The Opportunity
We're seeking an experienced PAM Engineer (Windows Specialist) to join a security-focused team responsible for securing privileged access across a complex enterprise environment.
This role is ideal for someone with strong expertise in Privileged Access Management (PAM), Windows Server, Active Directory, and Identity & Access Management (IAM). You'll play a key role in designing, implementing, and optimising privileged access controls to reduce risk, improve compliance, and strengthen overall security posture.
Key Responsibilities
- PAM Engineering & Administration
- Design, implement, and maintain enterprise PAM solutions.
- Onboard privileged, administrative, and service accounts into PAM platforms.
- Configure password vaulting, credential rotation, session monitoring, and access workflows.
- Perform platform upgrades, patching, and ongoing maintenance.
- Develop and enforce PAM policies and security controls.
- Windows & Identity Security
- Integrate PAM solutions with Windows Server environments.
- Secure Domain Admin, Enterprise Admin, and Local Admin accounts.
- Implement Just-In-Time (JIT) and Just-Enough Administration (JEA) controls.
- Integrate PAM with Active Directory and Microsoft Entra ID.
- Support privileged account lifecycle management and governance.
- Security & Compliance
- Monitor privileged account activity and investigate security events.
- Support internal and external audits through reporting and evidence collection.
- Work with Security, Risk, and Compliance teams to address findings and remediation actions.
- Maintain documentation, standards, and operational procedures.
- Automation & Support
- Develop automation using PowerShell and other scripting tools.
- Improve onboarding, password management, and reporting processes.
- Provide Level 2/3 support for PAM-related incidents and service requests.
- Collaborate with Infrastructure, Security, Cloud, and Application teams on access management initiatives.
Essential Skills & Experience
- Strong experience implementing and supporting Privileged Access Management (PAM) solutions.
- Expertise in:
- Windows Server Administration
- Active Directory
- Microsoft Entra ID (Azure AD)
- Identity & Access Management (IAM)
- Experience securing privileged and administrative accounts.
- Knowledge of MFA, privileged session management, and access governance.
- Strong PowerShell scripting and automation skills.
- Experience supporting security audits and compliance requirements.
- Excellent troubleshooting, stakeholder management, and documentation skills.
Desirable Skills
- Experience with enterprise PAM platforms such as CyberArk, BeyondTrust, Delinea, or similar.
- Knowledge of Zero Trust and Privileged Access strategies.
- Experience working in highly regulated or security-sensitive environments.
What We're Looking For
You'll be a technically strong security professional with a passion for identity security and privileged access management.
Comfortable working across infrastructure and security teams, you'll combine hands-on engineering expertise with a proactive approach to improving security controls and reducing organisational risk.
If you're an SC-cleared PAM Engineer with strong Windows, Active Directory, and IAM experience, we'd love to hear from you.