- Location
- Bucharest, B, RO
- Type
- Full-time
- Department
- IT
- Seniority
- Senior
- Closing date
- Today
- Source
- iCIMS
Description
Overview
Expleo is a global engineering, technology, and consulting service provider that partners with leading organizations to guide them through their business transformation, helping them achieve operational excellence and future-proof their businesses. Expleo benefits from more than 50 years of experience developing complex products in automotive and aerospace, optimizing manufacturing processes, and ensuring the quality of information systems. Leveraging its deep sector knowledge and wide-ranging expertise in fields including AI engineering, digitalization, automation, cybersecurity and data science, the group’s mission is to fast-track innovation through each step of the value chain. With a worldwide presence in 30 countries, our global footprint includes excellence centers around the world, including Romania since 1994.Responsibilities
The Privileged Access Management (PAM) function is responsible for innovating, sustaining and continuously improving a centralized PAM solution used across a large international organization. The team supports the onboarding of applications and systems into the platform, enhances and automates PAM workflows, and provides advanced troubleshooting, patch management and end-to-end infrastructure management.
The role is part of an international team working collaboratively to meet delivery objectives, drive continuous improvement and identify and close security gaps arising from audits and risk assessments. The team focuses on maintaining strong operational performance and customer satisfaction while continuously improving quality, automation and cost efficiency.
The team follows an Agile/DevOps delivery model, favoring pragmatic reuse of existing platform policies, components and plugins where appropriate instead of designing every solution from scratch. The environment combines Privileged Access Management, infrastructure operations, security engineering, automation and platform reliability.
Responsibilities:
- Participate actively in Agile/Scrum delivery ceremonies, including daily stand-ups, retrospectives, backlog refinement, sprint reviews and sprint planning, and contribute to the delivery of agreed sprint goals.
- Deliver new features, enhancements and automation for the centralized PAM platform.
- Onboard applications and systems into the PAM platform and support efficient management of privileged access.
- Perform advanced troubleshooting and deliver technical solutions that improve the day-to-day operation and usability of the PAM platform.
- Support patch management and end-to-end infrastructure management for the PAM environment.
- Support and improve the architecture of the PAM platform by proposing and contributing to new designs and technical improvements.
- Identify and help close security gaps related to audits, risks and compliance requirements.
- Produce and maintain PAM technical and operational documentation.
- Support and advise internal customers regarding non-personal privileged accounts and PAM-related requirements.
- Work closely with colleagues across the DevOps team, including architects and team leads, to ensure timely and high-quality delivery of objectives.
- Proactively share knowledge and support colleagues through technical collaboration, knowledge-sharing sessions and relevant technical forums.
- Participate in on-call / standby duties for the PAM platform when required.
Qualifications
- At least 4-5 years of experience in Privileged Access Management (PAM).
- Hands-on experience with one or more PAM platforms such as CyberArk, Delinea Secret Server, BeyondTrust or comparable solutions.
- Familiarity with Agile/Scrum delivery practices and DevOps principles and ways of working.
- Knowledge of enterprise user stores and directory services such as LDAP and Active Directory.
- Understanding of core networking concepts, protocols and services, including IP, DHCP, DNS, BGP and load balancing.
- Experience working with Windows and Linux environments, including Red Hat Linux.
- Experience with monitoring and alerting tools or platforms such as Prometheus, Grafana, Datadog, PagerDuty or New Relic.
- Experience with collaboration and service-management tooling such as JIRA, Confluence and Service Line (as used in the current environment).
- Familiarity with web services and integration technologies such as SOAP and REST.
- Familiarity with security and compliance frameworks such as PCI DSS, ISO 27001, KFS and ISAE.
- Familiarity with scripting and automation, particularly PowerShell. Exposure to Toad or similar supporting tools is an advantage where relevant to the environment.
- Experience working with Terraform for infrastructure-as-code and automated infrastructure management.
- Experience working with Puppet for configuration management and automation.
- Strong analytical and advanced troubleshooting skills.
- Ability to work independently while collaborating effectively with global functional and technical teams in a dynamic environment.
- Proactive mindset, ownership of assigned responsibilities, willingness to learn and ability to contribute to continuous improvement.
- Excellent English communication skills, both written and verbal, with the ability to communicate clearly with a wide range of technical and non-technical
Desired skills
- Hands-on experience with CyberArk components such as Vault, PVWA, CPM, PSM and Disaster Recovery (DR).
- Experience creating or maintaining custom CyberArk plugins.
- Cloud-provider certifications or practical experience with AWS and/or GCP technologies.
- Understanding of compliance and security best practices in cloud environments
What do I need before I apply
- Hybrid, a few days per month at the office.
- CIM only
Benefits
- Benefit Platform
- Holiday Voucher
- Private medical insurance
- Performance bonus
- Easter and Christmas bonus
- Employee referral bonus
- Bookster subscription
- Work from home options depending on project.