Identity Security Specialist Solutions Engineer

AHEAD

Chicago (IL)

Remote

USD 120,000 - 180,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical Insurance
Dental Insurance
Vision Insurance
401(k)
Paid time off
Parental leave

Job summary

AHEAD is seeking an Identity Security Specialist Solutions Engineer to act as a nationwide identity-security resource across regions, account teams, and partners. You will craft CyberArk-centered architectures, guide pre-sales efforts, and align with delivery to ensure implementable solutions.

The role focuses on PIM/PAM strategies, privilege access across on-prem and cloud, and collaboration with OEM teams to enable sales and services.

Qualifications

  • 7+ years in cybersecurity/identity/security consulting, incl. 4+ years in identity security.
  • Experience with customer-facing pre-sales, solutions engineering, or security architecture.
  • Proven CyberArk implementation across lifecycle stages.
  • Expertise in PIM and PAM concepts and operating models.
  • Ability to craft proposals, SOWs, and service designs.
  • Ability to present identity-security architectures to technical and exec audiences.
  • Experience integrating privileged access with enterprise platforms.
  • Strong written and verbal communication and stakeholder management.

Responsibilities

  • Serve as national identity-security resource across regions.
  • Lead advisory discovery, security assessments, architecture workshops, and demos.
  • Design CyberArk-centered privileged-access architectures.
  • Advise on privileged-account discovery, vaulting, rotation, and least privilege.
  • Coordinate with delivery leadership to ensure implementable solutions.
  • Create solution designs, configurations, and statements of work.
  • Provide pricing and effort inputs for proposals.
  • Qualify opportunities based on requirements and readiness.
  • Define CyberArk strategies across on-prem and cloud.
  • Connect PIM/PAM to IAM, MFA, SSO, and Zero Trust.
  • Collaborate with OEM field teams on alignment and enablement.
  • Develop reusable architectures and discovery content.

Skills

CyberArk
PIM
PAM
Pre-sales
Solution design
Cloud IAM
Executive communication

Tools

CyberArk Privilege Cloud
PAM Self-Hosted
Endpoint Privilege Manager
Secrets Manager
Microsoft Entra ID
Okta

Job description

AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digital transformation. At AHEAD, we prioritize creating a culture of belonging, where all perspectives and voices are represented, valued, respected, and heard. We create spaces to empower everyone to speak up, make change, and drive the culture at AHEAD. We are an equal opportunity employer, and do not discriminate based on an individual's race, national origin, color, gender, gender identity, gender expression, sexual orientation, religion, age, disability, marital status, or any other protected characteristic under applicable law, whether actual or perceived. We embrace all candidates that will contribute to the diversification and enrichment of ideas and perspectives at AHEAD.

AHEAD is hiring an Identity Security Specialist Solutions Engineer to serve as a national identity-security resource across AHEAD's regions, account teams, delivery organization, and strategic partners.

This role specializes in CyberArk, Privileged Identity Management (PIM), and Privileged Access Management (PAM). The successful candidate will help customers assess privileged-access risk, design target-state architectures, select and size solutions, validate technical approaches, and build practical implementation roadmaps.

This is a customer-facing pre-sales and advisory role. The position shapes technical solutions, scopes services, supports proposals, and guides technical validation. Delivery teams own post-sale implementation and operational execution.

Responsibilities
  • Serve as a national identity-security resource supporting qualified opportunities across AHEAD regions.
  • Lead advisory discovery, technical sales calls, identity-security assessments, architecture workshops, demonstrations, POVs/POCs, and executive briefings.
  • Design and present CyberArk-centered privileged-access architectures for workforce, administrator, vendor, service, machine, and non-human identities.
  • Advise customers on privileged-account discovery, vaulting, credential rotation, onboarding, session management, monitoring, just-in-time access, least privilege, break-glass access, and shared-account reduction.
  • Partner with delivery leadership to ensure proposed solutions are implementable and aligned with AHEAD's professional and managed services capabilities.
  • Create solution designs, configurations, sizing inputs, services proposals, statements of work, presentations, technical justifications, and customer roadmaps.
  • Provide pricing and effort inputs for account and delivery teams; final commercial approval remains with the appropriate AHEAD leaders.
  • Qualify opportunities based on technical requirements, business outcomes, decision process, funding, and customer readiness.
  • Define CyberArk and adjacent identity-security strategies across on-premises, AWS, Azure, GCP, SaaS, and hybrid environments.
  • Connect PIM/PAM strategy to IAM, IGA, MFA, SSO, ITDR, secrets management, cloud IAM, SIEM/SOAR, ITSM, and Zero Trust programs.
  • Work with OEM field teams on technical alignment, enablement, certifications, and active customer campaigns.
  • Contribute reusable architectures, discovery guides, workshop content, competitive insights, and enablement materials.
Required Qualifications
  • 7+ years of experience in cybersecurity, identity, cloud, technology consulting, or solutions engineering, including at least 4 years focused on identity security.
  • Prior customer-facing pre-sales, solutions engineering, consulting, or security-architecture experience.
  • Demonstrated CyberArk experience in at least one enterprise program spanning two or more lifecycle stages, such as assessment, design, migration, implementation, integration, or operationalization.
  • Practical expertise in PIM and PAM concepts, controls, workflows, and operating models.
  • Experience creating customer-facing proposals, solution designs, SOWs, services proposals, or equivalent pre-sales artifacts.
  • Ability to design and present identity-security architectures to technical practitioners and executive stakeholders.
  • Experience integrating privileged access with enterprise identity, cloud, endpoint, security operations, and ITSM platforms.
  • Strong written, verbal, whiteboarding, presentation, and customer-management skills.
Preferred Qualifications
  • CyberArk certification or equivalent demonstrated product expertise.
  • Experience with CyberArk Privilege Cloud, PAM Self-Hosted, Endpoint Privilege Manager, Secrets Manager, or related capabilities.
  • Experience with Microsoft Entra ID, Active Directory, Okta, SailPoint, Saviynt, Delinea, BeyondTrust, or comparable platforms.
  • Familiarity with identity threat detection and response, non-human identity, workload identity, and cloud entitlement management.
  • Consulting experience at a systems integrator, professional services firm, advisory practice, or technology provider.
  • Delivery experience standing up, configuring, migrating, or operationalizing privileged-access tooling.
  • Familiarity with NIST, CIS Controls, Zero Trust, SOX, PCI DSS, HIPAA, or other control frameworks relevant to privileged access.
  • Relevant certifications such as CISSP, CCSP, CyberArk, GIAC, or equivalent.
Success Measures: First 6-12 months
  • Establish trusted working relationships with Security Sales, account teams, delivery leaders, CyberArk, and adjacent partners.
  • Lead repeatable identity-security discovery and workshop motions that produce qualified opportunities and clear next steps.
  • Demonstrate the ability to produce accurate solution designs, services proposals, and technical validation plans.
  • Build reusable CyberArk/PIM/PAM architectures, discovery assets, and enablement content.
  • Support successful transitions from pre-sales scope to delivery without material ambiguity in assumptions, dependencies, or customer outcomes.
Behavioral Expectations
  • Explains complex privileged-access concepts clearly to technical and executive audiences.
  • Uses specific customer evidence to connect technical design to risk reduction, operational improvement, and business value.
  • Facilitates alignment across security, identity, infrastructure, cloud, audit, and operations stakeholders.
  • Communicates assumptions, dependencies, risks, and decisions clearly in written and verbal form.
  • Works effectively in a matrixed national organization with multiple account teams, delivery groups, and OEM partners.
  • Maintains professional judgment when customer requirements, product capabilities, or commercial constraints conflict.

