- Company Name
- InterSources Inc
- Job Title
- Privileged Access Management /IAM Engineer
- Job Description
-
Job Title: Privileged Access Management / IAM Engineer
Role Summary: Design, implement, and maintain privileged identity controls across Active Directory, Entra ID, Linux, and cloud platforms (Azure, AWS, GCP). Ensure least‑privilege, just‑in‑time (JIT) access, and zero‑trust principles for administrators and endpoints.
Expectations: Deliver measurable reduction of standing admin rights, improve MFA/passwordless adoption, and strengthen audit visibility. Collaborate cross‑functionally with desktop engineering, IGA, audit, and DevOps to enforce secure access policies and automate lifecycle management.
Key Responsibilities:
- Administer and enhance the corporate vaulting platform for privileged credentials across AD, Entra ID, Linux, and major cloud services.
- Configure credential randomization, time‑bound access, and approval workflows for local, service, and cloud root accounts.
- Implement endpoint least‑privilege policies on Windows, Linux, and macOS; replace standing admin rights with controlled elevation and application control.
- Lead local admin cleanup, enforce removal of unauthorized rights, and harden Entra ID and cloud tenant hygiene.
- Apply ITDR practices to detect and mitigate suspicious privileged activity on-prem and in the cloud.
- Contribute to Zero Trust architecture, aligning privileged access controls with NIST, CIS, CSA, and corporate standards.
- Drive adoption of MFA, SSO, passwordless authentication for privileged identities.
- Manage privileged roles in Azure AD (Entra ID), AWS IAM, and GCP IAM; integrate with PAM vaulting, session recording, and approval workflows.
- Automate provisioning, deprovisioning, and recertification of privileged accounts through IGA collaboration.
- Create and maintain runbooks, architecture diagrams, and operational procedures; provide usage, hygiene, and compliance reporting.
Required Skills:
- 3–5+ years PAM/IAM or security engineering experience.
- Expertise in AD, Entra ID, Linux, and at least one major cloud platform.
- Deep knowledge of vaulting technologies, endpoint privilege management, and application control.
- Proficiency with MFA, SSO, passwordless, Kerberos, certificate‑based access, and conditional access.
- Familiarity with NIST 800‑63B, Zero Trust, ITDR, and cloud security standards (CIS, CSA).
- Strong scripting/automation skills (PowerShell, Python, Bash, Terraform).
- Excellent documentation and communication abilities.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Security, or related field.
- Relevant certifications (e.g., CISSP, CISM, CCSP, Microsoft Certified: Azure Security Engineer Associate, AWS Certified Security – Specialty, or equivalent) preferred.
New york city, United states
Hybrid
15-11-2025