Job title: Privileged Access Management (PAM) Architect
Duration: 9 months
Clearance required: DV or DV Eligible
Rate: To be discussed
Location: Hybrid, onsite in Corsham twice a week
Specification: Below
Overview:
- We are seeking an experienced Privileged Access Management (PAM) Architect and Subject Matter Expert (SME) to lead the design, implementation, and optimisation of enterprise PAM solutions, with a strong focus on CyberArk. This role requires deep technical expertise, strategic oversight, and hands-on delivery capability within secure, high-assurance environments.
- The successful candidate will play a key role in securing critical systems and sensitive data, supporting a UK secure account, and engaging directly with stakeholders across customer sites.
Key Responsibilities:
- Lead the architecture, design, and implementation of CyberArk-based PAM solutions across on-premise complex enterprise environments
- Act as the technical SME for PAM, providing expert guidance on best practices, standards, and emerging capabilities
- Deliver end-to-end CyberArk deployments, including Privileged Access Security (PAS), Privilege Cloud, and associated components
- Define and implement privileged access policies, credential management, session monitoring, and vaulting strategies
- Work closely with security, infrastructure, and application teams to integrate PAM controls into existing environments
- Conduct security assessments and gap analyses, providing remediation recommendations aligned to industry standards (eg, NIST, ISO 27001)
- Support audit and compliance requirements, ensuring adherence to security policies and regulatory obligations
- Provide technical leadership and mentoring to internal teams and stakeholders
- Engage directly with internal and external stakeholder with visiting customers on-site, building trusted relationships and ensuring successful delivery outcomes
- Contribute to continuous improvement initiatives and innovation within the PAM domain
Required Skills & Experience:
- Proven experience in a PAM Architect or Senior SME role
- Strong hands-on expertise with CyberArk (PAS, CPM, PSM, PVWA, PTA, desirable)
- Experience designing and delivering enterprise-scale PAM solutions
Demonstrable experience producing high-quality design documentation, including:
- High-Level Designs (HLDs)
- Low-Level Designs (LLDs)
- Security architecture documents
- Implementation and operational runbooks
- Deep understanding of identity and access management (IAM) principles and security best practices
- Strong knowledge of privileged credential life cycle management, session isolation/recording, and least privilege models
Experience integrating CyberArk with:
- Active Directory/LDAP
- SIEM tools
- ITSM tools
- Familiarity with DevSecOps and secrets management is advantageous
- Excellent stakeholder management and communication skills
Industry Experience:
- Prior experience working in the Defence and/or Aerospace sector is highly desirable
- Understanding of high-assurance, regulated environments and secure system delivery
Desirable Certifications
- CyberArk Certified Delivery Engineer (CDE)/Defender (CDP)/Sentry
- CISSP, CISM, or equivalent security certifications
- TOGAF or other architecture frameworks (desirable)
If you are available and interested in this opportunity, please apply for further information. Please note that due to high volumes of applications we are unable to contact every applicant. If you do not hear back from us within 7 days of sending your application, please assume that you have not been successful on this occasion.
At Lucid, we celebrate difference and value diverse perspectives, underpinned by our values 'Honesty, Integrity and Pragmatism'. We are proud to provide equal opportunities in line with our Diversity and Inclusion policy and welcome applications from all suitably qualified or experienced people, regardless of personal characteristics. If you have a disability or health condition and seek support throughout the recruitment process, please do not hesitate to contact us via the details below.