The Senior Engineer - Privileged Access Management (PAM) will be responsible for implementing, operating, and optimizing enterprise PAM platforms across both self-hosted and cloud deployments. This role will partner with infrastructure, IAM, security operations, and application teams to deliver secure privileged access controls, maintain platform reliability, and execute automation to improve operational efficiency. The ideal candidate has hands-on expertise across multiple PAM tools such as CyberArk, Delinea, and Segura etc., with strong troubleshooting capabilities, connector development experience, and scripting proficiency.
Key Responsibilities
- Design, implement, and onboard privileged accounts, systems, and applications into PAM solutions across self-hosted and SaaS environments.
- Execute end-to-end PAM deployments including architecture, build, configuration, integration, and go-live support.
- Integrate PAM solutions with directories and identity services (eg, Active Directory/LDAP, SSO, MFA) and align configurations with security standards.
- Implement and maintain credential vaulting, password rotation, session management, privileged session recording, and just-in-time access workflows.
- Own BAU operations for PAM platforms including monitoring, patching/upgrades, certificate management, and capacity planning.
- Manage platform health, availability, and performance; respond to incidents and service requests with defined SLAs.
- Perform regular access reviews, safe/vault governance support, and audit evidence collection for compliance requirements.
- Maintain operational documentation, SOPs/runbooks, and knowledge articles.
- Troubleshoot complex PAM issues across components (vault, session manager, connector/integration layers, agents, proxies) and coordinate vendor support as needed.
- Perform root cause analysis, implement corrective actions, and drive problem management to prevent recurrence.
- Support onboarding failures, rotation errors, session issues, connectivity/authentication problems, and policy misconfigurations.
- Develop and maintain custom connectors/integrations for account onboarding and password rotation (eg, REST/API-based, CLI-based, or platform SDK-based connectors).
- Implement and support integrations with ticketing systems (eg, ServiceNow), SIEM/SOAR, and monitoring platforms.
- Contribute to standard patterns for onboarding and connector reuse across platforms and business units.
- Build automation for onboarding, password rotation validation, reporting, and routine operational tasks using PowerShell and shell scripting.
Required Qualifications
- 5 years of hands-on experience in Privileged Access Management engineering and operations.
- Experience with one / multiple PAM technologies such as CyberArk, Delinea (Thycotic/Secret Server), Segura, or equivalent platforms.
- Proven experience with both self-hosted and cloud/SaaS PAM implementations.
- Strong troubleshooting skills across infrastructure, authentication, network connectivity, and PAM platform components.
- Hands-on experience with custom connector development and/or API integrations.
- Strong scripting and automation capability in PowerShell and shell scripting (Bash).
- Working knowledge of Windows/Linux administration fundamentals, AD/LDAP concepts, and networking basics (DNS, certificates, ports, proxies, TLS).
Preferred Qualifications