
Manager, Privileged Access Management Architect and Lead Engineer
at KPMG
Posted 6 days ago
No clicks
- Compensation
- $108,100 – $230,900 USD
- City
- Los Angeles
- Country
- United States
Currency: $ (USD)
Lead the architecture and delivery of Privileged Access Management (PAM) solutions to support enterprise IAM programs. Serve as the technical lead for PAM deployments (CyberArk On-Prem and SaaS), including privileged account management, session management, just-in-time access, and endpoint management. Collaborate with IT Security, Cloud, and IAM teams to design PAM processes across hybrid/multi-cloud environments, orchestrating automation using Terraform, Ansible, PowerShell, Python, and REST APIs. Guide customer delivery, provide technical mentorship to engineering teams, and ensure alignment with regulatory frameworks and industry best practices.
The KPMG Advisory practice is at the forefront of transformation, offering excellent opportunities for individuals to advance their careers and expertise with KPMG. Looking ahead, we anticipate continued evolution and success within the practice, fostering both personal and professional development, thereby creating new pathways for growth. In this ever-changing market environment, our professionals must be adaptable and thrive in a collaborative, team-driven culture. At KPMG, our people are our number one priority. With a wealth of learning and career development opportunities, a world-class training facility, and leading market tools, we help our people continue to grow both professionally and personally. If you're looking for a firm with a strong team connection where you can be your whole self, have an impact, advance your skills, deepen your experiences, and have the flexibility and access to constantly find new areas of inspiration and expand your capabilities, then consider a career in Advisory.
KPMG is currently seeking a Manager, Privileged Access Management Architect and Lead Engineer to join our Advisory Services practice.
- Architect, design, and lead the implementation of Privileged Access Management (PAM) solutions to support enterprise-wide Identity & Access Management (IAM) programs
- Serve as the technical lead engineer for PAM solution deployments (such as, CyberArk On-Prem and SaaS solutions), including implementation of privileged account management, session management, just-in-time access, and endpoint management capabilities
- Partner with IT and Security Architecture teams to help design PAM solutions and processes in alignment with project requirements and industry leading practices; partner with cloud engineering teams to integrate PAM capabilities across hybrid and multi cloud environments
- Oversee end to end PAM lifecycle activities including discovery, testing, onboarding, access workflows, break glass processes, policy design, and integration with enterprise controls/platforms (such as, IdP, SIEM, ITSM, and IGA platforms)
- Design automation strategies to accelerate deployment tasks including onboarding, policy deployment, and reporting using industry standard tooling/methods (that is, Terraform, Ansible, PowerShell, Python, REST APIs, and more); design and implement automated integration across adjacent security solutions (for example: Crowdstrike, SIEM solutions, ServiceNow); conduct privileged access risk assessments and develop remediation strategies aligned to regulatory and security frameworks and requirements (such as, NIST CSF/800-53, ISO 27001, SOX, PCI DSS, and others)
- Lead customer-facing delivery, including scope estimation, risk/issue/dependency management, technical workshop facilitation, and technical workstream oversight; provide technical leadership, mentorship, and guidance to engineering teams while collaborating with cross functional stakeholders
- Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment
- Minimum five years of recent professional experience in IT security, IAM, or Privileged Access Management roles
- Bachelor's degree from an accredited college or university is required; CyberArk Certified Delivery Engineer (CDE) or CyberArk Endpoint Privilege Manager (EPM) Certification preferred
- Strong expertise in Privileged Access Management technologies with hands-on experience architecting and engineering CyberArk solutions; additional experience with secrets management platforms (such as, Conjur, HashiCorp) and other PAM platforms (such as Delinea, BeyondTrust) preferred
- Experience integrating PAM solutions with cloud platforms (for example: Azure, AWS, GCP); knowledge and expertise in systems and/or infrastructure administration (that is Windows, Linux, Databases, Cloud) and networking principles; proficiency designing and implementing scripting and automation to accelerate tasks and solution deployments
- Demonstrated understanding of IAM concepts, security controls, and regulatory expectations related to privileged access
- Strong analytical, communication, and problem-solving skills with the ability to lead technical discussions and drive complex engineering initiatives
- Ability to travel as required
- Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future; KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa)
https://kpmg.com/us/en/how-we-work/pay-transparency.html/?id=M105_3_25
California Salary Range: $108100 - $230900

