The Identity & Access Management (IAM) Privileged Access Management (PAM) Lead is responsible for the strategy, governance, engineering, operational oversight, and continuous enhancement of Northern Trust's privileged access management capabilities. This role partners with Cyber Security Engineering, Infrastructure Services, Application Development, Risk Management, Audit, Compliance, and Business Technology teams to reduce cyber risk associated with privileged accounts, administrative access, elevated entitlements, and non-human identities.
The successful candidate will lead the adoption, optimization, and governance of CyberArk PAM capabilities while supporting the broader IAM strategy across workforce, privileged, and machine identities. The role is accountable for ensuring privileged access controls align with regulatory expectations, internal security standards, least privilege principles, and industry frameworks including NIST, FFIEC, and financial services best practices. CyberArk serves as Northern Trust's approved PAM solution for privileged credential management, session monitoring, governance, and audit reporting.
CyberArk Platform Ownership
- Serve as a subject matter expert for the CyberArk platform, including:
- Privileged Access Manager (PAM)
- Privileged Session Manager (PSM)
- Central Policy Manager (CPM)
- Application Access Manager (AAM/Secrets Management)
- Endpoint Privilege Management (EPM)
- Privileged Threat Analytics (PTA)
- Drive platform upgrades, integrations, onboarding, and operational maturity activities.
- Develop and maintain standards for privileged account lifecycle management through CyberArk controls.
- Partner with engineering teams to integrate CyberArk with critical infrastructure, cloud platforms, applications, databases, and automation tooling.
Risk & Control Management
- Ensure privileged access controls satisfy Northern Trust security policies, audit requirements, and regulatory obligations.
- Lead control design and continuous monitoring efforts for privileged identities across workforce and non-human populations.
- Evaluate privileged access risks, control gaps, policy exceptions, and remediation plans.
- Support RCSA, audit evidence collection, and regulatory examination activities impacting privileged access management.
- Implement detective controls and monitoring capabilities for privileged account activities and administrative sessions.
Engineering & Automation
- Develop automation and integration capabilities supporting privileged account provisioning, credential rotation, access review, and secrets management.
- Drive API-based integrations between CyberArk, IGA platforms, ticketing systems, cloud environments, and enterprise applications.
- Support modernization initiatives involving machine identity management, cloud privilege management, and privileged authorization models.
- Partner with IAM engineering teams to enhance scalability, reliability, and operational efficiency across PAM services.
Stakeholder Management & Leadership
- Provide leadership and strategic direction for PAM engineering and operations teams.
- Collaborate with infrastructure, cloud, application, and security architects to define privileged access requirements.
- Present PAM strategy, risk posture, metrics, and roadmap updates to senior leadership, governance forums, and regulators.
- Influence enterprise technology decisions involving administrative access, privileged credentials, and identity security architectures.
Preferred Qualifications- 7+ years of experience in IAM, Cyber Security, or PAM-related disciplines.
- Deep experience administering or engineering CyberArk PAM solutions.
- Strong understanding of privileged account governance, credential vaulting, session management, secrets management, and least privilege principles.
- Experience with enterprise IAM capabilities including:
- Saviynt
- Active Directory / Entra ID
- Authentication and MFA platforms
- Identity Governance & Administration
- Non-Human Identity Management
- Familiarity with NIST 800-53, NIST CSF 2.0, FFIEC guidance, COBIT, and financial services regulatory expectations.
- Experience supporting audit, risk, compliance, and regulatory examinations within a highly regulated environment.
Work Authorization
Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. Northern Trust will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa).
About Our Tempe Office
The Northern Trust Tempe office opened in 2015 with 75 employees and now serves over 75 different business functions with more than 700 employees. The team is recognized as a Global Capability Center that delivers exceptional value, quality, expertise and innovation through our diverse talent.