Skip to content
  • Home
  • Services
  • About Us
  • Locations
  • S3 Europe
  • S3 Americas
  • S3 Asia
  • Veterans
  • Media
  • Leadership
  • Find a Job
  • IAM Security Engineer/ Lead PAM

    IAM Security Engineer / Lead – PAM

    Position Overview

    We are seeking a senior-level IAM Security Engineer / Lead with deep expertise in Identity and Access Management (IAM) and Privileged Access Management (PAM).

    This is not a Tier 1/Tier 2 IAM administration or operational support role. The ideal candidate will bring hands-on engineering and configuration experience and will help drive the maturity, modernization, and strategic direction of the organization’s IAM and PAM capabilities.

    Candidates should have strong experience with CyberArk, Idira EPM, or comparable enterprise PAM technologies, including direct configuration, implementation, integration, and troubleshooting.

    Benefits

    • 16 days of PTO
    • 10 paid holidays

    Key Responsibilities

    • Lead the design, configuration, implementation, and enhancement of enterprise IAM and PAM solutions.
    • Develop and maintain an IAM security roadmap aligned with business, cybersecurity, and technology objectives.
    • Configure and optimize CyberArk, Idira EPM, or similar PAM platforms to support enterprise privileged-access requirements.
    • Design and implement access-control policies and authorization mechanisms using the principle of least privilege.
    • Develop and enhance identity lifecycle processes for onboarding, offboarding, transfers, and access changes.
    • Design and maintain RBAC, position-based security, access certification, and compliance-monitoring processes.
    • Develop scripts, connectors, integrations, or custom solutions to extend IAM capabilities and automate security processes.
    • Integrate IAM platforms with enterprise applications, directories, authentication platforms, and other security technologies.
    • Implement and support SSO and MFA solutions, including SAML and OpenID Connect integrations.
    • Serve as an IAM subject matter expert supporting audit, compliance, and regulatory requirements.
    • Analyze authorization assignments and Segregation of Duties (SOD) conflicts and partner with audit and compliance teams to remediate violations.
    • Troubleshoot complex IAM, PAM, authentication, authorization, and privileged-access issues.
    • Identify opportunities to improve IAM architecture, processes, controls, automation, and overall security maturity.
    • Collaborate with cybersecurity, HR, application teams, infrastructure teams, business leaders, and other technical and non-technical stakeholders.

    Required Qualifications

    • Senior-level experience in Identity and Access Management (IAM) and/or Privileged Access Management (PAM) engineering.
    • Strong hands-on experience configuring, implementing, integrating, and enhancing CyberArk, Idira EPM, or comparable PAM solutions.
    • Advanced knowledge of identity lifecycle management, including onboarding, offboarding, transfers, and access changes.
    • Strong understanding of RBAC, privileged-access controls, least privilege, authorization models, and position-based security.
    • Experience developing scripts, connectors, automation, or custom code to enhance IAM functionality.
    • Experience integrating IAM systems with enterprise applications, directories, and security platforms.
    • Advanced troubleshooting skills involving identity, authentication, authorization, and access-control issues.
    • Experience supporting IAM-related audit, risk, and compliance activities.
    • Knowledge of security and regulatory frameworks such as NERC CIP, SOX, NIST, and PCI.
    • Strong communication and collaboration skills with the ability to work effectively across technical and non-technical teams.

    Additional Valuable Experience

    • SAP security and authorization experience, including SAP Portal, Portal Roles, SSO, directory services, and web services.
    • SAP GRC Access Control experience, including authorization analysis and SOD conflict identification and remediation.
    • Active Directory or other LDAP directory services.
    • Scripting or automation involving directory queries and updates.
    • MFA implementation and support.
    • Enterprise SSO implementation and troubleshooting.
    • SAML and OpenID Connect (OIDC).
    • Azure AD / Microsoft Entra ID groups and access management.
    • Reporting-platform security and authorization management.
    August 21, 2026
  • Digital Collaboration Analyst

    Digital Collaboration Analyst

    Location: Lutz, FL / Tampa Bay Area
    Work Arrangement: Onsite
    Contract Length: 6 Months
    Employment Type: Contract

    Position Summary

    We are seeking a Digital Collaboration Analyst to provide day-to-day technical support for enterprise collaboration, unified communications, and workplace technology platforms.

    The ideal candidate will have hands-on experience troubleshooting collaboration technologies, managing users and devices, supporting conference rooms and audiovisual systems, and resolving incidents and service requests. This position works closely with senior IT team members, vendors, and internal technology teams to maintain reliable and effective communication services.

