What are the responsibilities and job description for the PAM Engineer Lead position at Delviom LLC?
Position Overview
The Lead PAM Engineer shall be responsible for planning, designing, and implementing Privileged Access Management (PAM) capabilities across enterprise on-premises and cloud environments. The role shall lead stakeholder engagement, PAM architecture design, implementation planning, and operational integration activities supporting Zero Trust Architecture (ZTA) objectives.
The environment currently utilizes CyberArk as the primary on-premises PAM platform with Microsoft Entra Privileged Identity Management (PIM) being introduced for Microsoft 365 cloud environments. The Lead PAM Engineer shall develop and execute a convergence strategy aligning CyberArk and Entra PIM under a unified privileged identity management framework. PAM implementation activities are considered a Phase 1 Zero Trust deliverable and shall commence at contract award.
Minimum Qualifications
- CISSP (Certified Information Systems Security Professional)
- PMP (Project Management Professional)
- And/or relevant platform certifications including:
- CyberArk Certified Delivery Engineer (CDE) or CyberArk Guardian
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Okta certifications, if applicable to scope
Note: CyberArk and Microsoft identity certifications are considered equally important for this role.
Required Experience
- Demonstrated experience implementing CyberArk PAM in on-premises enterprise environments
- Demonstrated experience with Microsoft Entra Privileged Identity Management (PIM)
- Experience architecting unified PAM strategies across hybrid cloud and on-premises environments
- Experience implementing privileged access workflows, credential vaulting, and session management capabilities
- Experience providing stakeholder engagement, executive briefings, and technical presentations
- Familiarity with Zero Trust Architecture identity pillar principles
- Experience integrating PAM platforms with SIEM solutions for privileged activity logging and monitoring
Preferred Qualifications
- CyberArk Certified Delivery Engineer (CDE) or Guardian certification
- Microsoft SC-300 certification
- Experience migrating from legacy PAM solutions to hybrid CyberArk and Entra PIM environments
- Experience with CyberArk Conjur for DevSecOps and secrets management
- Experience implementing Just-in-Time (JIT) privileged access models
- Combined CISSP and PMP credentials
- Prior federal PAM implementation experience at enterprise scale
Work Location
Hybrid work environment with onsite presence required for CyberArk infrastructure activities and stakeholder engagement. Washington, DC metropolitan area candidates preferred.