Talent.com
Privileged Access Management (PAM) Engineer
Privileged Access Management (PAM) EngineerInterSources • NYC, NY, US
Privileged Access Management (PAM) Engineer

Privileged Access Management (PAM) Engineer

InterSources • NYC, NY, US
[job_card.30_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

Overview


We are seeking a skilled Privileged Access Management (PAM) Engineer to join our cybersecurity team. This role will focus on securing privileged identities across Active Directory (AD), Entra ID, Linux, and major cloud platforms (Azure, AWS, and GCP). The PAM Engineer will design, implement, and maintain controls that ensure administrators and endpoints only have the access they need—at the right time and with the least privilege possible.
The ideal candidate will have strong expertise in vaulting platforms, endpoint privilege management, and zero-trust principles, with a proven track record of reducing attack surfaces and improving identity hygiene.

KEY RESPONSIBILITIES

Privileged Identity Security
- Administer and enhance the corporate vaulting platform to manage privileged credentials across AD, Entra, Linux, and cloud platforms (Azure, AWS, GCP).
- Implement credential randomization for local/built-in administrator accounts, service accounts, and cloud root/admin accounts.
- Ensure time-bound, approval-based access for administrators following least privilege and just-in-time (JIT) principles.

Endpoint Privilege Management
- Implement and maintain endpoint least-privilege policies across Windows, Linux, and macOS environments.
- Replace standing local admin rights with controlled privilege elevation workflows.
- Apply application control and privilege granularity to reduce risks from malware, ransomware, and insider threats.
- Partner with desktop engineering teams to improve usability while enforcing strong endpoint controls.

Identity Hardening & Hygiene
- Lead local administrator cleanup projects and enforce removal of unauthorized admin rights.
- Harden Entra ID and cloud tenant hygiene by monitoring stale accounts, privileged roles, and excessive permissions.
- Apply ITDR (Identity Threat Detection & Response) practices to detect and mitigate suspicious privileged activity across on-prem and cloud platforms.

Security Architecture & Standards
- Contribute to enterprise Zero Trust architecture initiatives for hybrid and multi-cloud environments.
- Align privileged access controls with NIST standards and organizational policies.
- Drive adoption of passwordless authentication, MFA, and SSO for both on-prem and cloud privileged identities.

Cloud Identity & Access
- Manage and monitor privileged roles and accounts in Azure AD (Entra ID), AWS IAM, and GCP IAM.
- Implement least-privilege design for cloud workloads, service principals, keys, and secrets.
- Integrate cloud platform identities with PAM vaulting, session recording, and access approval workflows.

Identity Lifecycle Management
- Collaborate with IGA teams to automate provisioning, deprovisioning, and recertification of privileged accounts across on-prem and cloud.
- Ensure privileged entitlements are tied to clear business justification and ownership.

Documentation & Governance
- Create and maintain technical runbooks, architecture diagrams, and operational procedures.
- Provide reporting on privileged access usage, endpoint privilege management, hygiene metrics, and compliance results.
- Partner with audit, compliance, and risk teams to demonstrate control effectiveness.

Required Qualifications
- 3–5+ years of experience in PAM, IAM, or related security engineering roles.
- Hands-on experience with AD, Entra ID, Linux, and at least one major cloud platform (Azure, AWS, or GCP).
- Strong knowledge of vaulting technologies and endpoint privilege management practices (least privilege, privilege elevation, application control).
- Proficiency with authentication methods: MFA, SSO, passwordless, Kerberos, and certificate-based access.
- Familiarity with NIST 800-63B, Zero Trust frameworks, ITDR, and cloud security standards (CIS, CSA, etc.).
- Strong scripting/automation skills (PowerShell, Python, Bash, Terraform, etc.).
- Excellent documentation and communication abilities.

Preferred Qualifications
- Experience securing privileged access in multi-cloud environments (Azure, AWS, GCP).
- Knowledge of Entra ID Conditional Access, PIM, AWS IAM policies, and GCP IAM roles.
- Experience integrating PAM solutions with CI/CD pipelines, DevOps tools, or ITSM workflows.

Success in This Role Looks Like
- Reduction of standing local administrator rights and adoption of endpoint least-privilege controls.
- Demonstrated adoption of MFA, passwordless, vault-based workflows, and privilege elevation.
- Improved audit and compliance posture with clear reporting of privileged activity and endpoint control enforcement.
- Measurable reduction in attack surface through consistent identity hygiene and lifecycle management.

[job_alerts.create_a_job]

Privileged Access Management (PAM) Engineer • NYC, NY, US

[internal_linking.similar_jobs]

Director, Access & Pricing (UK and US-based)

Genesis Research LLCHoboken, NJ, United States
[job_card.full_time]

Genesis Research Group (GRG) is an international real-world evidence (RWE) and health economics & outcomes research (HEOR) consultancy providing end-to-end value evidence development, optimization ...[internal_linking.show_more]

 • [job_card.promoted]

Cloud Enterprise Architect - AWS/Azure & Secure Coding

TechDigital GroupSecaucus, NJ, United States
[job_card.full_time]

An established industry player is seeking a seasoned Technical Architect with over a decade of experience in cloud platforms, particularly AWS.This role emphasizes the importance of secure coding p...[internal_linking.show_more]

 • [job_card.promoted] • [job_card.new]

ML Infra Engineer — Remote, Scalable Pipelines

algojobsNew York, NY, United States
[filters.remote]
[job_card.full_time]

