Green Card Privileged Access Management Jobs
Privileged Access Management roles sit at the intersection of cybersecurity and identity governance, making them strong candidates for EB-2 and EB-3 green card sponsorship through PERM labor certification. Employers filing for PAM engineers and analysts must document that no qualified U.S. worker is available, clearing the path to permanent residency sponsorship for foreign professionals.
Find Green Card Privileged Access Management JobsOverview
Showing 5 of 8+ Privileged Access Management jobs










See all Privileged Access Management Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Privileged Access Management roles.
Get Access To All Jobs
INTRODUCTION
Join Mizuho as Privileged Access Management Engineer! Mizuho’s Identity and Access Management (IAM) team is undergoing an exciting transformation. We're building a dedicated high performing IAM function that is central to the firm's cybersecurity and regulatory strategy. Our environment is dynamic, growing, and rich with opportunity. You’ll work alongside a talented group of professionals who are passionate about solving complex access challenges, automating at scale, and strengthening security posture across both on-premises and cloud environments. This is a unique chance to join our team that's shaping the future of IAM at a major financial institution. We are seeking a CyberArk Engineer to support the implementation, operation, and ongoing management of our Privileged Access Management (PAM) platform. The role is responsible for securing privileged and service accounts, ensuring compliance with security standards, and supporting enterprise users and applications. This hands-on engineering role focuses on delivering secure and scalable solutions for managing privileged accounts used by servers, applications, services, APIs, and cloud workloads. The ideal candidate has deep expertise in CyberArk and related technologies. This role is critical to strengthening the firm's identity security posture, enabling secure cloud adoption, and supporting compliance with regulatory and internal control requirements.
KEY RESPONSIBILITIES
Core CyberArk / PAM Engineering:
- Design, implement, and maintain CyberArk Privileged Access Management (PAM) solutions to secure privileged, service, and application accounts across enterprise environments.
- Configure and manage CyberArk components including Digital Vault, PVWA, CPM, PSM, and connectors (Windows, Unix, Database, Cloud where applicable).
- Create and manage safes, platforms, access policies, and permissions in accordance with least-privilege and security standards.
- Build automations to support the core PAM activities.
Privileged Account Onboarding & Lifecycle Management:
- Lead onboarding of privileged and service accounts into CyberArk, including inventory validation, account vaulting, and enabling password rotation.
- Work closely with infrastructure and application teams to identify dependencies and ensure password changes do not disrupt services.
- Manage account lifecycle activities such as modifications, offboarding, and exception handling.
Password & Session Management:
- Implement and monitor automated password rotation and reconciliation for managed accounts.
- Configure and support Privileged Session Management (PSM) for secure access and session recording.
- Troubleshoot password rotation failures, access issues, and CPM/PSM errors.
Operations, Monitoring & Support:
- Provide L2/L3 operational support, including root-cause analysis and coordination with vendors or internal teams.
- Maintain and update runbooks, SOPs, and operational documentation for CyberArk processes.
Compliance, Audit & Governance:
- Support audit and regulatory requirements by generating CyberArk reports, access certifications, and compliance evidence.
- Participate in periodic privileged access recertifications and remediation of findings.
- Ensure CyberArk configurations align with IAM standards, internal policies, and regulatory frameworks (e.g., SOX, ISO, internal audits).
Integration & Automation:
- Integrate CyberArk with IAM tools (e.g., SailPoint), Active Directory, ServiceNow and other enterprise applications.
- Support use of CyberArk REST APIs and Central Credential Provider (CCP) for application integrations and automation.
- Assist with automation and reconciliation processes related to privileged account discovery and onboarding.
Stakeholder Collaboration:
- Act as a subject-matter expert (SME) for CyberArk/PAM, advising application, infrastructure, and security teams.
- Coordinate with IAM Governance, Risk, Compliance, and Audit teams on PAM-related initiatives.
- Participate in design and architecture discussions to identify gaps and drive scalable, automation-friendly improvements.
PREFERRED QUALIFICATIONS
- Experience with cloud PAM (AWS, Azure, GCP)
- Scripting (PowerShell, Python) for automation
- CyberArk certifications (CPC, CDE, Defender)
BASIC QUALIFICATIONS
- 7+ years of experience in Identity & Access Management, cybersecurity engineering, or related infrastructure security roles, with a strong focus on Privileged Access Management.
- Demonstrated experience with CyberArk.
- Experience in enterprise environments (Windows, Unix, databases, service accounts).
- Familiarity with security controls and regulatory expectations related to identity, credential, and Privileged Access Management (e.g., SOX, NIST).
- Strong collaboration and communication skills, with the ability to work effectively across infrastructure, cloud, security, and DevOps teams.
The expected base salary ranges from $81,000 - $150,000. Salary offers are based on a wide range of factors including relevant skills, training, experience, education, and, where applicable, certifications and licenses obtained. Market and organizational factors are also considered. In addition to salary and a generous employee benefits package, including Medical, Dental and 401K plans, successful candidates are also eligible to receive a discretionary bonus.
