Identity Security Specialist Solutions Engineer
Summary
A customer-facing pre-sales and advisory role serving as AHEAD's national identity-security expert, specializing in CyberArk, PIM, and PAM. Day to day involves leading assessments, workshops, demos and POVs, designing privileged-access architectures, and producing solution designs, proposals, and roadmaps for customers.
AHEAD is hiring an Identity Security Specialist Solutions Engineer to serve as a national identity-security resource across AHEAD’s regions, account teams, delivery organization, and strategic partners.
This role specializes in CyberArk, Privileged Identity Management (PIM), and Privileged Access Management (PAM). The successful candidate will help customers assess privileged-access risk, design target-state architectures, select and size solutions, validate technical approaches, and build practical implementation roadmaps.
This is a customer-facing pre-sales and advisory role. The position shapes technical solutions, scopes services, supports proposals, and guides technical validation. Delivery teams own post-sale implementation and operational execution.
Responsibilities
- Serve as a national identity-security resource supporting qualified opportunities across AHEAD regions.
- Lead advisory discovery, technical sales calls, identity-security assessments, architecture workshops, demonstrations, POVs/POCs, and executive briefings.
- Design and present CyberArk-centered privileged-access architectures for workforce, administrator, vendor, service, machine, and non-human identities.
- Advise customers on privileged-account discovery, vaulting, credential rotation, onboarding, session management, monitoring, just-in-time access, least privilege, break-glass access, and shared-account reduction.
- Partner with delivery leadership to ensure proposed solutions are implementable and aligned with AHEAD’s professional and managed services capabilities.
- Create solution designs, configurations, sizing inputs, services proposals, statements of work, presentations, technical justifications, and customer roadmaps.
- Provide pricing and effort inputs for account and delivery teams; final commercial approval remains with the appropriate AHEAD leaders.
- Qualify opportunities based on technical requirements, business outcomes, decision process, funding, and customer readiness.
- Define CyberArk and adjacent identity-security strategies across on-premises, AWS, Azure, GCP, SaaS, and hybrid environments.
- Connect PIM/PAM strategy to IAM, IGA, MFA, SSO, ITDR, secrets management, cloud IAM, SIEM/SOAR, ITSM, and Zero Trust programs.
- Work with OEM field teams on technical alignment, enablement, certifications, and active customer campaigns.
- Contribute reusable architectures, discovery guides, workshop content, competitive insights, and enablement materials.
Required Qualifications
- 7+ years of experience in cybersecurity, identity, cloud, technology consulting, or solutions engineering, including at least 4 years focused on identity security.
- Prior customer-facing pre-sales, solutions engineering, consulting, or security-architecture experience.
- Demonstrated CyberArk experience in at least one enterprise program spanning two or more lifecycle stages, such as assessment, design, migration, implementation, integration, or operationalization.
- Practical expertise in PIM and PAM concepts, controls, workflows, and operating models.
- Experience creating customer-facing proposals, solution designs, SOWs, services proposals, or equivalent pre-sales artifacts.
- Ability to design and present identity-security architectures to technical practitioners and executive stakeholders.
- Experience integrating privileged access with enterprise identity, cloud, endpoint, security operations, and ITSM platforms.
- Strong written, verbal, whiteboarding, presentation, and customer-management skills.
Preferred Qualifications
- CyberArk certification or equivalent demonstrated product expertise.
- Experience with CyberArk Privilege Cloud, PAM Self-Hosted, Endpoint Privilege Manager, Secrets Manager, or related capabilities.
- Experience with Microsoft Entra ID, Active Directory, Okta, SailPoint, Saviynt, Delinea, BeyondTrust, or comparable platforms.
- Familiarity with identity threat detection and response, non-human identity, workload identity, and cloud entitlement management.
- Consulting experience at a systems integrator, professional services firm, advisory practice, or technology provider.
- Delivery experience standing up, configuring, migrating, or operationalizing privileged-access tooling.
- Familiarity with NIST, CIS Controls, Zero Trust, SOX, PCI DSS, HIPAA, or other control frameworks relevant to privileged access.
- Relevant certifications such as CISSP, CCSP, CyberArk, GIAC, or equivalent.
Success Measures: First 6-12 months
- Establish trusted working relationships with Security Sales, account teams, delivery leaders, CyberArk, and adjacent partners.
- Lead repeatable identity-security discovery and workshop motions that produce qualified opportunities and clear next steps.
- Demonstrate the ability to produce accurate solution designs, services proposals, and technical validation plans.
- Build reusable CyberArk/PIM/PAM architectures, discovery assets, and enablement content.
- Support successful transitions from pre-sales scope to delivery without material ambiguity in assumptions, dependencies, or customer outcomes.
Behavioral Expectations
- Explains complex privileged-access concepts clearly to technical and executive audiences.
- Uses specific customer evidence to connect technical design to risk reduction, operational improvement, and business value.
- Facilitates alignment across security, identity, infrastructure, cloud, audit, and operations stakeholders.
- Communicates assumptions, dependencies, risks, and decisions clearly in written and verbal form.
- Works effectively in a matrixed national organization with multiple account teams, delivery groups, and OEM partners.
- Maintains professional judgment when customer requirements, product capabilities, or commercial constraints conflict.
Skills
As published by lever · 11 questions · 1 written answer
Basics
Resume/CV, Full name, Pronouns, Email, Phone, Current location, Current company, LinkedIn URL, Twitter URL, GitHub URL, Portfolio URL, Other website
Short answers (7)
- Where do you currently reside? (City/State)?
- What % of travel are you open to?
- If so, where would you be open to relocating?
- Do you hold any industry related certifications?
- Expected Salary?
- Primary Residence Address
- Work Authorization status (US Citizen, Green Card Holder, etc.)
Pick from a list (3)
- Are you willing to relocate if needed?
- Confirm the ability to perform the requisite duties of the role with or without reasonable accommodations optional
- AHEAD will consider the contents of an uploaded resume or LinkedIn profile only insofar as it pertains to employment history, and any data that contains or could be a proxy for data that would indicate a person’s age, race, gender, disability status, veteran status, national origin, religion, or other protected characteristic will be disregarded optional
Written answers (1)
- Provide All Post-Secondary Education Attained - Formatted as: College Name; Degree Obtained (e.g.: University of Somewhere; Bachelor of Science). Please include only educational programs from which you graduated. **Any additional information provided, such as dates/year of graduation, will be disregarded.**