    Key Responsibilities

    • Provide Tier 2/Tier 3 technical support for enterprise collaboration and unified communications technologies.
    • Troubleshoot and resolve incidents and service requests related to collaboration platforms and endpoints.
    • Perform user administration, account configuration, provisioning, and troubleshooting.
    • Support deployment, maintenance, upgrades, testing, and validation of collaboration technologies.
    • Support Microsoft Teams, Microsoft 365, Cisco collaboration platforms, and Webex environments.
    • Troubleshoot conference room technology, video conferencing systems, AV equipment, digital signage, and collaboration endpoints.
    • Support mobile devices and enterprise Apple iPhone environments as needed.
    • Coordinate with vendors and internal IT teams to investigate and resolve technical issues.
    • Monitor and troubleshoot connectivity and communication issues involving VoIP, SIP, and networking fundamentals.
    • Use ITSM tools to document, track, and resolve incidents and service requests.
    • Create and maintain technical documentation, knowledge articles, troubleshooting procedures, and user instructions.
    • Assist with testing and validating system changes, upgrades, configurations, and new collaboration features.
    • Provide strong customer service and communicate technical issues and resolutions effectively.

    Required Qualifications

    • 3–5 years of experience supporting enterprise collaboration, unified communications, or IT infrastructure technologies.
    • Hands-on experience supporting one or more of the following:
      • Microsoft Teams
      • Microsoft 365
      • Cisco Unified Communications Manager (CUCM)
      • Cisco Unity Connection
      • Cisco Webex
      • Cisco Jabber
      • Contact Center platforms
      • Apple iPhone/mobile device management
      • Video conferencing and conference room technologies
      • Audio/Visual systems
      • Digital signage
    • Experience troubleshooting technical issues using established troubleshooting methodologies.
    • Working knowledge of VoIP, SIP, and networking fundamentals.
    • Experience working with ITSM/IT service management tools.
    • Strong documentation, communication, customer service, and problem-solving skills.

    Preferred Qualifications

    • Experience supporting Microsoft Teams Voice and enterprise collaboration services.
    • Familiarity with Contact Center technologies.
    • Experience supporting mobile devices and MDM platforms.
    • Experience supporting conference rooms, AV systems, and video conferencing environments.
    • Experience coordinating technical issues with third-party vendors.
    • Associate degree in Information Technology, Computer Science, or a related field.

    Ideal Candidate

    The ideal candidate is a hands-on collaboration/Unified Communications support professional who can troubleshoot enterprise communication technologies and provide effective Tier 2/Tier 3 support.

    Strong candidates may come from Microsoft Teams, Cisco UC, Webex, Contact Center, AV/conferencing, or enterprise collaboration support backgrounds. The role does not require expertise across every listed technology; solid experience in one or more major collaboration platforms is valuable.

    Work arrangement: This is an onsite Tampa/Lutz-area position.

    August 20, 2026
  • Endpoint Services Coordinator

    STRATEGIC STAFFING SOLUTIONS HAS AN OPENING!

    This is a Contract Opportunity with our company that MUST be worked on a W2 Only. No C2C eligibility for this position. Visa Sponsorship is Available! The details are below.

    “Beware of scams. S3 never asks for money during its onboarding process.”

    Job Title: Endpoint Services Coordinator
    Location: Lutz, FL 33549
    On Site Work
    Contract Length: 6+ Months

    Job ref# 247517

    Support the Endpoint Engineering team by coordinating endpoint-related activities, communicating with IT teams and business users, maintaining technical documentation, and assisting with the administration and troubleshooting of Microsoft SCCM/MECM-managed endpoints. This is a coordination and operational support role, not an engineering position.

    Required Qualifications

    • Experience supporting Microsoft SCCM/MECM environments
    • Working knowledge of SCCM client troubleshooting
    • Endpoint support experience
    • Strong technical documentation experience (SOPs, work instructions, knowledge articles, process documentation)
    • Excellent written and verbal communication skills
    • Strong organizational skills with exceptional attention to detail
    • Ability to coordinate multiple tasks with technical teams and business stakeholders
    • Strong problem-solving and customer service skills

    Preferred Qualifications

    • Experience supporting enterprise Windows endpoint environments
    • Microsoft Intune experience or endpoint management knowledge
    • Software deployment coordination experience
    • Application packaging knowledge
    • ServiceNow experience
    • Microsoft Office 365 experience
    • Windows administration experience

