing, validation, rollback, and post-implementation reviews. Lead or support RCA for major incidents. Publish SOPs, runbooks, and produce audit ready evidence aligned with KSA cybersecurity requirements, including access controls and privileged access governance.
  • Use PowerShell, Python, and REST APIs to automate onboarding, rotations, reporting, and operational checks.
Required Qualifications
  • Typically 5+ years in IAM. Hands on experience in MFA and PAM operations at enterprise scale.
  • Strong experience with Cerebra mPass (or equivalent MFA platform) and CyberArk.
  • Solid understanding of authentication and identity concepts, including SAML, OAuth 2.0, OpenID Connect, AD and LDAP.
  • Strong troubleshooting, stakeholder communication, and documentation skills.
  • Practical scripting skills (PowerShell or Python). Comfortable with REST APIs.
Preferred Qualifications
  • Experience with enterprise MFA rollout and user adoption strategies.
  • Exposure to Windows Hello for Business, SailPoint, or BeyondTrust.
  • Experience operating in regulated environments with strong evidence and audit readiness.
  • Certifications are a plus (CyberArk, Microsoft Identity, CISSP/CISM, ITIL).
Working Model

Riyadh based. Standard business hours.

Occasional after hours or weekend windows for planned changes and critical operations.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Administrator - CyberArk PAM, DellOne TPAM
Administrator - CyberArk PAM, DellOne TPAM

HCL Technologies Limited • Riyadh

On-site
SAR 180,000 - 260,000
IAM & PAM PKI Engineer — Cybersecurity Identity Lead
IAM & PAM PKI Engineer — Cybersecurity Identity Lead

CBT • Riyadh

On-site
SAR 120,000 - 150,000
Identity & Access Management (IAM/PAM) Specialist
Identity & Access Management (IAM/PAM) Specialist

CCDS • Riyadh

On-site
SAR 300,000 - 420,000
Cybersecurity – Identity & Access Management Expert
Cybersecurity – Identity & Access Management Expert

atmaal • Riyadh

On-site
SAR 180,000 - 300,000
Business Development Manager (IAM)
Business Development Manager (IAM)

Paramount Assure • Saudi Arabia

On-site
SAR 150,000 - 210,000
Business Development Manager (IAM)
Business Development Manager (IAM)

Paramountassure • Saudi Arabia

On-site
SAR 180,000 - 300,000
Cybersecurity Access Control Specialist
Cybersecurity Access Control Specialist

Cipher | سايڤر • Riyadh

On-site
SAR 120,000 - 210,000
Technical Engineer
Technical Engineer

safe-pass • Riyadh

On-site
SAR 180,000 - 250,000
Competitive salary based on experience
Performance-based bonuses
Professional development and certificat
+1
Information Security Specialist | IDM Technologies | Riyadh, Saudi Arabia
Information Security Specialist | IDM Technologies | Riyadh, Saudi Arabia

Tech Junction Ltd • Riyadh

On-site
SAR 180,000 - 300,000
Identity and Access Control Manager
Identity and Access Control Manager

Derayah Financial • Riyadh

On-site
SAR 240,000 - 420,000