Senior PAM Engineer, VP

SMBC Group

Charlotte (NC)

Hybrid

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work model
Accommodations during candidacy

Job summary

SMBC Group is seeking an experienced IAM professional to lead Privileged Access Management initiatives across hybrid and cloud environments. You will design and deliver PAM solutions that support Zero Trust, Just-In-Time access, and least privilege controls, collaborating with security, infrastructure, cloud, and application teams.

The role emphasizes integrating CyberArk and Delinea platforms, architecting secure identity lifecycles, and ensuring compliance with audit requirements.

Qualifications

  • 5+ years of IAM experience with a strong focus on PAM.
  • Experience designing and implementing PAM solutions within complex enterprise environments.
  • Experience implementing privileged access controls for human and non-human identities.
  • Deep expertise with CyberArk PVWA, CPM, PSM, Conjur, and Secrets Manager.
  • Strong experience with Delinea Secret Server or comparable PAM platforms.
  • Knowledge of OAuth 2.0, OpenID Connect, and SAML.
  • Experience with Microsoft Entra ID, Entra PIM, Azure RBAC, and privileged role governance.
  • Strong scripting and automation skills to support PAM integrations and workflows.

Responsibilities

  • Design, implement, and maintain enterprise PAM architecture with vaulting and JIT access.
  • Lead deployment and optimization of CyberArk solutions (PVWA, CPM, PSM, Conjur).
  • Integrate CyberArk, Delinea Secret Server, and other PAM platforms across environments.
  • Develop CPM plugins and integrations for credential management.
  • Build and support authentication and secrets management using CyberArk Conjur.
  • Implement Microsoft Entra PIM for privileged role governance.
  • Define least privilege models using RBAC/ABAC across cloud and on-premises.
  • Automate PAM provisioning and onboarding with ServiceNow and SIEM tools.
  • Monitor privileged activity and improve audit-ready reporting.
  • Collaborate with IAM, Security, SOC, and Cloud teams; document standards and procedures.
  • Evaluate emerging PAM tech and mentor team members.

Skills

Privileged Access Management
CyberArk
PAM architecture
RBAC/ABAC/JIT
Scripting/Automation
OAuth/OIDC/SAML
Azure/AWS/GCP IAM

Education

Bachelor's degree in CS/IT/Cybersecurity

Tools

Delinea Secret Server
CyberArk Conjur
ServiceNow integration
SIEM integration
Microsoft Entra PIM

Job description

Select how often (in days) to receive an alert:

SMBC Group is a top-tier global financial group. Headquartered in Tokyo and with a 400-year history, SMBC Group offers a diverse range of financial services, including banking, leasing, securities, credit cards, and consumer finance. The Group has more than 130 offices and 80,000 employees worldwide in nearly 40 countries. Sumitomo Mitsui Financial Group, Inc. (SMFG) is the holding company of SMBC Group, which is one of the three largest banking groups in Japan. SMFG’s shares trade on the Tokyo, Nagoya, and New York (NYSE: SMFG) stock exchanges.

In the Americas, SMBC Group has a presence in the US, Canada, Mexico, Brazil, Chile, Colombia, and Peru. Backed by the capital strength of SMBC Group and the value of its relationships in Asia, the Group offers a range of commercial and investment banking services to its corporate, institutional, and municipal clients. It connects a diverse client base to local markets and the organization’s extensive global network. The Group’s operating companies in the Americas include Sumitomo Mitsui Banking Corp. (SMBC), SMBC Nikko Securities America, Inc., SMBC Capital Markets, Inc., SMBC MANUBANK, JRI America, Inc., SMBC Leasing and Finance, Inc., Banco Sumitomo Mitsui Brasileiro S.A., and Sumitomo Mitsui Finance and Leasing Co., Ltd.

JOB SUMMARY

Join SMBC's Identity and Access Management (IAM) Architecture and Engineering team and help strengthen the security of privileged identities across the organization. In this role, you will design and deliver Privileged Access Management (PAM) solutions that support Zero Trust principles, Just-In-Time (JIT) access, and least privilege controls across hybrid and cloud environments. You will work closely with security, infrastructure, cloud, and application teams to integrate PAM capabilities, improve operational efficiency, and support regulatory and audit requirements.