    Responsibilities

    • Coordinate endpoint management activities between Endpoint Engineers, IT teams, and business users
    • Serve as the primary point of contact for endpoint-related requests
    • Create and maintain technical documentation, SOPs, knowledge base articles, and process documentation
    • Troubleshoot SCCM/MECM client issues and escalate complex problems when necessary
    • Review endpoint requests and gather technical requirements
    • Track work items and ensure timely completion
    • Coordinate software deployments and endpoint lifecycle activities
    • Support process improvement initiatives
    • Maintain accurate operational documentation
    • The Endpoint Services Coordinator is responsible for managing the lifecycle of incoming client technical requests. The position requires independent, reasonable, decision-making to evaluate, prioritize, and route complex service and technical requests to Endpoint Engineers and IT, while maintaining comprehensive operational records for use in promoting optimal business operations.
    August 5, 2026
  • Enterprise Data & Platform Security Analyst

    Enterprise Data & Platform Security Analyst

    Location: Lutz, FL (Hybrid – 3 days onsite / 1 day remote)
    Contract Salary: $60,000–$80,000 annually
    Benefits: 16 accrued PTO days, paid client holidays, medical benefits available
    Schedule: Tuesdays and Thursdays onsite (additional onsite day as required)
    Employment Type: W2 Only (No C2C or 1099)
    Work Authorization: Must be a U.S. Citizen or Green Card Holder

    Position Concept

    The Enterprise Data & Platform Security Analyst protects sensitive data across endpoints, networks, cloud services, and enterprise platforms by designing, implementing, and operating data protection controls.

    This role partners with Security, Infrastructure, Application, Legal, Privacy, and business teams to reduce the risk of data loss, improve governance, support regulatory compliance, and strengthen the organization’s overall security posture.

    The role is also responsible for building and scaling security engineering capabilities across cloud infrastructure, identity systems, data services, Kubernetes and container platforms, CI/CD pipelines, secrets management, and platform observability.


    Primary Duties & Responsibilities

    1. Enterprise Data Protection (30%)

    • Design and lead enterprise-scale data protection strategies across on-premises, cloud, SaaS, and hybrid environments.
    • Define policy architecture, control objectives, and implementation patterns for:
      • Data classification
      • Encryption
      • Retention
      • Tokenization
      • Data exfiltration prevention
    • Drive roadmap planning, vendor evaluations, and continuous improvement initiatives for data protection platforms.

    2. Secure Platform Architecture (25%)

    • Define secure architecture patterns and engineering guardrails for:
      • Kubernetes
      • Containers
      • Virtual infrastructure
      • Storage platforms
      • Managed cloud services
      • APIs
      • Infrastructure-as-Code (IaC) pipelines

    3. Incident Response & Investigations (10%)

    • Lead complex incident investigations involving:
      • Sensitive data exposure
      • Insider risk
      • Control breakdowns
    • Coordinate remediation strategies and security architecture improvements across infrastructure, cloud, application, and data teams.
    • Drive incident response activities including forensic coordination, containment recommendations, lessons learned, and control enhancements.

    4. Security Assessments (10%)

    • Lead security assessments, threat analysis, and control design reviews for:
      • Enterprise platforms
      • Cloud environments
      • Databases
      • Middleware
      • Business-critical applications
    • Own vulnerability and misconfiguration investigations, prioritizing based on exploitability, business risk, and compensating controls.

    5. Governance & Risk Communication (10%)

    • Translate business, legal, privacy, and regulatory requirements into practical technical and operational controls.
    • Provide concise risk communication, metrics, and executive-ready summaries to leadership and governance stakeholders.

    6. Standards & Continuous Improvement (10%)

    • Develop and improve standards, baselines, playbooks, and security procedures for enterprise services and data platforms.
    • Develop dashboards, metrics, and trend analysis to measure policy effectiveness and risk reduction.

    7. Technical Leadership (5%)

    • Provide technical leadership, mentoring, and quality oversight for analysts and specialists at earlier career stages.

