H-1B Visa Privileged Access Management Jobs
Privileged Access Management roles qualify as H-1B visa specialty occupations under the Information Security Analysts SOC code, requiring at least a bachelor's degree in cybersecurity, computer science, or a related field. Financial services, healthcare systems, and enterprise tech firms file LCAs regularly for PAM engineers and architects, making this one of the more consistently sponsored cybersecurity disciplines.
Find H-1B Visa Privileged Access Management JobsOverview
Showing 5 of 7+ Privileged Access Management jobs










See all Privileged Access Management Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Privileged Access Management roles.
Get Access To All Jobs
INTRODUCTION
Join Mizuho as Privileged Access Management Engineer! Mizuho’s Identity and Access Management (IAM) team is undergoing an exciting transformation. We're building a dedicated high performing IAM function that is central to the firm's cybersecurity and regulatory strategy. Our environment is dynamic, growing, and rich with opportunity. You’ll work alongside a talented group of professionals who are passionate about solving complex access challenges, automating at scale, and strengthening security posture across both on-premises and cloud environments. This is a unique chance to join our team that's shaping the future of IAM at a major financial institution. We are seeking a CyberArk Engineer to support the implementation, operation, and ongoing management of our Privileged Access Management (PAM) platform. The role is responsible for securing privileged and service accounts, ensuring compliance with security standards, and supporting enterprise users and applications. This hands-on engineering role focuses on delivering secure and scalable solutions for managing privileged accounts used by servers, applications, services, APIs, and cloud workloads. The ideal candidate has deep expertise in CyberArk and related technologies. This role is critical to strengthening the firm's identity security posture, enabling secure cloud adoption, and supporting compliance with regulatory and internal control requirements.
KEY RESPONSIBILITIES
Core CyberArk / PAM Engineering:
- Design, implement, and maintain CyberArk Privileged Access Management (PAM) solutions to secure privileged, service, and application accounts across enterprise environments.
- Configure and manage CyberArk components including Digital Vault, PVWA, CPM, PSM, and connectors (Windows, Unix, Database, Cloud where applicable).
- Create and manage safes, platforms, access policies, and permissions in accordance with least-privilege and security standards.
- Build automations to support the core PAM activities.
Privileged Account Onboarding & Lifecycle Management:
- Lead onboarding of privileged and service accounts into CyberArk, including inventory validation, account vaulting, and enabling password rotation.
- Work closely with infrastructure and application teams to identify dependencies and ensure password changes do not disrupt services.
- Manage account lifecycle activities such as modifications, offboarding, and exception handling.
Password & Session Management:
- Implement and monitor automated password rotation and reconciliation for managed accounts.
- Configure and support Privileged Session Management (PSM) for secure access and session recording.
- Troubleshoot password rotation failures, access issues, and CPM/PSM errors.
Operations, Monitoring & Support:
- Provide L2/L3 operational support, including root-cause analysis and coordination with vendors or internal teams.
- Maintain and update runbooks, SOPs, and operational documentation for CyberArk processes.
Compliance, Audit & Governance:
- Support audit and regulatory requirements by generating CyberArk reports, access certifications, and compliance evidence.
- Participate in periodic privileged access recertifications and remediation of findings.
- Ensure CyberArk configurations align with IAM standards, internal policies, and regulatory frameworks (e.g., SOX, ISO, internal audits).
Integration & Automation:
- Integrate CyberArk with IAM tools (e.g., SailPoint), Active Directory, ServiceNow and other enterprise applications.
- Support use of CyberArk REST APIs and Central Credential Provider (CCP) for application integrations and automation.
- Assist with automation and reconciliation processes related to privileged account discovery and onboarding.
Stakeholder Collaboration:
- Act as a subject-matter expert (SME) for CyberArk/PAM, advising application, infrastructure, and security teams.
- Coordinate with IAM Governance, Risk, Compliance, and Audit teams on PAM-related initiatives.
- Participate in design and architecture discussions to identify gaps and drive scalable, automation-friendly improvements.
PREFERRED QUALIFICATIONS
- Experience with cloud PAM (AWS, Azure, GCP)
- Scripting (PowerShell, Python) for automation
- CyberArk certifications (CPC, CDE, Defender)
BASIC QUALIFICATIONS
- 7+ years of experience in Identity & Access Management, cybersecurity engineering, or related infrastructure security roles, with a strong focus on Privileged Access Management.
- Demonstrated experience with CyberArk.
- Experience in enterprise environments (Windows, Unix, databases, service accounts).
- Familiarity with security controls and regulatory expectations related to identity, credential, and Privileged Access Management (e.g., SOX, NIST).
- Strong collaboration and communication skills, with the ability to work effectively across infrastructure, cloud, security, and DevOps teams.
The expected base salary ranges from $81,000 - $150,000. Salary offers are based on a wide range of factors including relevant skills, training, experience, education, and, where applicable, certifications and licenses obtained. Market and organizational factors are also considered. In addition to salary and a generous employee benefits package, including Medical, Dental and 401K plans, successful candidates are also eligible to receive a discretionary bonus.
