Senior PAM Engineer – Delinea Cloud
Job Summary
Your work days are brighter here.
Were obsessed with making hard work pay off for our people our customers and the world around us. As a Fortune 500 company and a leading AI platform for managing people money and agents were shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join youll feel it. Not just in the products we build but in how we show up for each other. Our culture is rooted in integrity empathy and shared enthusiasm. Were in this together tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether youre building smarter solutions supporting customers or creating a space where everyone belongs youll do meaningful work with Workmates whove got your return well give you the trust to take risks the tools to grow the skills to develop and the support of a company invested in you for the long haul. So if you want to inspire a brighter work day for everyone including yourself youve found a match in Workday and we hope to be a match for you too.
About the Team
Identity and Access Management team manage Identity suite including Okta Delinea KeyFactor Active Directory and Entra ID environment. We manage workmate customer and partner identities.About the Role
We are looking for a Senior Delinea Cloud PAM Specialist to architect deploy and operationalize our cloud-native Privileged Access Management platform.
In this role you will be responsible for scaling the Delinea Cloud Platform extending privileged access controls across human and machine identities. You will manage Delinea Secret Server Cloud DevOps Secrets Vault (DSV) for high-velocity non-human credentials and Privilege Control for Servers / Cloud Suite (enforcing least privilege host-based elevation and AD Bridging across Unix Linux and Windows).
Key Responsibilities
1. Delinea Cloud Platform Implementation
- DevOps Secrets Vault (DSV): Implement and operate DSV for high-velocity machine-to-machine containerized (Kubernetes) and CI/CD pipeline secrets (Jenkins Terraform GitHub Actions).
- Unix/Linux/Windows Server Protection: Deploy and manage Delinea agents (Cloud Suite / Privilege Control for Servers) to enforce Zero Trust Just-In-Time (JIT) access and granular privilege elevation (sudo/su controls) on *NIX and Windows Server workloads.
- System Integration: Integrate Delinea Cloud with Entra ID (Azure AD) Okta Ping SIEM systems (Splunk/Sentinel) and ITSM platforms (ServiceNow).
- Ephemeral Credential Strategy: Ephemeral credential strategy should be evaluated and implemented wherever possible.
- Explore and implement new features best practices in Worday PAM environment
2. Operational Administration & Operations
- Secret Server Cloud Operations: Manage vaulting custom secret templates automated password rotation discovery rules SSH/RDP Web Launchers and session recordings.
- Server Privilege Administration: Manage Zone policies Active Directory Bridging for Linux/Unix platforms MFA enforcement at login/elevation and local account discovery across server estates.
- DevOps & Non-Human Identity Governance: Oversee dynamic secret generation PKI/SSH short-lived certificates API keys and service account rotations for applications and RPA tools.
- Platform Health & L3 Escalation: Monitor engine status API rate limits audit logs and serve as the tier-3 subject matter expert (SME) for PAM incidents.
3. Automation Policy & Governance
- Infrastructure as Code (IaC) & Scripting: Write PowerShell Python or Bash scripts utilizing Delinea Cloud REST APIs and CLI tools to automate onboarding vaulting and compliance auditing.
- Compliance & Auditing: Maintain forensic-level audit trails and continuous reporting to support regulatory frameworks (SOC 2 ISO 27001 PCI-DSS HIPAA).
- SOPs & Enablement: Create engineering documentation cloud architecture diagrams emergency break-glass procedures and developer onboarding guides for DSV.
About You
- 10 years in Identity & Access Management (IAM) with a strong focus on enterprise Privileged Access Management (PAM).
- 4 years of hands-on experience implementing and operating Delinea Cloud (Secret Server Cloud).
- Demonstrated hands-on experience with Delinea DevOps Secrets Vault (DSV) OR Delinea Server PAM / Cloud Suite / Privilege Control for Servers (Unix Linux Windows).
- Deep understanding of Linux/Unix security (PAM modules Sudoers SSH configuration AD joining/bridging via Delinea agents).
- Knowledge of DevOps toolchains (Kubernetes Terraform Ansible CI/CD pipelines) and API secrets management.
- Scripting experience in Python PowerShell or Bash utilizing REST APIs.
- Identity protocols: SAML OAuth OIDC Kerberos LDAP Active Directory Entra ID.
- Bachelors degree in Cybersecurity Computer Science IT or equivalent practical experience.
Preferred Certifications
- Delinea Certifications: Delinea Certified Secret Server Platform Engineer / Cloud Suite Specialist (Highly Desirable).
Our Approach to Flexible Work
With Flex Work were combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections maintain a strong community and do their best work. We know that flexibility can take shape in many ways so rather than a number of required days in-office each week we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers prospects and partners (depending on role). This means youll have the freedom to create a flexible schedule that caters to your business team and personal needs while being intentional to make the most of time spent together. Those in our remote home office roles also have the opportunity to come together in our offices for important moments that matter.
At Workday we are committed to providing an accessible and inclusive hiring experience where all candidates can fully demonstrate their skills. If you require assistance or an accommodation at any point please email .
Are you being referred to one of our roles If so ask your connection at Workday about our Employee Referral process!
At Workday we value our candidates privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers.
Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.
In addition Workday will never ask candidates to pay a recruiting fee or pay for consulting or coaching services in order to apply for a job at Workday.
Required Experience:
Senior IC