OTHER REQUIREMENTS
Mizuho has in place a hybrid working program, with varying opportunities for remote work depending on the nature of the role, needs of your department, as well as local laws and regulatory obligations. Roles in some of our departments have greater in-office requirements that will be communicated to you as part of the recruitment process.
COMPANY OVERVIEW
Mizuho Financial Group, Inc. is the 15th largest bank in the world as measured by total assets of ~$2 trillion. Mizuho's 60,000 employees worldwide offer comprehensive financial services to clients in 35 countries and 800 offices throughout the Americas, EMEA and Asia. Mizuho Americas is a leading provider of corporate and investment banking services to clients in the US, Canada, and Latin America. Through its acquisition of Greenhill, Mizuho provides M&A, restructuring and private capital advisory capabilities across Americas, Europe and Asia. Mizuho Americas employs approximately 3,500 professionals, and its capabilities span corporate and investment banking, capital markets, equity and fixed income sales & trading, derivatives, FX, custody and research.
Mizuho Americas offers a competitive total rewards package. We are an EEO/AA Employer - M/F/Disability/Veteran. We participate in the E-Verify program. We maintain a drug-free workplace and reserve the right to require pre- and post-hire drug testing as permitted by applicable law.
See all Green Card Privileged Access Management Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Green Card Privileged Access Management Jobs.
Get Access To All JobsTips for Finding Green Card Sponsorship in Privileged Access Management
Document your PAM credentials before applying
PERM requires your employer to verify your qualifications match the job requirements exactly. Gather certifications like CyberArk Defender, BeyondTrust, or Sailpoint credentials now, because credential gaps discovered mid-filing can stall or derail your green card case.
Target employers with dedicated security teams
Financial institutions, healthcare networks, and federal contractors regularly sponsor PAM roles because their compliance obligations create sustained demand. These organizations already understand PERM timelines and are more likely to absorb the multi-year sponsorship commitment without hesitation.
Use Migrate Mate to find green card sponsoring employers
Searching for PAM jobs and filtering by green card sponsorship history saves weeks of manual research. Migrate Mate surfaces employers who have filed PERM applications for cybersecurity and identity management roles, so you can prioritize outreach to organizations already in the pipeline.
Verify your role qualifies under the right EB category
PAM architect and senior engineer roles typically require a master's degree or equivalent, supporting EB-2 eligibility, while analyst and specialist positions often qualify under EB-3. Review the O*NET occupation profile for your specific title before your employer begins the PERM process.
Ask about prevailing wage level during offer negotiations
DOL assigns a wage level to your PERM application based on experience and duties. If your offered salary falls below the certified prevailing wage, USCIS can deny the I-140 petition. Check your title against the OFLC Wage Search so you negotiate with accurate benchmarks.
Clarify sponsorship scope before your employer files
PERM locks in a specific job description, work location, and employer entity. If your role shifts to a different team, site, or subsidiary after filing but before your green card is approved, your employer may need to restart the entire labor certification process from scratch.
Green Card Privileged Access Management: Frequently Asked Questions
Do Privileged Access Management roles typically qualify for EB-2 or EB-3 green card sponsorship?
Both categories apply depending on the specific position. PAM architects and senior engineers who require a master's degree or equivalent specialized experience often qualify for EB-2. Analysts, specialists, and administrators with a bachelor's degree in computer science or information security typically qualify under EB-3 as skilled workers. Your employer's job description and the DOL prevailing wage determination define which category fits your role.
How does green card sponsorship differ from H-1B sponsorship for PAM professionals?
The H-1B visa is a temporary work visa requiring renewal and subject to annual lottery caps, while PERM-based green card sponsorship leads to permanent residency with no annual cap concern at the EB-3 level for most nationalities. The tradeoff is timeline: PERM labor certification alone takes six to twelve months before your employer can file the I-140 petition, making an early conversation with your employer about sponsorship intent critical.
What does the PERM labor certification process involve for cybersecurity roles like PAM?
PERM requires your employer to conduct a good-faith recruitment campaign demonstrating no qualified U.S. worker is available for the position. For PAM roles, this means advertising the specific job title, duties, and minimum qualifications. DOL audits cybersecurity positions with some frequency given their demand, so your employer must keep thorough recruitment records. The certified PERM then supports your I-140 immigrant petition filed with USCIS.
How can I find employers already willing to sponsor green cards for PAM roles?
Migrate Mate aggregates PERM filing data so you can identify companies that have already sponsored cybersecurity and identity management roles through the green card process. This matters because employer willingness to commit to a multi-year PERM sponsorship is the single biggest variable in whether you get a green card offer alongside a job offer.
Can my employer start PERM while I'm still on an H-1B for a PAM position?
Yes, and starting early is strongly advisable. PERM can be filed regardless of your current visa status. If you're on an H-1B that is approaching its six-year cap limit, having an approved I-140 on file before that deadline can unlock H-1B extensions in one-year increments under AC21 portability rules, protecting your work authorization while your green card case matures.