OTHER REQUIREMENTS
Mizuho has in place a hybrid working program, with varying opportunities for remote work depending on the nature of the role, needs of your department, as well as local laws and regulatory obligations. Roles in some of our departments have greater in-office requirements that will be communicated to you as part of the recruitment process.
COMPANY OVERVIEW
Mizuho Financial Group, Inc. is the 15th largest bank in the world as measured by total assets of ~$2 trillion. Mizuho's 60,000 employees worldwide offer comprehensive financial services to clients in 35 countries and 800 offices throughout the Americas, EMEA and Asia. Mizuho Americas is a leading provider of corporate and investment banking services to clients in the US, Canada, and Latin America. Through its acquisition of Greenhill, Mizuho provides M&A, restructuring and private capital advisory capabilities across Americas, Europe and Asia. Mizuho Americas employs approximately 3,500 professionals, and its capabilities span corporate and investment banking, capital markets, equity and fixed income sales & trading, derivatives, FX, custody and research.
Mizuho Americas offers a competitive total rewards package. We are an EEO/AA Employer - M/F/Disability/Veteran. We participate in the E-Verify program. We maintain a drug-free workplace and reserve the right to require pre- and post-hire drug testing as permitted by applicable law.
See all H-1B Visa Privileged Access Management Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new H-1B Visa Privileged Access Management Jobs.
Get Access To All JobsTips for Finding H-1B Visa Sponsorship in Privileged Access Management
Verify your SOC code before applying
PAM roles are typically filed under SOC 15-1212 (Information Security Analysts). Check O*NET to confirm the job zone and degree requirements match your credentials before you apply, so your qualifications align with what the LCA certifies.
Target employers with PERM-track cybersecurity hiring
Companies that file PERM labor certifications for security roles signal long-term sponsorship intent. Use Migrate Mate to filter employers with active H-1B LCA filings in information security, so you're targeting sponsors, not just open roles.
Document your PAM tooling expertise specifically
When your H-1B petition lists specialty occupation, USCIS scrutinizes whether the role requires a specialized degree. List specific platforms you've administered, such as CyberArk, BeyondTrust, or Delinea, to reinforce the technical depth of your position.
Check prevailing wage before negotiating your offer
Your employer's LCA must certify a wage at or above the DOL prevailing wage for your location and SOC code. Run the OFLC Wage Search for your metro area before accepting an offer, so you know the floor your employer is legally obligated to meet.
Time your H-1B filing around your OPT cap-gap window
If you're on F-1 OPT, your employer must file the H-1B petition by the April 1 cap-subject deadline. A timely USCIS receipt notice triggers the cap-gap extension, letting you keep working through September 30 without a gap in authorization.
Confirm E-Verify enrollment if your role is STEM-adjacent
PAM roles at government contractors or regulated financial institutions often require E-Verify enrollment as a condition of employment. Confirm your employer is enrolled before your start date, since E-Verify status affects your eligibility for certain security clearances tied to these roles.
H-1B Visa Privileged Access Management: Frequently Asked Questions
Does a Privileged Access Management role qualify as an H-1B specialty occupation?
Yes. PAM roles qualify under the Information Security Analysts SOC code, which USCIS recognizes as a specialty occupation requiring at least a bachelor's degree in cybersecurity, computer science, or a directly related field. Roles that involve designing or administering PAM architecture carry the technical complexity USCIS looks for when evaluating specialty occupation status.
Which industries sponsor H-1B visas most consistently for PAM professionals?
Financial services, healthcare systems, federal contractors, and large enterprise technology firms file H-1B LCAs for PAM engineers and architects with regularity. These sectors handle sensitive data under strict compliance frameworks, which drives sustained demand for PAM expertise and makes them more likely to sponsor. You can filter by industry on Migrate Mate to find employers with verified H-1B filing history in this discipline.
How does the H-1B prevailing wage requirement apply to PAM roles?
Your employer must file an LCA certifying they'll pay you at or above the DOL prevailing wage for your SOC code and work location. PAM architects typically fall into higher wage levels than junior analysts, so the certified wage must reflect your actual seniority. Use the OFLC Wage Search to look up the wage level for your metro area before your offer letter is finalized.
Can I switch employers mid-H-1B if I find a better PAM role?
Yes, H-1B portability under AC21 lets you start working for a new employer as soon as they file an H-1B transfer petition, provided your original petition has been approved and you've maintained valid status. You don't need to wait for the transfer to be approved to begin the new role, but the new employer's petition must be filed before you switch.
Does holding a security clearance affect my H-1B sponsorship for PAM positions?
Security clearances are adjudicated separately from visa status, and many clearance-required PAM roles at federal contractors are off-limits to H-1B holders without existing clearances. Focus on positions that require a clearance eligibility review rather than an active clearance, or target commercial employers where clearance isn't a prerequisite. USCIS does not factor clearance status into H-1B adjudication.