Director, Interactive Privileged Access & Endpoint Elevation

Fidelity

United States

On-site

USD 180,000 - 250,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Fidelity is seeking a Director to lead Interactive Privileged Access and Endpoint Elevation, owning the enterprise PAM program and associated platforms. You will drive CyberArk, endpoint privilege management, and related technologies across workforce, infrastructure, and operations, balancing people leadership with hands-on technical ownership.

The role combines strategy, architecture, and delivery with a focus on secure-by-default experiences, audit readiness, and risk reduction.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, Engineering, or related field.
  • 3+ years direct people leadership experience.
  • Hands-on experience implementing and operating CyberArk in large-scale enterprise environments.
  • Deep expertise in Privileged Access Management architecture and controls.
  • Experience with endpoint privilege management platforms such as Delinea or BeyondTrust.
  • Strong understanding of Windows and endpoint privilege controls.
  • Experience with Infrastructure as Code, automation, and policy-driven controls.
  • Strong understanding of Zero Trust, identity security, and PAM governance.
  • Experience leading large-scale PAM deployments, migrations, and modernization initiatives.
  • Proven ability to influence senior stakeholders and drive strategic outcomes.
  • Strong communication and product delivery skills.

Responsibilities

  • Lead and develop engineering and product teams delivering enterprise privileged access and endpoint privilege management capabilities.
  • Own the enterprise platforms, roadmap, delivery, resiliency, and lifecycle management for PAM technologies.
  • Establish clear operating rhythms and foster an inclusive, learning-focused engineering culture.
  • Build scalable onboarding patterns and automation for privileged accounts, endpoints, servers, and workforce access use cases.
  • Ensure platform hardening, audit evidence, DR/IR readiness, and continuous risk reduction.
  • Design and implement least-privilege access models and just-in-time access capabilities.
  • Automate credential lifecycle management including vaulting, rotation, and policy enforcement.
  • Harden PAM platforms using secure configuration standards and IaC-based lifecycle management.
  • Enable self-service onboarding with reference implementations for administrators, engineers, and support teams.
  • Integrate privileged access platforms with identity, ITSM, workflow, and security monitoring solutions.
  • Partner with infrastructure and application teams to modernize enterprise access models.
  • Drive platform modernization and adoption of emerging PAM capabilities across the enterprise.

Skills

Leadership
Zero Trust
Stakeholder mgmt
Product ownership
Security governance
Windows security

Education

Bachelor's degree in CS/IS/Engineering

Tools

CyberArk
Delinea
BeyondTrust

Job description

Note: Fidelity will not provide immigration sponsorship for this position

The Role

The Director, Interactive Privileged Access & Endpoint Elevation leads the enterprise program and platforms for interactive privileged access, credential vaulting, session management, and endpoint/server privilege elevation.

This technical leadership role owns Fidelity's privileged access platforms, including CyberArk, endpoint privilege management solutions, and related privileged access technologies supporting workforce, infrastructure, and operational environments. The role combines people leadership, product ownership, and deep hands-on technical expertise in privileged access management to deliver secure-by-default experiences while meeting regulatory, audit, and risk management requirements.

