- Company Name
- TalentBurst, an Inc 5000 company
- Job Title
- Privileged Access Management (PAM) Platform Engineer
- Job Description
-
**Job Title:** Privileged Access Management (PAM) Platform Engineer
**Role Summary**
Technical specialist responsible for designing, deploying, and maintaining enterprise‑wide privileged access solutions. Leads large‑scale PAM implementations across Windows, macOS, Linux, and cloud environments while ensuring compliance, automation, and continuous improvement.
**Expectations**
- 4–6+ years of hands‑on PAM platform implementation and management.
- Vendor certifications in CyberArk, BeyondTrust, Delinea, or equivalent preferred.
- Proven ability to architect, secure, and support privileged account workflows in a large enterprise.
**Key Responsibilities**
- Lead PAM architecture, deployment, configuration, and optimization of password vaults and endpoint privilege management systems.
- Design and execute large‑scale PAM rollouts across diverse OS platforms, integrating with existing infrastructure.
- Develop and manage privilege elevation policies, credential rotation schedules, access request workflows, and governance rules.
- Integrate PAM with ITSM, SIEM, vulnerability scanners, directory services, and other security tools to create unified privileged access workflows.
- Provide expert technical support, troubleshoot performance issues, onboards privileged accounts, and manage user access requests.
- Ensure compliance with PCI DSS and other regulatory requirements through audit trails, session monitoring, and governance.
- Produce technical documentation, procedures, and training materials for internal stakeholders.
- Monitor platform performance, evaluate new features, and implement best practices for security posture and operational efficiency.
**Required Skills**
- Expertise in major PAM platforms (CyberArk, BeyondTrust, Delinea, PingOne Protect).
- Proficiency in Windows Server, Active Directory, Group Policy, PowerShell, Linux/Unix administration, shell scripting, and cross‑platform scripting (Bash, Python).
- Network fundamentals (protocols, ports, certificates, load balancing, security hardening).
- Cloud experience (AWS, Azure) and containerization (Docker, Kubernetes).
- Identity and access protocols (SAML, OIDC, OAuth, SCIM, LDAP) integration.
- Familiarity with DevOps practices, CI/CD, IaC (Terraform, Ansible).
- ITSM integration (ServiceNow, Jira) and SIEM tools (Splunk, QRadar) knowledge.
- Understanding of zero‑trust architecture, least privilege principles, and secrets management (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault).
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or equivalent technical discipline.
- Relevant vendor certifications (e.g., CyberArk Certified Delivery Engineer, BeyondTrust Certified Implementation Engineer, Delinea Professional).
- Industry certifications such as CISSP, CISM, or cloud security certifications are a plus.