Job Description

Company Description

About us:

Passion for food. Hunger for tech. We make METRO digital.

Today technology is driving the world. And at METRO.digital we are driving the technology for one of the leading international wholesalers specializing in food - METRO. From e-commerce to checkout, to delivery software, we work on a wide range of products to make each day a success for our customers and colleagues. With passion and ownership, we build the future of wholesale.

You are driving to create smart solutions for customers around the globe? You want to grow in a flexible environment? Let the right career opportunity find you and join us!

Job Description

Solution Architect – Microsoft Entra ID, Active Directory & CyberArk PAM

Role Summary

We are seeking an experienced Solution Architect to define and drive the identity and privileged access management (PAM) architecture across a hybrid Microsoft Entra ID and On‑Prem Active Directory environment, with deep expertise in CyberArk PAM solutions.

This role owns the end‑to‑end design, integration, and governance of identity and privileged access controls, ensuring alignment with enterprise IAM strategy, Zero Trust principles, and regulatory requirements. The architect will work closely with IAM engineers, security teams, infrastructure, application owners, and DevOps teams to deliver secure, scalable, and compliant solutions.

Key Responsibilities

Identity & Access Architecture (Entra ID & Active Directory)

  • Define and own the hybrid identity architecture across Microsoft Entra ID and On‑Prem Active Directory
  • Design secure authentication and authorization models:
    • Conditional Access
    • MFA and authentication strengths
    • Passwordless authentication (FIDO2, Windows Hello for Business)
  • Define hybrid identity patterns including Entra Connect and authentication models
  • Establish identity standards and guardrails aligned with Zero Trust architecture

Privileged Access Management (CyberArk)

  • Define and drive Privileged Access Management (PAM) architecture using CyberArk, aligned with the enterprise IAM strategy
  • Lead the design and implementation of privileged access controls across:
    • Servers
    • Endpoints
    • Databases
    • Applications
  • Integrate PAM with Access Management capabilities:
    • SSO
    • MFA
    • Microsoft Entra ID
  • Integrate CyberArk with the broader enterprise security ecosystem, including:
    • SIEM platforms
    • ITSM tools
  • Define and enforce least privilege and Zero Trust principles across infrastructure and endpoints
  • Drive secrets management strategy for applications using:
    • CyberArk Conjur
    • CyberArk CCP
  • Collaborate with application, infrastructure, and DevOps teams to enable secure credential management and automation
  • Provide architectural guidance for CyberArk EPM‑based endpoint privilege control

Solution Design & Integration

  • Design secure integrations between:
    • Entra ID
    • Active Directory
    • CyberArk PAM platforms
    • On‑prem, cloud, and SaaS applications
  • Define application onboarding patterns:
    • SSO and federation
    • Privileged access flows
    • Secrets consumption models
  • Ensure solutions are scalable, resilient, and auditable

Architecture, Strategy & Governance

  • Define the PAM roadmap and maturity model, aligned with IAM and enterprise security strategy
  • Establish standards for:
    • Privileged account onboarding
    • Password rotation
    • Session recording and monitoring
  • Drive risk reduction initiatives, including:
    • Removal of standing administrative access
    • Credential hardening
  • Ensure audit readiness and compliance for privileged access:
    • SOX
    • ISO
    • GDPR
  • Participate in threat modeling, security reviews, and risk assessments

Leadership & Collaboration

  • Act as the design authority for identity and PAM solutions
  • Partner with:
    • IAM and PAM engineering teams
    • Security architecture
    • Cloud and infrastructure teams
    • Application owners
  • Review and approve technical designs and implementations
  • Provide architectural guidance and mentorship to senior engineers

Required Skills & Expertise

CyberArk & PAM

  • Strong expertise in CyberArk PAS, EPM, CCP, and Conjur
  • Deep understanding of privileged access risks, controls, and governance models
  • Hands‑on experience designing and integrating PAM solutions at enterprise scale

Microsoft Identity

  • Microsoft Entra ID (P2)
  • Conditional Access and Identity Protection
  • Privileged Identity Management (PIM)
  • Entra Connect and hybrid authentication
  • Active Directory security and tiered admin models

Operating Systems & Platforms

  • Strong knowledge of:
    • Windows privilege models
    • Unix/Linux privilege models
    • Active Directory security concepts

Automation & Integration

  • Hands‑on experience with automation and integration using:
    • REST APIs
    • PowerShell
    • Python
  • Experience integrating PAM into CI/CD and automated workflows

Security & Architecture

  • Zero Trust architecture
  • Least privilege enforcement
  • Identity‑based and privileged access attack techniques and mitigations

Nice to Have

  • Exposure to cloud PAM use cases across:
    • Azure
    • AWS
    • GCP
  • Experience with DevOps and cloud‑native environments
  • CyberArk certifications:
    • Sentry
    • CDE
  • Microsoft security certifications (SC‑300, AZ‑500)
  • CISSP or equivalent

Qualifications

Graduation OR Post Graduation

Share this job:
Please let METRO AG know you found this job on Remote First Jobs 🙏

210 similar remote jobs

Explore latest remote opportunities and join a team that values work flexibility.

Remote companies like METRO AG

Find your next opportunity with companies that specialize in Wholesale, Retail Property, Food, and Horeca. Explore remote-first companies like METRO AG that prioritize flexible work and home-office freedom.

Relais & Châteaux Logo

Relais & Châteaux

An association of 580 independent luxury hotels and restaurants worldwide, established in 1954.

View company profile →
Belmond Logo

Belmond

5001-10000 www.belmond.com

Operates a global collection of luxury hotels, trains, river cruises, and safaris across 24 countries and territories.

View company profile →
Walgreens Boots Alliance Logo

Walgreens Boots Alliance

An integrated healthcare, pharmacy, and retail leader serving customers and patients globally.

View company profile →
FreshRealm Logo

FreshRealm

1001-5000 freshrealm.co

A Food-as-a-Service (FaaS) company providing back-end solutions and a fresh food platform for food manufacturers.

View company profile →
Taco Bell Logo

Taco Bell

Global Mexican-inspired quick service restaurants, innovating with food and digital ordering solutions.

View company profile →
Eataly Logo

Eataly

5001-10000 www.eataly.com

A global marketplace for artisanal Italian food and beverages, featuring retail stores, restaurants, and cooking education.

View company profile →

Project: Career Search

Rev. 2026.6

[ Remote Jobs ]
Direct Access

We source jobs directly from 21,000+ company career pages. No intermediaries.

01

Discover Hidden Jobs

Unique jobs you won't find on other job boards.

02

Advanced Filters

Filter by category, benefits, seniority, and more.

03

Priority Job Alerts

Get timely alerts for new job openings every day.

04

Manage Your Job Hunt

Save jobs you like and keep a simple list of your applications.

21,000+ SOURCES UPDATED 24/7
Apply