PAM Engineer
RemoteUnited States
Job Summary
Design, implement, and maintain enterprise Privileged Access Management solutions across on-premises, hybrid, and multi-cloud environments. Enforce least privilege access models, automate credential rotation, and configure session management with monitoring and audit capabilities. Integrate PAM platforms with identity providers, directories, cloud platforms, and security tools while developing technical specifications and operational procedures. Troubleshoot platform performance issues and incidents, then support compliance and risk management activities through accurate record-keeping and reporting. Partner with IAM, Information Security, and operations teams to identify risks and define PAM standards and roadmaps under leadership direction. Strengthen the security posture by delivering reliable services, reducing credential-related risk, and enabling secure access to critical systems through clear communication and effective collaboration.
Required Qualifications
- Hands-on experience supporting Privileged Access Management, Identity and Access Management, information security, or related security engineering functions.
- Experience with enterprise PAM platforms such as CyberArk, BeyondTrust, Delinea, Bravura Security, HashiCorp Vault, or similar technologies.
- Strong understanding of privileged account management, service account governance, secrets management, password vaulting, credential rotation, and access control principles.
- Experience integrating PAM solutions with directories, authentication services, servers, databases, applications, APIs, and cloud platforms.
- Working knowledge of Windows, Linux/Unix, databases, networking concepts, and common enterprise infrastructure patterns.
- Ability to develop clear technical documentation, operational runbooks, process flows, and stakeholder communications.
- Strong analytical, troubleshooting, collaboration, and communication skills.
Desired Qualifications
- Experience with PAM modernization, platform upgrades, disaster recovery planning, and operational resiliency improvements.
- Familiarity with cloud security and secrets management across Microsoft Azure, AWS, Google Cloud, or similar cloud environments.
- Experience with automation, scripting, APIs, CI/CD pipelines, or infrastructure-as-code practices.
- Knowledge of security frameworks, audit requirements, regulatory expectations, and compliance-driven access controls.
- Relevant certifications such as CISSP, Security+, CyberArk, BeyondTrust, Delinea, Microsoft Azure, AWS, or other security and cloud certifications.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.