IT Security C&T logoIT Security C&T logo

IAM/PAM PKI Engineer - Saudi National

On-site Full-time

Clicking Apply Now takes you to AutoApply where you can tailor your resume and apply.


Experience Level

Mid to Senior

Qualifications

Required QualificationsSaudi national with a Bachelor's degree or equivalent experience. Typically more than 5 years of experience in IAM, with hands-on involvement in MFA and PAM operations at an enterprise level. Extensive experience with Cerebra mPass (or similar MFA platforms) and CyberArk. Strong understanding of identity and authentication concepts, including SAML, OAuth 2.0, OpenID Connect, Active Directory, and LDAP. Excellent troubleshooting, stakeholder communication, and documentation skills. Practical scripting skills in PowerShell or Python, familiar with REST APIs. Preferred QualificationsExperience in enterprise MFA rollout and user adoption strategies. Familiarity with Windows Hello for Business, SailPoint, or BeyondTrust. Experience in regulated environments.

About the job

Join our team as an IAM/PAM PKI Engineer, where you will enhance enterprise identity security solutions with a focus on Cerebra mPass (MFA) and CyberArk (PAM). Your role will involve stabilizing daily operations, facilitating onboarding processes, enhancing policy frameworks, and preparing the strategic roadmap for the migration to Windows Hello for Business along with the future implementation of SailPoint (IGA), BeyondTrust (PAM), and Thales HSM for PKI. A strong aptitude for troubleshooting, meticulous documentation, and maintaining audit evidence is essential for success in this position.

Key Responsibilities

MFA Management using Cerebra mPass

  • Design, configure, and support MFA policies, integrations, and user onboarding processes for Cerebra mPass.
  • Integrate MFA with enterprise applications such as VPN, remote access, cloud services, and internal systems using established authentication protocols.
  • Monitor authentication workflows, troubleshoot access issues, and enhance the reliability and user experience.
  • Develop and execute a comprehensive migration plan from mPass to Windows Hello for Business, including pilot planning, risk management, and transition support.

PAM Management with CyberArk and BeyondTrust

  • Manage and scale CyberArk environments, including safes, platforms, health checks, onboarding, rotations, and access workflows.
  • Facilitate privileged account onboarding and uphold operational hygiene through break glass, vault policies, RBAC, and session controls.
  • Support the evaluation and future implementation of BeyondTrust as required.

IGA Preparation with SailPoint

  • Assist in preparations for IGA adoption, including joiner/mover/leaver processes, segregation of duties concepts, connector requirements, and reporting needs.
  • Contribute to implementation planning and operational documentation once adopted.

PKI Coordination with Thales HSM

  • Oversee certificate lifecycle processes and coordinate with Active Directory and PKI stakeholders.
  • Support discovery, inventory, renewal tracking, and operational processes related to certificates.
  • Engage in planning for HSM-backed PKI with Thales, including key ceremony concepts, dual control, and operational readiness for CRL/OCSP.

Operational Compliance and Delivery Hygiene

  • Ensure visibility of IAM, MFA, and PAM events within the SIEM. Maintain health KPIs and minimize alert noise.
  • Execute changes through ITSM, ensuring thorough testing, validation, and post-change inspections.
  • Lead or assist in root cause analysis for significant incidents. Document standard operating procedures, runbooks, and hardening guidelines.
  • Generate audit-ready evidence aligned with cybersecurity regulations in KSA, focusing on access controls and privileged access governance.

Automation Initiatives

  • Utilize PowerShell, Python, and REST APIs to automate onboarding, rotation processes, and administrative tasks.

About IT Security C&T

IT Security C&T is a dynamic and rapidly growing security consulting and training firm. Our expert management team collaborates with skilled consultants and engineers to deliver comprehensive security solutions across the MENA region. We are continuously expanding our team of qualified professionals and welcome talented individuals to explore a variety of career opportunities. Interested candidates are encouraged to apply through our career webpage at www.itsecurityct.com.

Similar jobs

Browse all companies, explore by city & role, or SEO search pages. View directory listings: all jobs, search results, location & role pages.

Tailoring 0 resumes

We'll move completed jobs to Ready to Apply automatically.