A leading research organization is seeking a Software Engineer to develop sophisticated machine learning infrastructures.This role involves collaborating closely with Data Scientists, optimizing ma...[internal_linking.show_more]

 • [job_card.promoted]

IAM SME / Tech PM

VISTRADANew York City, NY, US
[job_card.full_time]
[filters_job_card.quick_apply]

Vistrada is seeking a highly motivated and experienced candidate to serve as a Subject Matter Expert (SME) / Tech PM on Identity & Access Management (IAM) planning and implementation engagements su...[internal_linking.show_more]

CA IAM Engineer

OpenkyberNY, United States
[job_card.full_time]
[filters_job_card.quick_apply]

Role- ForgeRock Developer Location - New York, NY Job type- Fulltime Job description Below Key Responsibilities Design, configure and implement ForgeRock Identity platform components such as ForgeR...[internal_linking.show_more]

Remote Founding Protocol Engineer - THORChain

Blockchain WorksBronx, NY, United States
[filters.remote]
[job_card.full_time]

THORChain is a settlement layer that facilitates swaps between Bitcoin, Ethereum, BNB Chain, Avalanche, Cosmos Hub, Dogecoin, Bitcoin Cash and Litecoin.THORChain is secured by its native token, RUN...[internal_linking.show_more]

 • [job_card.promoted]

AI Engineer, Business Operations

SK Life ScienceParamus, New Jersey, United States
[job_card.full_time]

AI Engineer, Business Operations.In this role, you will take AI models developed by AI Scientists and transform them into scalable, productionready applications by designing inference pipelines, AP...[internal_linking.show_more]

 • [job_card.promoted]

Epic Security Architect – IAM & Compliance Lead

Quest DiagnosticsSecaucus, NJ, United States
[job_card.full_time]

A health services provider is seeking a Senior Security Specialist to manage security applications and ensure compliance within the organization.The candidate will have a Bachelor’s degree in Techn...[internal_linking.show_more]

 • [job_card.promoted]

IAM Architect

TekNavigators StaffingNew York, NY, United States
[job_card.full_time]

Brooklyn NY - 3 days onsite and 2 days remote.IAM architect, engineering, administration and operations with focus on directory services and PKI.Deep expertise in Active Directory (on-prem and hybr...[internal_linking.show_more]

 • [job_card.promoted]

Pricing & Market Access Project Lead

ClearView Healthcare PartnersNew York, New York, United States
[job_card.full_time]

A leading healthcare consulting firm is seeking a Consulting Project Team Lead to manage multiple pricing and market access projects.This role requires 5-7 years of life sciences consulting experie...[internal_linking.show_more]

 • [job_card.promoted] • [job_card.new]

Solution Architect - Generative AI

Helix Tech IT ServicesVillage of Tarrytown, NY, United States
[job_card.full_time] +1

Be among the first 25 applicants.Direct message the job poster from Helix Tech IT Services.The ideal candidate will play a pivotal role in architecting scalable, secure, and efficient applications ...[internal_linking.show_more]

 • [job_card.promoted]

Senior EUC Partner Solutions Architect - GTM

AmazonNew York, NY, United States
[job_card.full_time]

A leading cloud computing company is seeking a Partner Solutions Architect based in New York.This role focuses on establishing AWS End User Computing as a market leader, engaging with partners and ...[internal_linking.show_more]

 • [job_card.promoted]

AWS Data Architect

E-SolutionsVillage of Tarrytown, NY, United States
[job_card.full_time]

Tarrytown NY 10591 (100% Onsite).Spark, PySpark, AWS Redshift, Airflow, EMR, Python.Candidate should have strong 12+ Years of experience in data engineering architecture for large-scale platforms.C...[internal_linking.show_more]

 • [job_card.promoted]

ACH Compliance Specialist

Valley National BancorpClifton, NJ, United States
[job_card.full_time]

Responsibilities include, but are not limited to:.Specializes in ACH Compliance ensuring proper file delivery and accurate processing with Third Party Senders, as well as all Originators, who are a...[internal_linking.show_more]

 • [job_card.promoted]

Identity and Access Management Data Engineer III

Capital GroupNew York, New York, United States
[job_card.full_time]

We want you to feel comfortable doing great work and bringing your best, authentic self to everything you do.We value your talents, traditions, and uniqueness-and we're committed to fostering a str...[internal_linking.show_more]

 • [job_card.promoted] • [job_card.new]

C-UAS Engineer

LMI Consulting, LLCNew York, New York, United States
[job_card.full_time]

Salaried High Fringe/Full-Time.Candidates should have strong project management abilities to lead planning and execution of test and evaluation and C-UAS projects for our DHS client in collaboratio...[internal_linking.show_more]

 • [job_card.promoted]

Oracle Cloud Tech Director – ERP/EPM & Integration Leader

Huron Consulting GroupNew York, NY, United States
[job_card.full_time]

A leading global consultancy is seeking a Technical Director based in New York to drive technical solutions and lead a high-performing team.The ideal candidate should have substantial experience in...[internal_linking.show_more]

 • [job_card.promoted]

Senior Enterprise Architect - Health IT & Security Roadmap

Siemens HealthineersVillage of Tarrytown, NY, United States
[job_card.full_time]

A leading health technology company is seeking an experienced Enterprise Architect in New York to drive IT architecture solutions and ensure alignment with business strategies.The role requires at ...[internal_linking.show_more]