    Knowledge, Skills & Abilities

    Required

    • Deep understanding of cybersecurity principles including:
      • Confidentiality
      • Integrity
      • Availability
      • Least privilege
      • Defense in depth
    • Strong knowledge of:
      • Data protection
      • Networking
      • Operating systems
      • Cloud fundamentals
      • Enterprise threat vectors
    • Deep familiarity with enterprise environments, ticketing systems, and documentation practices.
    • Experience with SIEM, DLP, or endpoint monitoring tools.
    • Ability to review and interpret logs from:
      • Active Directory
      • VPN
      • Endpoint security platforms
      • Cloud environments
    • Ability to independently investigate complex security incidents, build timelines, gather evidence, and document findings.
    • Ability to communicate technical findings to executive leadership through risk summaries and recommendations.
    • Ability to manage multiple priorities in a fast-paced environment.
    • Experience mentoring junior analysts and collaborating with HR, Legal, IT, Compliance, and business teams.
    • Excellent analytical, organizational, written, and verbal communication skills.

    Experience

    • Minimum 5 years of Cybersecurity, Information Security, or related IT experience.
    • Hands-on technical experience may include networking, telecommunications, communications systems, hardware, software, or related technologies.

    Education Substitutions

    The following may substitute for experience:

    • Associate degree in Computer Science, Information Systems, or related IT field with 3 years of experience.
    • Bachelor’s degree in Computer Science, Information Systems, or related IT field with 1 year of experience.
    • Up to one year of formal internship or co-op IT experience may count toward the experience requirement.
     
     
    July 24, 2026
  • Lead IAM Security Engineer- Saviynt IGA

    STRATEGIC STAFFING SOLUTIONS HAS AN OPENING!

    This is a Contract Opportunity with our company that MUST be worked on a W2 Only. No C2C eligibility for this position. Visa Sponsorship is Available! The details are below.

    “Beware of scams. S3 never asks for money during its onboarding process.”

    Job Title: Lead IAM Security Engineer- Saviynt IGA
    On Site Work
    Location: Lutz, FL 33549
    Contract Length: 12+ Months

    Job ref# 247302

    We are seeking an experienced Lead IAM Security Engineer with deep expertise in Saviynt Identity Governance & Administration (IGA) to help mature and modernize a large enterprise IAM program.

    This is an engineering-focused role designed for professionals who build, improve, and transform IAM capabilities—not individuals primarily performing day-to-day administration or ticket-based support. The ideal candidate will drive IAM strategy, automation, governance, and program maturity while partnering with internal stakeholders and third-party service providers.

    Success in this role is measured by innovation, problem solving, process improvement, and the ability to deliver long-term IAM solutions that strengthen security, compliance, and operational efficiency.

    What We’re Looking For

    We are interested in professionals who:

    • Challenge the status quo and continuously seek improvements.
    • Identify security gaps and opportunities for modernization.
    • Drive IAM program maturity through engineering and automation.
    • Develop strategic roadmaps and execution plans.
    • Improve governance, compliance, and audit readiness.
    • Build scalable IAM capabilities rather than perform routine operational tasks.
    • Possess an engineering and solution-oriented mindset.

    Candidates with fewer years of experience but demonstrated success implementing or transforming IAM programs may be considered over individuals with extensive administrative experience.

    Primary Responsibilities

    • Develop and execute the enterprise Identity & Access Management (IAM) roadmap aligned with business and security objectives.
    • Design and implement Identity Governance & Administration (IGA) solutions using Saviynt.
    • Design, implement, and maintain Role-Based Access Control (RBAC) models and least-privilege access strategies.
    • Develop identity lifecycle workflows for user onboarding, transfers, and offboarding.
    • Build and maintain certification campaigns, access reviews, compliance reporting, and governance processes.
    • Design and enhance authentication, authorization, Single Sign-On (SSO), and access control solutions.
    • Integrate enterprise applications, directories, and identity providers into the IAM platform.
    • Develop custom workflows, scripts, connectors, and automation to improve IAM operations.
    • Monitor and respond to IAM-related security incidents and unauthorized access events.
    • Serve as a subject matter expert during audits and regulatory assessments involving IAM, SOX, PII, and related compliance requirements.
    • Partner closely with Cyber Security, Human Resources, business units, and technology teams to deliver secure and scalable IAM solutions.
    • Identify opportunities to improve automation, governance, and operational efficiency across the IAM environment.

