PAM Engineering Lead

WTW

Minneapolis (MN)

On-site

USD 130,000 - 170,000

Full time

44 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Health benefits
401(k) plan with company contribution
Paid time off

Job summary

Willis Towers Watson IT seeks a senior PAM Engineering Lead to drive CyberArk (Idira) PAM solutions, own the platform backlog, and mentor the IAM team. The role focuses on building, operating, and improving the privileged access platform while aligning with business risk and regulatory priorities.

The candidate will manage automation of credential rotation, integrate with AD/Entra ID, Windows, Unix/Linux, databases, and networks, and collaborate with senior stakeholders to deliver secure access

Qualifications

  • 5+ years in IAM/PAM SaaS engineering, incl. 3+ years with CyberArk (Idira) Privileged Access Manager.
  • Experience leading PAM engineering teams and setting technical direction.
  • Experience integrating CyberArk with Active Directory/Entra ID, Windows, Unix/Linux, databases, and network devices.
  • Scripting proficiency with CyberArk REST API, PACLI, PowerShell and Python.
  • Strong stakeholder communication and backlog management.

Responsibilities

  • Lead design, build and maintenance of CyberArk Privileged Access Manager solutions.
  • Own PAM platform backlog and roadmap in collaboration with stakeholders.
  • Oversee onboarding, credential rotation automation and platform health.
  • Define privileged access policies and just-in-time access models.
  • Communicate status to leadership and mentor IAM team members.

Skills

PAM engineering
Backlog ownership
Stakeholder communication
Mentoring engineers

Tools

CyberArk Vault
CPM
PVWA
PSM
PACLI
PowerShell
Python
Active Directory/Entra ID

Job description

The Role

Willis Towers Watson IT is currently seeking a senior, experienced candidate for the position of PAM Engineering Lead. In this position, the successful candidate must demonstrate significant hands‑on experience engineering CyberArk PAM solutions, together with the seniority to set technical direction, own and prioritise a product backlog, and mentor engineers within the team. The main focus of this position is to lead the build, operation and continuous improvement of our CyberArk (Idira) platform while acting as product owner for the privileged access platform roadmap, influencing senior stakeholders and ensuring successful delivery of service, stakeholder alignment and continuous development of the IAM Team.

Description
The Role

Willis Towers Watson IT is currently seeking a senior, experienced candidate for the position of PAM Engineering Lead. In this position, the successful candidate must demonstrate significant hands‑on experience engineering CyberArk PAM solutions, together with the seniority to set technical direction, own and prioritise a product backlog, and mentor engineers within the team. The main focus of this position is to lead the build, operation and continuous improvement of our CyberArk (Idira) platform while acting as product owner for the privileged access platform roadmap, influencing senior stakeholders and ensuring successful delivery of service, stakeholder alignment and continuous development of the IAM Team.

Major Accountabilities
  • Lead the design, build and maintenance of CyberArk (Idira) Privileged Access Manager solutions, including Vault architecture, Safes, target platforms and session management across WTW.
  • Own and prioritise the PAM platform backlog, setting technical direction and acting as product owner for the privileged access roadmap based on business risk, compliance deadlines and stakeholder demand.
  • Oversee the build and maintenance of privileged account onboarding and credential/SSH key rotation automation via the Central Policy Manager (CPM), integrating with Active Directory/Entra ID, Windows, Unix/Linux, databases and network devices.
  • Define and govern privileged access policies, least‑privilege and just‑in‑time access models and privileged session review campaigns across WTW.
  • Act as the senior technical authority within IAM, covering all aspects of Privileged Access Management.
  • Drive solution development through problem solving, ensuring adherence to Security Controls, Policies and Standards with a focus on automation and control.
  • Influence senior stakeholders across IT, Compliance and the business to align the privileged access roadmap with WTW's risk and regulatory priorities.
  • Lead the development of skills and capabilities within the IAM team, mentoring engineers and driving process improvements and documentation.
Responsibilities
  • Oversee configuration and troubleshooting of CyberArk connectors and platforms (PSM, CPM, PVWA) to Windows, Unix/Linux, database and network device targets, working hands‑on where required.
  • Author and review custom platforms, connection components and automation scripts (CyberArk REST API, PACLI, PowerShell and Python), setting standards for the wider team.
  • Govern the operational execution of privileged session recording and review, Safe membership reviews, and privileged account discovery initiatives.
  • Oversee platform health, ensuring credential rotation and session recording failures are resolved and audit trail integrity is maintained.
  • Lead sprint planning, backlog grooming and roadmap reviews.
  • Own roadmap and status communications for leadership and stakeholders.
  • Oversee the privileged account lifecycle, including onboarding, offboarding and account updates.
  • Ensure compliance with internal policies and external regulations, escalating risks as needed.
  • Own the response to audit findings and drive remediation measures to closure.
  • Oversee resolution of escalated issues and support tickets, providing senior technical input where needed.
Qualifications
The Requirements
  • 5+ years in IAM/PAM SaaS engineering, including 3+ years hands‑on with CyberArk (Idira) Privileged Access Manager (Vault, CPM, PSM, PVWA), with demonstrated experience leading PAM engineering teams.
  • Strong understanding of PAM concepts: privileged account lifecycle, credential/SSH key rotation, session isolation and monitoring, least‑privilege and just‑in‑time access.
  • Experience integrating CyberArk with Active Directory/Entra ID, Windows, Unix/Linux, databases, network devices and SaaS applications.
  • Scripting proficiency with the CyberArk REST API, PACLI, PowerShell and Python for automation and integration.
  • Working knowledge of identity and secrets management standards: SAML, OAuth2/OIDC and secrets management (Conjur/AAM or equivalent).
  • Experience with access governance frameworks and compliance mapping (ISO 27001, SOC 2, GDPR or similar).
  • Demonstrated experience writing user stories, managing a backlog, or working closely with product/agile teams.
  • Strong stakeholder communication skills, able to translate technical detail for both engineers and business stakeholders.
  • Good project management skills.
  • Positive team‑first attitude with strong verbal and written communication skills.
  • Must possess sound analytical and problem‑solving capabilities.
Nice to have
  • CyberArk certification (CyberArk Defender/Sentry - PAM).
  • Experience with BeyondTrust, Delinea (Thycotic) or HashiCorp Vault as a comparison point.
  • Familiarity with Agile/Scrum ceremonies and tools (Jira, Azure DevOps).
  • Exposure to Zero Trust principles and NIST SP 800-53 AC/IA control families.
Note:

