Overview
Lead engineering ownership for enterprise Privileged Access Management (PAM) capabilities within the Global Cybersecurity organization. This hands-on technical leadership role focuses on CyberArk, HashiCorp Vault, PIM, AKV, AWS, automation, platform modernization, and operational resilience in complex, highly regulated environments.
What you'll do
- Lead the engineering lifecycle for enterprise PAM platforms, including CyberArk, HashiCorp Vault, CA-PAM migration support, PIM, AKV, AWS, and related privileged access capabilities.
- Drive platform architecture, design, implementation, integration, and continuous improvement for privileged access services.
- Own engineering delivery for CyberArk platform uplift, HashiCorp adoption, secrets management expansion, CPM/PSM capability development, access modernization, and migration from legacy PAM platforms.
- Lead engineering design and implementation across CyberArk Vault, PVWA, CPM, PSM, PSMP, DR, connectors, integrations, monitoring, and platform automation.
- Drive HashiCorp Vault engineering for cloud workload identities, Azure service principals, AWS workloads, static secrets, database secrets, certificate/PKI use cases, and application credential modernization.
- Ensure PAM platforms are engineered for scalability, resilience, auditability, secure operations, least privilege, zero trust, credential vaulting, session monitoring, access control, and audit logging.
- Support privileged account onboarding across Windows, Unix/Linux, databases, network devices, cloud platforms, service accounts, application accounts, and non-human identities.
- Identify and deliver automation opportunities using APIs, scripting, CI/CD, Terraform, PowerShell, REST API, and workflow-based automation.
- Establish reusable engineering patterns, onboarding templates, reference architectures, and technical accelerators.
- Promote test automation, code review, technical debt reduction, platform refactoring, and continuous improvement.
- Partner with governance and audit teams to close control gaps, generate evidence, remediate findings, and improve control traceability.
- Drive remediation of platform vulnerabilities, configuration gaps, audit issues, and resiliency risks.
- Integrate PAM controls with IAM, SIEM, ServiceNow, SailPoint, monitoring, change management, and incident response processes.
- Translate business and regulatory requirements into scalable PAM engineering solutions.
- Provide senior technical leadership during major incidents, platform escalations, design reviews, audit discussions, and program governance forums.
- Lead, mentor, and develop a PAM engineering team and provide technical guidance across L2/L3/L4 responsibilities.
- Build engineering capability across CyberArk, HashiCorp Vault, cloud PAM, automation, secrets management, and non-human identity security.
- Create and maintain architecture diagrams, engineering standards, SOPs, runbooks, implementation patterns, knowledge articles, and support handover documents.
- Establish ownership models, RACI alignment, support handoffs, escalation paths, and post-implementation validation practices.
What you'll need
- 16+ years of technology experience, with significant experience in cybersecurity, IAM, PAM, infrastructure security, or platform engineering.
- Strong hands-on experience with one or more leading PAM platforms such as CyberArk, HashiCorp Vault, BeyondTrust, Delinea, or CA-PAM.
- Deep understanding of privileged account management, credential vaulting, session monitoring, password rotation, privileged access workflows, and least privilege principles.
- Experience leading large-scale PAM engineering or modernization initiatives in complex enterprise environments.
- Strong knowledge of CyberArk architecture and components including Vault, PVWA, CPM, PSM, PSMP, DR, connectors, policies, safes, platforms, and onboarding patterns.
- Experience with HashiCorp Vault architecture, secrets engines, authentication methods, policies, namespaces, replication, audit logging, and application integration patterns.
- Experience integrating PAM solutions with IAM, SIEM, ServiceNow, SailPoint, Active Directory, cloud platforms, and enterprise monitoring tools.
- Strong understanding of Windows, Linux/Unix, databases, network devices, cloud platforms, service accounts, and application credential management.
- Experience with platform upgrades, patching, DR validation, certificate management, vulnerability remediation, and operational readiness.
- Experience with Agile delivery, Jira, change management, incident management, problem management, and production support governance.
- Technical skills in CyberArk Vault, PVWA, CPM, PSM, PSMP, PTA, EPM, AIM/Conjur or Secrets Manager capabilities.
- Technical skills in HashiCorp Vault KV, database secrets, AppRole, LDAP/OIDC, Kubernetes auth, PKI, transit, dynamic secrets, replication, and audit logging.
- Technical skills in PowerShell, Python, Shell scripting, REST APIs, Terraform, Ansible, and CI/CD pipelines.
- Experience with Azure, AWS, and hybrid cloud identity and access patterns.
- Experience with ServiceNow, SailPoint, Active Directory, LDAP, SIEM, monitoring platforms, and application onboarding workflows.
- Experience with audit evidence, access reviews, control validation, policy compliance, and risk remediation.
- Proven ability to lead technical initiatives and drive results across teams without relying solely on direct authority.
- Strong people leadership, mentoring, stakeholder management, and executive communication skills.
- Ability to simplify complex technical topics for senior stakeholders, risk partners, and engineering teams.
- Strong ownership mindset focused on stability, security, resilience, and measurable delivery outcomes.
- Ability to operate effectively across global teams and time zones.
Nice to have
- CyberArk Defender, Sentry, or CDE certification.
- HashiCorp Vault Associate or Professional certification.
- Cloud certifications in Azure or AWS.
- Experience with non-human identity governance, secrets discovery, credential rotation automation, and elimination of hardcoded credentials.
- Experience with PAM modernization programs, CA-PAM to CyberArk/HashiCorp migration, cloud-native PAM, and ephemeral access models.
- Familiarity with regulatory, audit, and risk expectations in financial services.
- Experience leading transformation from operational support models into engineering-led platform ownership.
Details
- Location: Bangalore or Hyderabad.
- Work across time zones and global teams to support enterprise delivery.
Read the full description and apply on the company’s own careers page.