A global financial-services organization is seeking an Executive-level Privileged Access Management leader to oversee its enterprise PAM function.
This individual will define the strategic direction of privileged-access services while leading the engineering, operations, governance, and controls supporting critical infrastructure, applications, databases, network technologies, and cloud environments.
The successful candidate will mature privileged-access models, expand automation, strengthen lifecycle and session controls, remediate audit and regulatory issues, and ensure the PAM program consistently meets enterprise security and operational requirements.
RESPONSIBILITIES- Define and execute a multiyear enterprise PAM roadmap
- Lead PAM engineering and operations
- Establish clear service ownership and delivery accountability
- Standardize privileged-access models across operating systems, databases, networks, cloud platforms, and applications
- Lead enterprise adoption of CyberArk-based privileged-access services
- Scale privileged-account and custom-application onboarding
- Improve privileged-account discovery and validation
- Strengthen credential vaulting, password rotation, session monitoring, and session verification
- Implement and mature Just-In-Time privileged access
- Design controlled, auditable break-glass and emergency-access processes
- Automate privileged-access reviews and quarterly certifications
- Ensure PAM controls and supporting evidence remain audit-ready
- Lead remediation of Internal Audit and regulatory findings
- Integrate PAM with identity-governance and security-monitoring platforms
- Establish KRIs and KPIs that measure control effectiveness and risk reduction
- Partner with Infrastructure, Applications, Cybersecurity, Architecture, GRC, and Internal Audit
- Embed PAM requirements into new and existing technology environments
- Communicate PAM strategy, risk, remediation progress, and performance to executives and control stakeholders
Role Requirements:- At least 10 years of IAM, cybersecurity, or information-security experience
- At least five years of substantial Privileged Access Management experience
- Deep enterprise CyberArk expertise
- Demonstrated leadership of PAM engineering, operations, or enterprise programs
- Experience owning enterprise PAM strategy and operational execution
- Experience remediating regulatory or Internal Audit findings involving privileged access
- Strong understanding of PAM across Windows, Unix/Linux, Active Directory, databases, networks, applications, and cloud environments
- Experience implementing Just-In-Time access and privileged-session controls
- Experience designing emergency and break-glass access
- Enterprise-scale privileged-account and application onboarding
- Knowledge of SailPoint, Splunk, or comparable identity-governance and security-monitoring platforms
- Experience building sustainable governance, certification, and evidence processes
- Strong executive communication and stakeholder-management skills
- Ability to balance security controls with practical operational requirements
- Ability to meet the required Iselin hybrid schedule
PREFERRED EXPERIENCE- Banking, capital-markets, insurance, or comparable regulated-industry experience
- CISSP, CISM, or another relevant cybersecurity certification
- AWS and Azure privileged-access experience
- NIST CSF 2.0 or comparable cybersecurity-framework experience
- Experience developing PAM KRIs and KPIs
- CyberArk integration with SailPoint and Splunk
- Strategic technology-vendor management
- PAM workflow, monitoring, and certification automation