    Required Qualifications

    • Approximately 5+ years of Identity & Access Management experience (strong candidates with exceptional accomplishments may also be considered).
    • Hands-on experience with Saviynt Identity Governance & Administration (IGA).
    • Strong understanding of:
      • Identity lifecycle management
      • Role-Based Access Control (RBAC)
      • Least privilege principles
      • Access certifications
      • Identity governance
      • Workflow development
    • Experience designing and implementing IAM workflows for onboarding, offboarding, and user lifecycle management.
    • Experience developing custom scripts, connectors, or integrations for IAM platforms.
    • Strong understanding of enterprise authorization models and organizational security structures.
    • Experience integrating IAM solutions with enterprise applications, directories, and business systems.
    • Experience securing enterprise reporting platforms and user privileges.
    • Knowledge of SAP security concepts, including:
      • SAP authorization concepts
      • Portal security
      • Single Sign-On
      • Directory Services
      • Internet Transaction Server (ITS)
      • Web services security
    • Experience with Governance, Risk & Compliance (GRC), Segregation of Duties (SoD), and access controls.
    • Experience supporting compliance initiatives including:
      • SOX
      • NERC CIP
      • NIST
      • PCI
    • Strong troubleshooting, analytical, and problem-solving skills.
    • Excellent communication skills with both technical and business stakeholders.

    Preferred Qualifications

    • Experience with Active Directory (AD) or LDAP directory services.
    • Experience with Azure Active Directory / Microsoft Entra ID.
    • Experience deploying and supporting Multi-Factor Authentication (MFA).
    • Experience implementing and supporting Single Sign-On (SSO).
    • Experience with SAML and OpenID Connect (OIDC).
    • Experience with privileged access management technologies.
    • Knowledge of Azure AD group administration.
    • Experience supporting hybrid enterprise identity environments.
    July 17, 2026
  • CyberArk & Endpoint Security Engineer

    STRATEGIC STAFFING SOLUTIONS HAS AN OPENING!

    This is a Contract Opportunity with our company that MUST be worked on a W2 Only. No C2C eligibility for this position. Visa Sponsorship is Available! The details are below.

    “Beware of scams. S3 never asks for money during its onboarding process.”

     

    We are seeking a CyberArk & Endpoint Security Engineer to design, implement, and maintain our enterprise identity and endpoint security platforms. In this role, you will lead the deployment and management of CyberArk PAM (Privileged Access Management) and CyberArk EPM (Endpoint Privilege Manager). Your primary goal will be to enforce the principle of least privilege, eliminate standing local administrator rights across thousands of workstations, and secure high-value infrastructure credentials.

    Core Responsibilities

    • Platform Administration: Manage the health, configuration, and scaling of CyberArk PAM (Privilege Cloud or Self-Hosted) and CyberArk EPM environments.
    • Least Privilege Enforcement: Design, test, and implement EPM application control policies to remove local admin rights from Windows and macOS endpoints without disrupting business operations.
    • Credential Management: Configure automated password rotation, verification, and session monitoring policies via CyberArk Central Policy Manager (CPM) and Privileged Session Manager (PSM).
    • Agent Deployment: Partner with Desktop Engineering teams to package and distribute the CyberArk EPM agent globally using tools like Microsoft Intune and Jamf.
    • Policy Optimization: Analyze EPM discovery logs to create just-in-time (JIT) privilege elevation rules and trusted application definitions for standard users.
    • Integration & Automation: Develop PowerShell or Python scripts using CyberArk REST APIs to automate account onboarding and integrate workflows with ServiceNow.
    • Incident Support: Act as the Tier 3 escalation point for troubleshooting credential rotation failures, agent communication issues, and application elevation blocks.

    Required Technical Skills & Qualifications

    • CyberArk Expertise: Minimum 3+ years of hands-on experience managing CyberArk PAM and EPM policy structures.
    • Operating Systems: Deep technical knowledge of Windows OS architecture (UAC, Registry, Local Groups) and macOS security frameworks.
    • Directory Services: Strong understanding of Active Directory, Azure AD/Entra ID, Group Policy Objects (GPOs), and LDAP.
    • Endpoint Management Tools: Proven experience deploying software and configuration profiles via Microsoft Intune, SCCM, or Jamf.
    • Scripting: Proficiency in PowerShell, Bash, or Python for task automation and API integration.
    • Security Fundamentals: Solid grasp of enterprise network architecture, TLS/SSL certificates, SIEM integrations (e.g., Splunk), and modern IAM concepts (SAML, OIDC, MFA).

    Preferred Qualifications

    • Certifications: CyberArk Certified Defender, Sentry, or CDE (CyberArk Delivery Engineer). CISSP or CompTIA Security+ is a plus.
    • Experience: Prior experience executing a successful global rollout of EPM or similar application whitelisting solutions.
    July 17, 2026

© 2026 Strategic Staff. All rights reserved.