Your work days are brighter here.
We’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on what matters most. The minute you join, you’ll feel it. Not just in the products we build, but in how we show up for each other. Our culture is rooted in integrity, empathy, and shared enthusiasm. We’re in this together, tackling big challenges with bold ideas and genuine care. We look for curious minds and courageous collaborators who bring sun-drenched optimism and drive. Whether you're building smarter solutions, supporting customers, or creating a space where everyone belongs, you’ll do meaningful work with Workmates who’ve got your back. In return, we’ll give you the trust to take risks, the tools to grow, the skills to develop and the support of a company invested in you for the long haul. So, if you want to inspire a brighter work day for everyone, including yourself, you’ve found a match in Workday, and we hope to be a match for you too.
About the Team
Identity and Access Management team manage Identity suite including Okta, Delinea, KeyFactor, Active Directory and Entra ID environment. We manage workmate, customer and partner identities.
We are looking for a Senior Delinea Cloud PAM Specialist to architect, deploy, and operationalize our cloud-native Privileged Access Management platform.
In this role, you will be responsible for scaling the Delinea Cloud Platform, extending privileged access controls across human and machine identities. You will manage Delinea Secret Server Cloud, DevOps Secrets Vault (DSV) for high-velocity non-human credentials, and Privilege Control for Servers / Cloud Suite (enforcing least privilege, host-based elevation, and AD Bridging across Unix, Linux, and Windows).
DevOps Secrets Vault (DSV): Implement and operate DSV for high-velocity machine-to-machine, containerized (Kubernetes), and CI/CD pipeline secrets (Jenkins, Terraform, GitHub Actions).
Unix/Linux/Windows Server Protection: Deploy and manage Delinea agents (Cloud Suite / Privilege Control for Servers) to enforce Zero Trust, Just-In-Time (JIT) access, and granular privilege elevation (sudo/su controls) on *NIX and Windows Server workloads.
System Integration: Integrate Delinea Cloud with Entra ID (Azure AD), Okta, Ping, SIEM systems (Splunk/Sentinel), and ITSM platforms (ServiceNow).
Ephemeral Credential Strategy: Ephemeral credential strategy should be evaluated and implemented wherever possible.
Explore and implement new features, best practices in Worday PAM environment
2. Operational Administration & Operations
Secret Server Cloud Operations: Manage vaulting, custom secret templates, automated password rotation, discovery rules, SSH/RDP Web Launchers, and session recordings.
Server Privilege Administration: Manage Zone policies, Active Directory Bridging for Linux/Unix platforms, MFA enforcement at login/elevation, and local account discovery across server estates.
DevOps & Non-Human Identity Governance: Oversee dynamic secret generation, PKI/SSH short-lived certificates, API keys, and service account rotations for applications and RPA tools.
Platform Health & L3 Escalation: Monitor engine status, API rate limits, audit logs, and serve as the tier-3 subject matter expert (SME) for PAM incidents.
3. Automation, Policy & Governance
Infrastructure as Code (IaC) & Scripting: Write PowerShell, Python, or Bash scripts utilizing Delinea Cloud REST APIs and CLI tools to automate onboarding, vaulting, and compliance auditing.
Compliance & Auditing: Maintain forensic-level audit trails and continuous reporting to support regulatory frameworks (SOC 2, ISO 27001, PCI-DSS, HIPAA).
SOPs & Enablement: Create engineering documentation, cloud architecture diagrams, emergency break-glass procedures, and developer onboarding guides for DSV.
About You
10+ years in Identity & Access Management (IAM) with a strong focus on enterprise Privileged Access Management (PAM).
4+ years of hands-on experience implementing and operating Delinea Cloud (Secret Server Cloud).
Demonstrated hands-on experience with Delinea DevOps Secrets Vault (DSV) OR Delinea Server PAM / Cloud Suite / Privilege Control for Servers (Unix, Linux, Windows).
Deep understanding of Linux/Unix security (PAM modules, Sudoers, SSH configuration, AD joining/bridging via Delinea agents).
Knowledge of DevOps toolchains (Kubernetes, Terraform, Ansible, CI/CD pipelines) and API secrets management.
Scripting experience in Python, PowerShell, or Bash utilizing REST APIs.
Bachelor’s degree in Cybersecurity, Computer Science, IT, or equivalent practical experience.
Nice to have
Delinea Certifications: Delinea Certified Secret Server Platform Engineer / Cloud Suite Specialist (Highly Desirable).
Our Approach to Flexible Work
With Flex Work, we’re combining the best of both worlds: in-person time and remote. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. We know that flexibility can take shape in many ways, so rather than a number of required days in-office each week, we simply spend at least half (50%) of our time each quarter in the office or in the field with our customers, prospects, and partners (depending on role). This means you'll have the freedom to create a flexible schedule that caters to your business, team, and personal needs, while being intentional to make the most of time spent together. Those in our remote "home office" roles also have the opportunity to come together in our offices for important moments that matter.
At Workday, we are committed to providing an accessible and inclusive hiring experience where all candidates can fully demonstrate their skills. If you require assistance or an accommodation at any point, please email accommodations@workday.com.
Are you being referred to one of our roles? If so, ask your connection at Workday about our Employee Referral process!
At Workday, we value our candidates’ privacy and data security. Workday will never ask candidates to apply to jobs through websites that are not Workday Careers.
Please be aware of sites that may ask for you to input your data in connection with a job posting that appears to be from Workday but is not.
In addition, Workday will never ask candidates to pay a recruiting fee, or pay for consulting or coaching services, in order to apply for a job at Workday.