PAM Engineering Lead

Willis Towers Watson

Minneapolis (MN)

On-site

USD 130,000 - 170,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health and wellbeing benefits
401(k) and pension plan
Paid holidays and PTO

Job summary

Willis Towers Watson is seeking a Senior PAM Engineering Lead in Minneapolis to direct the design, build, and operation of CyberArk Idira Privileged Access Manager solutions. You will own the PAM backlog, partner with stakeholders, and mentor IAM engineers to drive automation and secure access controls.

This role requires hands-on CyberArk expertise, strong scripting skills, and experience integrating PAM with AD/Entra ID, Windows, Unix/Linux, databases, and networks.

Qualifications

  • 5+ years in IAM/PAM SaaS engineering, including 3+ years hands-on with CyberArk (Idira) Privileged Access Manager (Vault, CPM, PSM, PVWA)
  • Strong understanding of PAM concepts: privileged account lifecycle, credential/SSH key rotation, session isolation and monitoring
  • Experience integrating CyberArk with Active Directory/Entra ID, Windows, Unix/Linux, databases, network devices and SaaS applications
  • Scripting proficiency with the CyberArk REST API, PACLI, PowerShell and Python for automation and integration
  • Working knowledge of identity and secrets management standards: SAML, OAuth2/OIDC and secrets management (Conjur/AAM or equivalent)
  • Experience with access governance frameworks and compliance mapping (ISO 27001, SOC 2, GDPR or similar)
  • Demonstrated experience writing user stories, managing a backlog, or working closely with product/agile teams
  • Strong stakeholder communication skills, able to translate technical detail for both engineers and business stakeholders
  • Good project management skills
  • Positive team-first attitude with strong verbal and written communication skills
  • Must possess sound analytical and problem-solving capabilities

Responsibilities

  • Lead the design, build and maintenance of CyberArk Privileged Access Manager solutions (Vault, CPM, PSM, PVWA)
  • Own and prioritise the PAM platform backlog and act as product owner for the privileged access roadmap
  • Oversee onboarding and credential/SSH key rotation automation via CPM, integrating with AD/Entra ID, Windows, Unix/Linux, databases and network devices
  • Define and govern privileged access policies, least-privilege and just-in-time access models
  • Drive solution development and automation while ensuring security controls and standards
  • Influence senior stakeholders to align the privileged access roadmap with risk priorities
  • Lead IAM team skills development, mentoring engineers and driving process improvements
  • Oversee privileged account lifecycle management and audit readiness
  • Ensure compliance and remediation of audit findings
  • Oversee incident/escalation resolution and provide senior technical input

Skills

CyberArk Idira PAM
PAM engineering
Automation scripting
Active Directory/Entra ID
PowerShell
Python
SAML/OIDC/OAuth2
ISO 27001 / SOC 2

Tools

CyberArk CPM
CyberArk PSM
CyberArk PVWA
PACLI

Job description

Description

The Role

Willis Towers Watson IT is currently seeking a senior, experienced candidate for the position of PAM Engineering Lead. In this position, the successful candidate must demonstrate significant hands-on experience engineering CyberArk PAM solutions, together with the seniority to set technical direction, own and prioritise a product backlog, and mentor engineers within the team. The main focus of this position is to lead the build, operation and continuous improvement of our CyberArk (Idira) platform while acting as product owner for the privileged access platform roadmap, influencing senior stakeholders and ensuring successful delivery of service, stakeholder alignment and continuous development of the IAM Team.

Major Accountabilities:

  • Lead the design, build and maintenance of CyberArk (Idira) Privileged Access Manager solutions, including Vault architecture, Safes, target platforms and session management across WTW.
  • Own and prioritise the PAM platform backlog, setting technical direction and acting as product owner for the privileged access roadmap based on business risk, compliance deadlines and stakeholder demand.
  • Oversee the build and maintenance of privileged account onboarding and credential/SSH key rotation automation via the Central Policy Manager (CPM), integrating with Active Directory/Entra ID, Windows, Unix/Linux, databases and network devices.
  • Define and govern privileged access policies, least-privilege and just-in-time access models and privileged session review campaigns across WTW.
  • Act as the senior technical authority within IAM, covering all aspects of Privileged Access Management.
  • Drive solution development through problem solving, ensuring adherence to Security Controls, Policies and Standards with a focus on automation and control.
  • Influence senior stakeholders across IT, Compliance and the business to align the privileged access roadmap with WTW's risk and regulatory priorities.
  • Lead the development of skills and capabilities within the IAM team, mentoring engineers and driving process improvements and documentation.

Responsibilities

  • Oversee configuration and troubleshooting of CyberArk connectors and platforms (PSM, CPM, PVWA) to Windows, Unix/Linux, database and network device targets, working hands-on where required.
  • Author and review custom platforms, connection components and automation scripts (CyberArk REST API, PACLI, PowerShell and Python), setting standards for the wider team.
  • Govern the operational execution of privileged session recording and review, Safe membership reviews, and privileged account discovery initiatives.
  • Oversee platform health, ensuring credential rotation and session recording failures are resolved and audit trail integrity is maintained.
  • Lead sprint planning, backlog grooming and roadmap reviews.
  • Own roadmap and status communications for leadership and stakeholders.
  • Oversee the privileged account lifecycle, including onboarding, offboarding and account updates.
  • Ensure compliance with internal policies and external regulations, escalating risks as needed.
  • Own the response to audit findings and drive remediation measures to closure.
  • Oversee resolution of escalated issues and support tickets, providing senior technical input where needed.
Qualifications

