PAM Engineer
$130,000–$160,000 year
HybridWashington, District of Columbia, United States or Washington, United States
Job Summary
Lead the design, implementation, and ongoing management of privileged access management solutions across hybrid environments. Deploy and administer enterprise PAM platforms like CyberArk, Delinea, or Keeper, securing service and admin accounts through vaulting, rotation, and session monitoring. Enforce least-privilege and Just-In-Time access policies while integrating with Entra ID and Active Directory to enable centralized governance. Develop automation scripts using PowerShell or Python to streamline operations and perform regular access certifications and audit reporting. Establish break-glass procedures and collaborate with security teams to monitor privileged account activity, ensuring strong authentication methods such as FIDO2 are enforced.
Required Qualifications
- 5+ years of experience in identity and access management
- at least 3 years focused on privileged access management
- Hands-on experience administering an enterprise PAM platform
- Strong understanding of least-privilege principles
- Strong understanding of Zero Trust architecture
- Strong understanding of privileged access best practices
- Experience integrating PAM solutions with Entra ID
- Experience integrating PAM solutions with Active Directory
- Experience integrating PAM solutions with SIEM platforms
- Proficiency in PowerShell
- Proficiency in Python
- Bachelor's degree in Computer Science
- Bachelor's degree in Information Technology
- Bachelor's degree in Cybersecurity
- Bachelor's degree in a related field
- equivalent hands-on experience
- Ability to obtain a Public Trust clearance
- U.S. citizenship
Desired Qualifications
- Direct experience with Keeper
- Familiarity with NIST SP 800-53
- Familiarity with FISMA
- Familiarity with federal identity guidelines
- Knowledge of federal compliance frameworks including FedRAMP
- Knowledge of applicable CISA guidance
- Experience supporting ATO processes
- Experience documenting PAM controls within System Security Plans
- Experience in cloud/GovCloud environments
- Experience with Azure
- Experience with AWS
- Relevant certifications (e.g., CISSP, Security+, CyberArk Defender/Sentry)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.