The key responsibilities of the role are:
  • Lead and develop engineering and product teams delivering enterprise privileged access and endpoint privilege management capabilities.
  • Own the enterprise platforms, roadmap, delivery, resiliency, and lifecycle management for CyberArk, endpoint privilege management, workforce vault, and related PAM technologies.
  • Establish clear operating rhythms (standups, planning, retrospectives) and an inclusive, learning-focused engineering culture.
  • Build scalable onboarding patterns and automation for privileged accounts, endpoints, servers, and workforce access use cases.
  • Ensure platform hardening, compliance, audit evidence, DR/IR readiness, and continuous risk reduction.
  • Design and implement least-privilege access models, just-in-time access capabilities, privileged session controls, and command elevation policies.
  • Automate credential lifecycle management, including vaulting, rotation, reconciliation, session management, and policy enforcement.
  • Harden PAM platforms using secure configuration standards and implement automated configuration, upgrades, and lifecycle management through Infrastructure as Code.
  • Enable scalable onboarding and self-service experiences with paved paths and reference implementations for administrators, engineers, and support teams.
  • Integrate privileged access platforms with enterprise identity, ITSM, workflow, and security monitoring solutions.
  • Partner with infrastructure, workplace, and application teams to eliminate standing privileged access and modernize enterprise access models.
  • Drive platform modernization, tool rationalization, and adoption of emerging PAM capabilities across the enterprise.
The Expertise and Skills You Bring
  • Bachelor's degree in Computer Science, Information Security, Engineering, or related field (Master's preferred).
  • 3+ years direct people leadership experience, including hiring, coaching, performance management, and career development.
  • Deep hands-on engineering experience implementing and operating CyberArk in large-scale enterprise production environments.
  • Deep expertise in Privileged Access Management architecture, controls, operational processes, and industry best practices.
  • Strong hands-on experience with endpoint privilege management platforms such as Delinea, BeyondTrust, or equivalent technologies.
  • Expertise with CyberArk core components, privileged credential management, session management, privileged workflows, credential rotation, and vault operations.
  • Strong understanding of Windows and endpoint privilege controls, including LAPS, local administrator management, and least-privilege enforcement.
  • Experience with Infrastructure as Code, automation, policy-driven controls, and operational engineering practices.
  • Strong understanding of Zero Trust, identity security, and privileged access governance principles.
  • Experience leading large-scale PAM deployments, migrations, transformations, and platform modernization initiatives.
  • Proven ability to influence senior stakeholders and drive strategic outcomes across engineering, infrastructure, security, and risk organizations.
  • Strong communication, stakeholder influence, and product delivery skills.
Fidelity's Onsite Working Model

Fidelity is transitioning to a full-time onsite working model through a phased rollout across regions and roles. Currently, some roles and locations require 100% onsite presence, while others require less. Onsite expectations are likely to evolve as the rollout continues. This transition does not apply to fully remote roles.

Certifications:

Category:

Information Technology Please be advised that Fidelity's business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Digital Assets Systems Engineer
Senior Digital Assets Systems Engineer

Fidelity Investments • Roanoke (TX)

On-site
USD 140,000 - 230,000
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Soteria Reinsurance Ltd. • Town of Texas (WI)

On-site
USD 95,000 - 135,000
Principal Cybersecurity Analyst
Principal Cybersecurity Analyst

Fidelity • Durham (NC)

On-site
USD 130,000 - 180,000
On-site health centers
Fully paid parent leave
On-site wellness facilities
Director, Software Engineering
Director, Software Engineering

Worky • Durham (NC)

On-site
USD 180,000 - 240,000
Director, Software Engineering (Individual Contributor)
Director, Software Engineering (Individual Contributor)

Soteria Reinsurance Ltd. • Merrimack (NH)

On-site
USD 150,000 - 210,000
Director, Software Engineering
Director, Software Engineering

Soteria Reinsurance Ltd. • Durham (NC)

On-site
USD 180,000 - 260,000
Principal Cybersecurity Analyst
Principal Cybersecurity Analyst

Soteria Reinsurance Ltd. • Durham (NC)

On-site
USD 120,000 - 180,000
Onsite Working Model
Director, Software Engineering (UI)
Director, Software Engineering (UI)

Fidelity Investments • Merrimack (NH)

On-site
USD 180,000 - 240,000
Director, Software Engineering
Director, Software Engineering

Soteria Reinsurance Ltd. • Town of Texas (WI)

On-site
USD 180,000 - 230,000
Principal, Cybersecurity Risk
Principal, Cybersecurity Risk

Fidelity Investments • Durham (NC)

On-site
USD 120,000 - 180,000