The Requirements

  • 5+ years in IAM/PAM SaaS engineering, including 3+ years hands-on with CyberArk (Idira) Privileged Access Manager (Vault, CPM, PSM, PVWA), with demonstrated experience leading PAM engineering teams.
  • Strong understanding of PAM concepts: privileged account lifecycle, credential/SSH key rotation, session isolation and monitoring, least-privilege and just-in-time access.
  • Experience integrating CyberArk with Active Directory/Entra ID, Windows, Unix/Linux, databases, network devices and SaaS applications.
  • Scripting proficiency with the CyberArk REST API, PACLI, PowerShell and Python for automation and integration.
  • Working knowledge of identity and secrets management standards: SAML, OAuth2/OIDC and secrets management (Conjur/AAM or equivalent).
  • Experience with access governance frameworks and compliance mapping (ISO 27001, SOC 2, GDPR or similar).
  • Demonstrated experience writing user stories, managing a backlog, or working closely with product/agile teams.
  • Strong stakeholder communication skills, able to translate technical detail for both engineers and business stakeholders.
  • Good project management skills.
  • Positive team-first attitude with strong verbal and written communication skills.
  • Must possess sound analytical and problem-solving capabilities.

Nice to have

  • CyberArk certification (CyberArk Defender/Sentry - PAM).
  • Experience with BeyondTrust, Delinea (Thycotic) or HashiCorp Vault as a comparison point.
  • Familiarity with Agile/Scrum ceremonies and tools (Jira, Azure DevOps).
  • Exposure to Zero Trust principles and NIST SP 800-53 AC/IA control families.

Note: Employment-based non-immigrant visa sponsorship and/or assistance is not offered for this specific job opportunity.

Compensation and Benefits

Compensation

The base salary compensation range being offered for this role is $130,000.00-$170,000.00 USD annually. This role is also eligible for an annual short-term incentive bonus.

Company Benefits

WTW provides a competitive benefit package which includes the following (eligibility requirements apply):

  • Health and Welfare Benefits: Mental health/emotional wellbeing (including Employee Assistance Program), medical (including prescription drug coverage and fertility benefits), dental, vision, Health Savings Account, Commuter Accounts, Health Care and Dependent Care Flexible Spending Accounts, company-paid life insurance, supplemental life insurance, AD&D, group accident, group critical illness, group legal, identify theft protection, wellbeing program, adoption assistance, surrogacy assistance, auto/home insurance, pet insurance and other work/life resources
  • Leave Benefits: Paid holidays, annual paid time off (includes state/local paid leave where required), company-paid disability (short-term and long-term disability), other leaves (e.g., bereavement, FMLA, ADA, jury duty, military leave, and Parental and Adoption Leave), Paid Time Off (only included for Washington roles)
  • Retirement Benefits: Qualified contributory pension plan (if eligible) and 401(k) plan with annual nonelective company contribution. Non-qualified retirement plans available to senior level colleagues who satisfy the plans’ eligibility requirements.

Pursuant to the San Francisco Fair Chance Ordinance and Los Angeles County Fair Chance Ordinance for Employers, we will consider for employment qualified applicants with arrest and conviction records.

This position will remain posted for a minimum of three business days from the date posted or until sufficient/appropriate candidate slate has been identified.

EOE, including disability/vets

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Privileged Access Management (PAM) Consultant
Privileged Access Management (PAM) Consultant

Palo Alto Networks • United States

On-site
USD 140,000 - 190,000
Privileged Access Management (PAM) Engineer - CyberArk Specialist | Cross-Border Banking and Ma[...]
Privileged Access Management (PAM) Engineer - CyberArk Specialist | Cross-Border Banking and Ma[...]

Techfellow Limited • Woodbridge Township (NJ)

Hybrid
USD 127,000 - 150,000
Privileged Access Management (PAM) Consultant
Privileged Access Management (PAM) Consultant

Palo Alto Networks • Columbus (OH)

On-site
USD 130,000 - 180,000
PAM Lead Engineer - Remote
PAM Lead Engineer - Remote

Experian • Austin (TX)

Remote
USD 180,000 - 240,000
Great compensation package and bonus plan
Core benefits including medical, dental, vision, and matching 401K
Flexible time off including volunteer and vacation
+2
Privileged Access Management (PAM) Engineer
Privileged Access Management (PAM) Engineer

Samsung SDS America • San Jose (CA)

On-site
USD 150,000 - 175,000
Health insurance
401K match
Paid Holidays
+3
Privileged Access Management (PAM) Engineer
Privileged Access Management (PAM) Engineer

Samsung SDS • San Jose (CA), Northern (KY)

Hybrid
USD 150,000 - 175,000
Medical coverage
Wellness program
401K match
+5
Identity and Access Management (IAM) Senior Analyst
Identity and Access Management (IAM) Senior Analyst

Synergy Business Consulting, Inc. • Miami (FL)

Hybrid
USD 100,000 - 130,000
CyberArk Engineer (Contract)
CyberArk Engineer (Contract)

Socket.dev • Dallas (TX)

Hybrid
USD 83,000 - 165,000
PAM Engineer
PAM Engineer

JCW Group • Charlotte (NC)

On-site
USD 120,000 - 180,000
Privileged Access Management Engineer
Privileged Access Management Engineer

JCW Group • Charlotte (NC)

On-site
USD 180,000 - 240,000