PRINCIPAL DUTIES AND RESPONSIBILITIES
  • Design, implement, and maintain enterprise PAM architecture, including credential vaulting, session monitoring, privileged access workflows, and JIT access controls.
  • Lead the deployment, configuration, and ongoing enhancement of CyberArk solutions, including PVWA, CPM, PSM, Conjur, and related components.
  • Integrate CyberArk, Delinea Secret Server, and other PAM platforms across on-premises, cloud, and hybrid environments.
  • Develop and maintain custom CPM plugins and integrations to manage credentials for proprietary or non-standard platforms.
  • Build and support application authentication and secrets management solutions using CyberArk Conjur and related technologies.
  • Implement and manage Microsoft Entra Privileged Identity Management (PIM) to govern privileged role assignments, approvals, and lifecycle management.
  • Define and enforce least privilege access models using RBAC, ABAC, and JIT methodologies across Azure, AWS, GCP, and on-premises platforms.
  • Automate PAM provisioning, access approvals, and onboarding workflows, including integration with ServiceNow, SIEM platforms, and monitoring solutions.
  • Monitor privileged activity, improve security controls, and enhance reporting to support compliance, audit readiness, and risk management.
  • Partner with IAM, Security Architecture, SOC, Infrastructure, Database, Cloud, and Application teams to embed PAM capabilities into operational processes.
  • Create and maintain architecture documentation, standard operating procedures, onboarding guides, and technical standards.
  • Evaluate emerging PAM technologies and provide technical guidance and mentoring to team members.
POSITION SPECIFICATIONS
  • 5+ years of experience in Identity and Access Management (IAM) with a strong focus on Privileged Access Management (PAM).
  • Experience designing and implementing PAM solutions within complex enterprise environments.
  • Experience implementing privileged access controls for both human and non-human identities.
  • Deep expertise with CyberArk, including PVWA, CPM, PSM, Conjur, and Secrets Manager solutions.
  • Strong experience with Delinea (formerly Thycotic) Secret Server or comparable PAM platforms.
  • Experience designing and operating credential vaulting, session management, privilege elevation, and JIT access solutions.
  • Strong understanding of authentication and federation standards, including OAuth 2.0, OpenID Connect (OIDC), and SAML.
  • Experience with Microsoft Entra ID, Entra PIM, Azure RBAC, and privileged role governance.
  • Knowledge of least privilege, Zero Trust, JIT access, and privileged identity lifecycle management.
  • Experience securing privileged access across Azure, AWS, and GCP environments.
  • Strong scripting and automation skills to support PAM integrations, workflows, and administration.
  • Ability to communicate complex technical concepts to both technical and non-technical audiences.
  • Strong analytical and problem-solving skills with attention to detail.

NICE TO HAVE

  • Experience with Identity Governance and Administration (IGA) platforms such as SailPoint, Saviynt, or Microsoft Entra IGA.
  • Experience integrating PAM platforms with Microsoft Sentinel, Cribl, or other SIEM solutions.
  • CyberArk certifications, training, or advanced product specialization.
  • CISSP, cloud security, or related cybersecurity certifications.
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field. Equivalent practical experience will also be considered.

SMBC’s employees participate in a Hybrid workforce model that provides employees with an opportunity to work from home, as well as, from an SMBC office. SMBC requires that employees live within a reasonable commuting distance of their office location. Prospective candidates will learn more about their specific hybrid work schedule during their interview process. Hybrid work may not be permitted for certain roles, including, for example, certain FINRA-registered roles for which in-office attendance for the entire workweek is required.

SMBC provides reasonable accommodations during candidacy for applicants with disabilities consistent with applicable federal, state, and local law. If you need a reasonable accommodation during the application process, please let us know at accommodations@smbcgroup.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior PAM Engineer, VP
Senior PAM Engineer, VP

SMBC • Charlotte (NC)

On-site
USD 120,000 - 180,000
Hybrid work model
Accommodations during candidacy
Sr. Cyber Security Analyst
Sr. Cyber Security Analyst

SMBC • Charlotte (NC)

Hybrid
USD 120,000 - 170,000
Hybrid work model
Sr. Cyber Security Analyst
Sr. Cyber Security Analyst

SMBC Group • Charlotte (NC)

Hybrid
USD 120,000 - 150,000
Cyber Security Engineer, VP
Cyber Security Engineer, VP

SMBC Group • Charlotte (NC), Northern (KY)

Hybrid
USD 138,000 - 208,000
Hybrid work model
Accommodations for disabilities
Senior Application Security Compliance Lead
Senior Application Security Compliance Lead

SMBC Group • Charlotte (NC)

Hybrid
USD 120,000 - 180,000
Hybrid work model
Accommodations during candidacy
Sr. Cyber Security Analyst
Sr. Cyber Security Analyst

SMBC • North Carolina

Hybrid
USD 120,000 - 180,000
Hybrid work model
Office/remote flexibility
Cybersecurity Audit Associate
Cybersecurity Audit Associate

SMBC Group • Charlotte (NC)

Hybrid
USD 70,000 - 90,000
Privileged Access Management Lead
Privileged Access Management Lead

mizuho • United States

Hybrid
USD 200,000 - 275,000
Discretionary bonus
Network Security Engineer (Palo Alto, Check Point & Firewall Policy Management)
Network Security Engineer (Palo Alto, Check Point & Firewall Policy Management)

SMBC • Charlotte (NC)

Hybrid
USD 90,000 - 130,000
Hybrid work model
Accommodations during candidacy
Vice President, Senior Data Engineer Vice President, Senior Data Engineer
Vice President, Senior Data Engineer Vice President, Senior Data Engineer

SMBC Group • Jersey City (NJ)

Hybrid
USD 169,000 - 195,000