Claranet→
Identity Security Engineer at Claranet in Lisbon, Lisbon, Portugal
Mid LevelHybridFull-timeLisbon, Lisbon, Portugal
Skills
cyberark privileged access managementactive directoryiampamkerberosntlmgpospurple knightnetwrix pingcastlezero trustleast-privilege principlesanalytical skillsproblem-solvingdetail-orientedteamworkcollaborative spiritother pam/iam platforms
Job Description
We're fast learners, hard workers, natural collaborators... and we Make Modern Happen!
Our ambition is to unlock the potential of our digital world so that organisations everywhere can innovate and thrive securely.
We aim to achieve this goal by bringing together the world’s most talented people and the most powerful technologies, combining them to address our customers' challenges and to build something stronger together.
If you share our vision, join us!
Right now, we are looking for a Identity Security Engineer to integrate our internal team, based in Lisbon/Porto.
Your responsibilities include:
- Administer, configure and operate the CyberArk Privileged Access Management (PAM) suite end-to-end (Vault, CPM, PVWA, PSM, PTA/Privilege Cloud), ensuring availability, performance and security of the platform.
- Design, implement and maintain IAM/PAM policies, safes, platforms and access workflows aligned with least-privilege and Zero Trust principles.
- Architect and implement CyberArk components focused on protecting domain credentials, service accounts and administrative access to Active Directory.
- Manage the full lifecycle of privileged accounts (onboarding, rotation, reconciliation, discovery) and continuously tune credential management policies.
- Develop and execute Active Directory Vulnerability Remediation plans to strengthen clients' AD security posture, in articulation with the PAM strategy.
- Lead Active Directory and IAM/PAM Assessment projects, using specialized tools such as Purple Knight or similar to identify and prioritise critical identity risks.
- Design and validate resilience and disaster recovery strategies for AD and for the CyberArk environment (backup, HA/DR).
- Act as technical reference and advisor on CyberArk architecture, IAM/PAM best practices, Kerberos, NTLM, GPOs and AD topology security.
You must have:
- Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering or a related field.
- 3 to 5 years of experience in cybersecurity, with proven, hands-on focus on IAM/PAM and Identity/Active Directory security.
- Demonstrable, recognised experience administering and managing CyberArk in production environments (Vault, CPM, PVWA, PSM, and ideally Privilege Cloud).
- Solid practical knowledge of IAM/PAM concepts and lifecycle management (privileged account onboarding, rotation, reconciliation, session monitoring).
- Hands-on experience using AD security assessment tools such as Purple Knight, Netwrix PingCastle or similar.
We value:
- CyberArk certifications (e.g., CyberArk Defender, CyberArk Sentry) are highly valued and considered a significant differentiator for this role.
- Broader IAM/PAM experience beyond CyberArk (e.g., other PAM/IAM platforms) as complementary knowledge.
- Strong analytical and problem-solving skills.
- A meticulous and detail-oriented mindset.
- Teamwork and a collaborative spirit.
We offer:
- Regular professional development;
- Certification paths resources;
- Regular teambuilding programs;
- Friendly workplace.
Workplace:Lisbon/Porto - Hybrid
Claranet: Make Modern Happen!
Benefits
Regular professional development
Certification paths resources
Regular teambuilding programs
Friendly workplace