- Company Name
- ASK Consulting
- Job Title
- Privileged Access Management (PAM) Platform Sr Engineer
- Job Description
-
**Job Title**
Privileged Access Management (PAM) Platform Senior Engineer
**Role Summary**
Lead the design, deployment, and ongoing management of enterprise‑wide PAM solutions across Windows, macOS, and Linux environments. Serve as the primary technical expert, ensuring secure privileged account handling, compliance, and integration with existing security and ITSM tools.
**Expectations**
- Deliver end‑to‑end PAM implementations for large‑scale organizations.
- Maintain high security posture, compliance with standards (e.g., PCI DSS).
- Act as the go‑to advisor on PAM architecture, policy, and automation.
**Key Responsibilities**
- Architect, deploy, and optimize PAM platforms (CyberArk, BeyondTrust, Delinea).
- Design privileged account discovery, credential rotation, session monitoring, and access request workflows.
- Integrate PAM with ITSM, SIEM, vulnerability scanners, directories, and cloud IAM services.
- Develop and enforce privilege elevation policies, audit trails, and compliance controls.
- Provide advanced troubleshooting, performance tuning, and user onboarding support.
- Create technical documentation, procedures, and training materials for internal stakeholders.
- Evaluate new features, monitor platform health, and recommend continuous improvement.
**Required Skills**
- 4–6+ years of hands‑on PAM implementation in enterprise settings.
- Deep expertise in privileged account discovery, password vaults, session management, and access workflows.
- Strong Windows Server, Active Directory, Group Policy, and PowerShell scripting knowledge.
- Linux/Unix system administration and shell scripting proficiency.
- Networking fundamentals (protocols, ports, certificates, load balancing).
- Cloud platform experience (AWS, Azure) and containerization (Docker, Kubernetes).
- Knowledge of identity protocols (SAML, OIDC, OAuth, SCIM, LDAP).
- Scripting: PowerShell, Bash, Python.
**Preferred Skills**
- Experience with multiple PAM vendors and migration projects.
- DevOps, CI/CD, and IaC (Terraform, Ansible).
- ITSM integration (ServiceNow, Jira) for ticket‑driven privileged access.
- SIEM integration (Splunk, QRadar).
- Zero‑trust and least‑privilege principles.
- Secrets management (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault).
- Retail technology or large‑enterprise deployment background.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Technology, or related field.
- Vendor certification in a major PAM platform (e.g., CyberArk Certified Delivery Engineer, BeyondTrust Certified Implementation Engineer, Delinea Certified Professional).
- Optional industry certifications (CISSP, CISM, relevant cloud security).