Employment‑based non‑immigrant visa sponsorship and/or assistance is not offered for this specific job opportunity.

Compensation And Benefits

Base salary range and benefits information for this position are being included in accordance with requirements of various state/local pay transparency legislation. Please note that salaries may vary for different individuals in the same role based on several factors, including but not limited to location of the role, individual competencies, education/professional certifications, qualifications/experience, performance in the role and potential for revenue generation (Producer roles only).

Compensation

The base salary compensation range being offered for this role is $130,000.00-$170,000.00 USD annually. This role is also eligible for an annual short‑term incentive bonus.

Company Benefits

WTW provides a competitive benefit package which includes the following (eligibility requirements apply):

  • Health and Welfare Benefits: Mental health/emotional wellbeing (including Employee Assistance Program), medical (including prescription drug coverage and fertility benefits), dental, vision, Health Savings Account, Commuter Accounts, Health Care and Dependent Care Flexible Spending Accounts, company‑paid life insurance, supplemental life insurance, AD&D, group accident, group critical illness, group legal, identify theft protection, wellbeing program, adoption assistance, surrogacy assistance, auto/home insurance, pet insurance and other work/life resources
  • Leave Benefits: Paid holidays, annual paid time off (includes state/local paid leave where required), company‑paid disability (short‑term and long‑term disability), other leaves (e.g., bereavement, FMLA, ADA, jury duty, military leave, and Parental and Adoption Leave), Paid Time Off (only included for Washington roles)
  • Retirement Benefits: Qualified contributory pension plan (if eligible) and 401(k) plan with annual nonelective company contribution. Non‑qualified retirement plans available to senior level colleagues who satisfy the plans’ eligibility requirements.

Pursuant to the San Francisco Fair Chance Ordinance and Los Angeles County Fair Chance Ordinance for Employers, we will consider for employment qualified applicants with arrest and conviction records.

This position will remain posted for a minimum of three business days from the date posted or until sufficient/appropriate candidate slate has been identified.

EOE, including disability/vets
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

PAM Engineering Lead
PAM Engineering Lead

Willis Towers Watson • Minneapolis (MN)

On-site
USD 130,000 - 170,000
Health and wellbeing benefits
401(k) and pension plan
Paid holidays and PTO
Privileged Access Management (PAM) Consultant
Privileged Access Management (PAM) Consultant

Palo Alto Networks • Columbus (OH)

On-site
USD 130,000 - 180,000
Privileged Access Management (PAM) Consultant
Privileged Access Management (PAM) Consultant

Palo Alto Networks • United States

On-site
USD 140,000 - 190,000
Privileged Access Management (PAM) Engineer - CyberArk Specialist | Cross-Border Banking and Ma[...]
Privileged Access Management (PAM) Engineer - CyberArk Specialist | Cross-Border Banking and Ma[...]

Techfellow Limited • Woodbridge Township (NJ)

Hybrid
USD 127,000 - 150,000
PAM Lead Engineer - Remote
PAM Lead Engineer - Remote

Experian • Austin (TX)

Remote
USD 180,000 - 240,000
Great compensation package and bonus plan
Core benefits including medical, dental, vision, and matching 401K
Flexible time off including volunteer and vacation
+2
Privileged Access Management (PAM) Engineer
Privileged Access Management (PAM) Engineer

Samsung SDS America • San Jose (CA)

On-site
USD 150,000 - 175,000
Health insurance
401K match
Paid Holidays
+3
Privileged Access Management (PAM) Engineer
Privileged Access Management (PAM) Engineer

Samsung SDS • San Jose (CA), Northern (KY)

Hybrid
USD 150,000 - 175,000
Medical coverage
Wellness program
401K match
+5
Senior Technology Security Engineer (IAM)
Senior Technology Security Engineer (IAM)

Pointwest-North America • Des Moines (IA)

On-site
USD 100,000 - 130,000
Identity and Access Management (IAM) Senior Analyst
Identity and Access Management (IAM) Senior Analyst

Synergy Business Consulting, Inc. • Miami (FL)

Hybrid
USD 100,000 - 130,000
Senior CyberArk Engineer - (Remote in the US)
Senior CyberArk Engineer - (Remote in the US)

GuidePoint Security, LLC • United States

Remote
USD 110,000 - 140,000
Group Medical Insurance options
Flexible Time Off (FTO) program
Healthy mobile phone allowance