Santander Consumer USA ยท 18 hours ago
PAM (Privileged Access Management) Senior CyberArk Engineer
Santander Consumer USA is a global leader in financial services, transitioning into a technology-driven organization. They are seeking a Senior CyberArk Engineer responsible for architecting, deploying, and maintaining privileged access security solutions using the CyberArk suite, ensuring the protection of critical systems and compliance with security best practices.
Financial Services
Responsibilities
Design, deploy, configure, and maintain the full on-premises CyberArk Privileged Access Security (PAS) suite, including: Enterprise Password Vault (EPV), Privileged Session Manager (PSM), Privileged Session Manager for SSH (PSM-SSH), Central Policy Manager (CPM), Privileged Threat Analytics (PTA)
Implement and maintain CyberArk safes, platforms, policies, and connectors
Integrate CyberArk with enterprise systems, including LDAP/AD, and SIEM ticketing systems, and cloud platforms (AWS, Azure, GCP)
Build and maintain custom connectors and plugins for applications and infrastructure
Develop and enforce privileged access policies and best practices
Conduct threat modeling and ensure PAM alignment with regulatory frameworks (SOX, GLBA, NYDFS , etc.)
Review privileged access workflows and recommend improvements to strengthen security posture
Automate onboarding of privileged accounts, systems, and applications using REST APIs, PowerShell, Python, or similar tools
Tune CPM/PSM performance, optimize vault operations, and improve automated credential rotation processes
Implement continuous monitoring, alerting, and reporting mechanisms
Serve as a subject matter expert (SME) for CyberArk-related issues across infrastructure, development, and security teams
Troubleshoot complex vaulting, credential, and session management issues
Perform CyberArk upgrades, patching, health checks, and system hardening
Participate in on-call rotations and provide escalation-level support
Work closely with IAM, security operations, risk, and compliance stakeholders
Provide guidance and mentorship to junior engineers
Develop documentation, runbooks, and best practice guides
Qualification
Required
Bachelor's Degree or equivalent work experience: Computer Science/Software Engineering or equivalent field
5+ years of experience in Information Security or Identity and Access Management
5+ years of hands-on on-premises CyberArk engineering experience
Strong understanding of privileged access management principles
Proficiency with: PowerShell, Python, or equivalent scripting languages
Windows and Linux administration
Active Directory, LDAP, MFA integrations
Networking basics (firewalls, proxies, DNS)
Experience supporting large-scale, high-availability PAM environments
Threat and vulnerability management related to privileged access
Background in regulated industries (finance, healthcare, government)
Strong analytical, problem-solving, and debugging skills
Excellent communication and documentation abilities
Ability to lead complex projects with minimal supervision
High attention to detail and commitment to security best practices
Preferred
CyberArk Defender, Sentry, or Guardian certifications
Established work history or equivalent demonstrated through a combination of work experience, training, military service, or education
Experience in Microsoft Office products
Company
Santander Consumer USA
In 1995, a group of young entrepreneurs thought they could make their mark on the world of automotive finance by thinking a little bigger and a lot bolder than the competition.
H1B Sponsorship
Santander Consumer USA has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (30)
2024 (39)
2023 (37)
2022 (31)
2021 (30)
2020 (34)
Funding
Current Stage
Late StageCompany data provided by crunchbase