Join our team as an IAM/PAM PKI Engineer, where you will enhance enterprise identity security solutions with a focus on Cerebra mPass (MFA) and CyberArk (PAM). Your role will involve stabilizing daily operations, facilitating onboarding processes, enhancing policy frameworks, and preparing the strategic roadmap for the migration to Windows Hello for Business along with the future implementation of SailPoint (IGA), BeyondTrust (PAM), and Thales HSM for PKI. A strong aptitude for troubleshooting, meticulous documentation, and maintaining audit evidence is essential for success in this position.Key ResponsibilitiesMFA Management using Cerebra mPassDesign, configure, and support MFA policies, integrations, and user onboarding processes for Cerebra mPass.Integrate MFA with enterprise applications such as VPN, remote access, cloud services, and internal systems using established authentication protocols.Monitor authentication workflows, troubleshoot access issues, and enhance the reliability and user experience.Develop and execute a comprehensive migration plan from mPass to Windows Hello for Business, including pilot planning, risk management, and transition support.PAM Management with CyberArk and BeyondTrustManage and scale CyberArk environments, including safes, platforms, health checks, onboarding, rotations, and access workflows.Facilitate privileged account onboarding and uphold operational hygiene through break glass, vault policies, RBAC, and session controls.Support the evaluation and future implementation of BeyondTrust as required.IGA Preparation with SailPointAssist in preparations for IGA adoption, including joiner/mover/leaver processes, segregation of duties concepts, connector requirements, and reporting needs.Contribute to implementation planning and operational documentation once adopted.PKI Coordination with Thales HSMOversee certificate lifecycle processes and coordinate with Active Directory and PKI stakeholders.Support discovery, inventory, renewal tracking, and operational processes related to certificates.Engage in planning for HSM-backed PKI with Thales, including key ceremony concepts, dual control, and operational readiness for CRL/OCSP.Operational Compliance and Delivery HygieneEnsure visibility of IAM, MFA, and PAM events within the SIEM. Maintain health KPIs and minimize alert noise.Execute changes through ITSM, ensuring thorough testing, validation, and post-change inspections.Lead or assist in root cause analysis for significant incidents. Document standard operating procedures, runbooks, and hardening guidelines.Generate audit-ready evidence aligned with cybersecurity regulations in KSA, focusing on access controls and privileged access governance.Automation InitiativesUtilize PowerShell, Python, and REST APIs to automate onboarding, rotation processes, and administrative tasks.
Jan 14, 2026