PAM Engineering Lead

WTWBloomington, MN
$130,000 - $170,000

About The Position

Willis Towers Watson IT is currently seeking a senior, experienced candidate for the position of PAM Engineering Lead. In this position, the successful candidate must demonstrate significant hands-on experience engineering CyberArk PAM solutions, together with the seniority to set technical direction, own and prioritise a product backlog, and mentor engineers within the team. The main focus of this position is to lead the build, operation and continuous improvement of our CyberArk (Idira) platform while acting as product owner for the privileged access platform roadmap, influencing senior stakeholders and ensuring successful delivery of service, stakeholder alignment and continuous development of the IAM Team.

Requirements

  • 5+ years in IAM/PAM SaaS engineering, including 3+ years hands-on with CyberArk (Idira) Privileged Access Manager (Vault, CPM, PSM, PVWA), with demonstrated experience leading PAM engineering teams.
  • Strong understanding of PAM concepts: privileged account lifecycle, credential/SSH key rotation, session isolation and monitoring, least-privilege and just-in-time access.
  • Experience integrating CyberArk with Active Directory/Entra ID, Windows, Unix/Linux, databases, network devices and SaaS applications.
  • Scripting proficiency with the CyberArk REST API, PACLI, PowerShell and Python for automation and integration.
  • Working knowledge of identity and secrets management standards: SAML, OAuth2/OIDC and secrets management (Conjur/AAM or equivalent).
  • Experience with access governance frameworks and compliance mapping (ISO 27001, SOC 2, GDPR or similar).
  • Demonstrated experience writing user stories, managing a backlog, or working closely with product/agile teams.
  • Strong stakeholder communication skills, able to translate technical detail for both engineers and business stakeholders.
  • Good project management skills.
  • Positive team-first attitude with strong verbal and written communication skills.
  • Must possess sound analytical and problem-solving capabilities.

Nice To Haves

  • CyberArk certification (CyberArk Defender/Sentry - PAM).
  • Experience with BeyondTrust, Delinea (Thycotic) or HashiCorp Vault as a comparison point.
  • Familiarity with Agile/Scrum ceremonies and tools (Jira, Azure DevOps).
  • Exposure to Zero Trust principles and NIST SP 800-53 AC/IA control families.

Responsibilities

  • Lead the design, build and maintenance of CyberArk (Idira) Privileged Access Manager solutions, including Vault architecture, Safes, target platforms and session management across WTW.
  • Own and prioritise the PAM platform backlog, setting technical direction and acting as product owner for the privileged access roadmap based on business risk, compliance deadlines and stakeholder demand.
  • Oversee the build and maintenance of privileged account onboarding and credential/SSH key rotation automation via the Central Policy Manager (CPM), integrating with Active Directory/Entra ID, Windows, Unix/Linux, databases and network devices.
  • Define and govern privileged access policies, least-privilege and just-in-time access models and privileged session review campaigns across WTW.
  • Act as the senior technical authority within IAM, covering all aspects of Privileged Access Management.
  • Drive solution development through problem solving, ensuring adherence to Security Controls, Policies and Standards with a focus on automation and control.
  • Influence senior stakeholders across IT, Compliance and the business to align the privileged access roadmap with WTW's risk and regulatory priorities.
  • Lead the development of skills and capabilities within the IAM team, mentoring engineers and driving process improvements and documentation.
  • Oversee configuration and troubleshooting of CyberArk connectors and platforms (PSM, CPM, PVWA) to Windows, Unix/Linux, database and network device targets, working hands-on where required.
  • Author and review custom platforms, connection components and automation scripts (CyberArk REST API, PACLI, PowerShell and Python), setting standards for the wider team.
  • Govern the operational execution of privileged session recording and review, Safe membership reviews, and privileged account discovery initiatives.
  • Oversee platform health, ensuring credential rotation and session recording failures are resolved and audit trail integrity is maintained.
  • Lead sprint planning, backlog grooming and roadmap reviews.
  • Own roadmap and status communications for leadership and stakeholders.
  • Oversee the privileged account lifecycle, including onboarding, offboarding and account updates.
  • Ensure compliance with internal policies and external regulations, escalating risks as needed.
  • Own the response to audit findings and drive remediation measures to closure.
  • Oversee resolution of escalated issues and support tickets, providing senior technical input where needed.

Benefits

  • Mental health/emotional wellbeing (including Employee Assistance Program)
  • medical (including prescription drug coverage and fertility benefits)
  • dental
  • vision
  • Health Savings Account
  • Commuter Accounts
  • Health Care and Dependent Care Flexible Spending Accounts
  • company-paid life insurance
  • supplemental life insurance
  • AD&D
  • group accident
  • group critical illness
  • group legal
  • identify theft protection
  • wellbeing program
  • adoption assistance
  • surrogacy assistance
  • auto/home insurance
  • pet insurance and other work/life resources
  • Paid holidays
  • annual paid time off (includes state/local paid leave where required)
  • company-paid disability (short-term and long-term disability)
  • other leaves (e.g., bereavement, FMLA, ADA, jury duty, military leave, and Parental and Adoption Leave)
  • Paid Time Off
  • Qualified contributory pension plan (if eligible)
  • 401(k) plan with annual nonelective company contribution
  • Non-qualified retirement plans available to senior level colleagues who satisfy the plans’ eligibility requirements.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service