Freshworks logo

Freshworks

IAM-PAM Principal Engineer, Cybersecurity ( 10 to 15 years ) - HashiCorp Vault or CyberArk Conjur

full-timeOn-site
pam
hashicorp vault
cyberark conjur
iam
engineer
cybersecurity

Job Description

NielsenIQ is looking to mature our Identity and Access Management (IAM) Program. To support that effort, we are seeking a skilled and driven Senior level Cybersecurity Engineer with a solid understanding of Identity and Access Management (IAM), Privilege Access Management (PAM) concepts and solutions, a strong background in cross-platform integration. In this role, you will be responsible for developing and delivering comprehensive Identity and Access Management solutions. This role will have hands-on IAM-PAM architectural, engineering, and operational responsibilities as well as technical leadership and expert level implementation skills. The candidate will be self-motivated, detailed orientated performer who wants to be part of growing NIQ global IAM program.

Responsibilities

  • Lead the design and evolution of the IAM technology stack, ensuring adherence to top-tier security practices across architecture, implementation, monitoring, maintenance, and enhancements.
  • Apply advanced engineering principles to analyze, design, develop, deploy, and support complex software solutions and infrastructure upgrades, setting standards for best practices.
  • Work alongside product owner for CyberArk or equivalent PAM technologies, driving roadmap decisions and enterprise-scale adoption and enforcement.
  • Define and articulate design concepts for CyberArk components, vaults, safes, session managers, key managers, credential providers, external integrations, auditing/reporting, and access control mechanisms.
  • Develop robust automated solutions leveraging REST APIs, scripting (PowerShell/Python), GitHub, and infrastructure-as-code to streamline privileged onboarding, credential rotation, and secrets management workflows.
  • Enforce IAM and PAM controls across Azure, AWS, and GCP, integrating with native PIM capabilities and extending coverage to hybrid and multi-cloud environments.
  • Design and implement enterprise secrets management solutions like HashiCorp Vault or CyberArk Conjur for non-human identities with understanding of CI/CD pipelines, GitHub and cloud-native workloads.
  • Drive AI-driven integrations with PAM and have knowledge in leveraging ML models and AI agents for identity and access pattern recognition.
  • Identify security gaps in privileged access and secrets management processes, design scalable, automated solutions.
  • Develop and support KPIs and KRIs for IAM, PAM and Secrets Management initiatives
  • Communicate effectively with internal customers and cross-functional teams to clarify objectives, provide status updates, and influence adoption of PAM and Secrets Management best practices.
  • Drive initiatives that enhance end-user experience, maximize technology value, and strengthen the organization’s security posture through measurable improvements.

Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Information Systems, or a related field (Master’s preferred) with 10+ years of progressive technology experience, including 8+ years in designing and implementing Cybersecurity solutions at global scale.
  • Deep understanding of Identity & Access Governance with a strong focus on Privileged Access Management across on-prem, cloud (Azure, AWS, GCP), and IaaS/PaaS platforms.
  • Proven ability to design and implement complex IAM/PAM architectures, including integrations with SIEM/SOAR, ITSM, DevOps pipelines, and secrets management solutions.
  • Broad knowledge of IAM capabilities, identity stores, authentication/authorization, strong authentication, privileged access methodologies, and Zero Trust principles.
  • Hands-on experience with PowerShell, Python, and REST APIs for automation, understanding of versioning tools like GitHub and orchestration of PAM workflows and secrets management.
  • Experience implementing enterprise-grade secrets management solutions for managing non-human identities
  • Solid experience with Active Directory, Azure EntraID, AWS IAM, databases, operating systems (Windows/Linux), application systems, and network infrastructure.
  • Familiarity with AI-driven security approaches for human and non-human identities.
  • Ability to effectively prioritize and execute tasks in a fast-paced environment, balancing risk reduction with business objectives.
  • Exceptional verbal and written communication skills, capable of translating complex technical concepts into clear, actionable insights for diverse stakeholders.
  • Strong ability to work autonomously while influencing cross-functional teams and have proven track record of driving adoption of security best practices across large organizations.

Additional Information

  • Enjoy a flexible and rewarding work environment with peer-to-peer recognition platforms. 
  • Recharge and revitalize with help of wellness plans made for you and your family. 
  • Plan your future with financial wellness tools. 
  • Stay relevant and upskill yourself with career development opportunities

Our Benefits

  • Flexible working environment
  • Volunteer time off
  • LinkedIn Learning
  • Employee-Assistance-Program (EAP)