The compensation range indicated in this posting reflects the On-Target Earnings ("OTE") for this role, which includes a base salary and any applicable target bonus amount. This OTE range may vary based on the candidate's relevant experience, qualifications, and geographic location.

Why AHEAD:

Through our daily work and internal groups like Moving Women AHEAD and RISE AHEAD, we value and benefit from diversity of people, ideas, experience, and everything in between. We fuel growth by stacking our office with top-notch technologies in a multi-million-dollar lab, by encouraging cross department training and development, sponsoring certifications and credentials for continued learning.

USA Employment Benefits include:
  • Medical, Dental, and Vision Insurance
  • 401(k)
  • Paid company holidays
  • Paid time off
  • Paid parental and caregiver leave
  • Plus more! See benefits for additional details.
Use of AI:

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, assessing responses, or to capture recordings and create transcriptions or summaries during interviews. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans.

If you would like more information about how your data is processed, please refer to the Candidate Privacy Notice or contact us at . You may opt-out of the review or analysis of your application and resume by AI tools by using the General Application. Please include the role you wish to apply for in the Additional Information field. You may also choose to opt-out of recording and transcription at any time, including after joining an interview. Candidates will not be penalized for choosing to opt-out.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Identity Security Specialist Solutions Engineer
Identity Security Specialist Solutions Engineer

AHEAD • United States

On-site
USD 270,000 - 300,000
Medical, Dental, and Vision Insurance
401(k)
Paid company holidays
+3
Identity Security Specialist Solutions Engineer
Identity Security Specialist Solutions Engineer

thinkahead • United States

On-site
USD 120,000 - 180,000
Senior Technical Consultant - Cloud Security
Senior Technical Consultant - Cloud Security

AHEAD • United States

Remote
USD 150,000 - 190,000
Medical Insurance
401(k) Plan
Paid Holidays
+2
Senior Identity Application Architect, CIAM/IAM
Senior Identity Application Architect, CIAM/IAM

AHEAD • Chicago (IL)

On-site
USD 140,000 - 200,000
Medical Insurance
Dental Insurance
Vision Insurance
+4
Senior Technical Consultant - Cloud Security
Senior Technical Consultant - Cloud Security

AHEAD • Northern (KY)

Hybrid
USD 170,000 - 220,000
Medical, Dental, Vision Insurance
401(k)
Paid holidays
+2
Technical Consultant - Cloud Security
Technical Consultant - Cloud Security

AHEAD • Chicago (IL)

Hybrid
USD 110,000 - 140,000
Medical Insurance
401(k)
Paid Time Off
+1
Senior Identity Application Architect, CIAM/IAM
Senior Identity Application Architect, CIAM/IAM

AHEAD • Northern (KY)

Hybrid
USD 145,000 - 175,000
Medical Insurance
401(k)
Paid holidays
+2
Project Manager: Security Services
Project Manager: Security Services

AHEAD • Northern (KY)

Hybrid
USD 140,000 - 170,000
Medical, Dental, and Vision Insurance
401(k)
Paid holidays
+2
Principal Technical Consultant – Cloud and Application Security
Principal Technical Consultant – Cloud and Application Security

AHEAD • Northern (KY)

Hybrid
USD 250,000 - 300,000
Medical, Dental, Vision Insurance
401(k)
Paid holidays
+2
Senior Consultant - Cyber Resilience
Senior Consultant - Cyber Resilience

AHEAD • Northern (KY)

Hybrid
USD 160,000 - 200,000
Medical, Dental, and Vision Insurance
401(k)
Paid company holidays
+2