Senior Specialist - PAM Operations & Governance - Job Description
CPX · Abu Dhabi, Abu Dhabi Emirate, United Arab Emirates
Apply & track with Apply EdgeJob Purpose :-Operate and govern Privileged Access Management services, with Delinea Secret Server as the primary platform, for R100 and other assigned CPX or client environments. The role provides hands-on PAM administration, privileged identity lifecycle governance, access reviews, policy enforcement, monitoring, audit evidence, incident support, and continuous control improvement. The position also supports vulnerability remediation governance, security risk tracking, operational reporting, and broader Information Security Operations activities, ensuring that privileged access and security findings are controlled, accountable, measurable, and driven to closure.Key Focus Areas : -Administer and support Delinea Secret Server, including secrets, folders, templates, policies, launchers, lists, discovery sources, remote password changing, heartbeats, proxy access, session recording, reporting, and platform configuration within approved change controls.Monitor platform health, web nodes, database connectivity, directory integrations, password rotation, discovery, recording, backup jobs, alerts, capacity, availability, and scheduled tasks; troubleshoot failures and coordinate restoration with infrastructure, database, network, cloud, and vendor teams.Maintain secure integration with Active Directory, FreeIPA or LDAP, load balancers, databases, target systems, ticketing platforms, SIEM, storage, and approved administrative access paths.Plan and support upgrades, patches, license or subscription activities, resilience testing, backup validation, recovery exercises, and controlled platform changes.Own privileged account, service account, administrative account, emergency account, vendor account, and non-human identity onboarding, modification, suspension, recertification, and offboarding workflows.Validate business justification, ownership, approvals, target scope, access duration, role assignment, folder permissions, secret sharing, checkout rules, and session-control requirements before provisioning.Enforce least privilege, role-based access, segregation of duties, time-bound access, credential rotation, controlled break-glass access, and removal of dormant, orphaned, duplicate, excessive, or unauthorized privileges.Maintain authoritative inventories of privileged identities, managed systems, secret owners, custodians, exceptions, integrations, dependencies, and lifecycle status.Plan and execute periodic privileged access and entitlement reviews with application, infrastructure, cloud, database, network, security, and business owners; track responses, evidence, revocations, overdue actions, and management escalations.Review privileged sessions, access events, failed checkouts, policy violations, unusual activity, stale secrets, missed rotations, disabled controls, bypasses, and exceptions; initiate investigation and corrective action where required.Produce audit-ready evidence for access certifications, privileged account governance, password rotation, approvals, session monitoring, control operation, issue closure, exceptions, and management oversight.Support internal and external audits, client reviews, compliance assessments, risk assessments, and control testing aligned to applicable contractual, regulatory, and CPX IMS requirements.Respond to PAM service incidents and security events, including failed privileged access, password rotation failures, vault or node issues, suspicious sessions, credential exposure, unauthorized access, and control bypass attempts.Provide 8x5 operational support and controlled best-effort on-call support for critical PAM-related incidents outside business hours, when assigned under the service model.Perform triage, evidence preservation, containment support, root-cause analysis, recovery coordination, problem management, and post-incident corrective action tracking.Assess PAM deviations and exceptions, document risk and compensating controls, obtain approvals, define expiry dates, and ensure timely review, renewal, or closure.Review and validate vulnerability findings from vulnerability scans, penetration tests, red and purple team exercises, configuration reviews, cloud posture assessments, audits, and operational security reviews.Normalize findings, confirm affected assets and ownership, validate severity and risk context, map remediation SLAs, and ensure accurate recording in the authorized ticketing and vulnerability-management workflow.Track remediation across infrastructure, application, cloud, endpoint, database, network, and security teams; monitor aging, overdue items, exceptions, dependencies, and recurring or systemic exposures.Validate closure through rescanning, retesting, configuration evidence, or approved risk disposition; escalate critical, high-risk, or overdue vulnerabilities through governance forums.Skills / Certifications (Technical & Non-technical) : -Hands-on experience with vulnerability-management and remediation workflows, including triage, severity validation, SLA tracking, aging analysis, exception management, closure validation, dashboards, and governance reporting. Experience with Rapid7, Tenable, Qualys, Microsoft Defender Vulnerability Management, or comparable tools is desirable.Experience in Information Security Operations, incident and problem management, risk registers, audit evidence, control testing, ticketing or ITSM platforms, operational metrics, and stakeholder governance.Ability to interpret security architecture and low-level designs, troubleshoot integrations, assess operational risk, write clear procedures and reports, and communicate effectively with technical and management stakeholders.Strong analytical, ownership, prioritization, documentation, collaboration, and client-facing communication skills.Preferred certifications: Delinea Secret Server certification or formal training; CISSP, CISM, CRISC, Security+, CyberArk Defender or Sentry, Microsoft security certifications, ITIL, or equivalent relevant credentials.Minimum Work Experience: -Demonstrated experience supporting vulnerability remediation governance and cross-functional security operations in an enterprise or managed-service environment.Experience working in client-facing or multi-stakeholder environments with formal SLAs, operational reporting, audit requirements, and controlled change processes is preferred.Education : -Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, Engineering, or a related discipline. Relevant postgraduate qualification is advantageous.