- Company Name
- TekWissen ®
- Job Title
- Beyond Trust Engineer - PAM
- Job Description
-
**Job Title:** Beyond Trust Engineer – PAM
**Role Summary:**
Lead architecture, deployment, and ongoing management of enterprise Privileged Access Management (PAM) solutions using BeyondTrust. Design and implement large‑scale PAM across Windows, macOS, and Linux environments, integrate with ITSM, SIEM, and identity platforms, and ensure compliance with security standards such as PCI DSS.
**Expectations:**
- Deliver end‑to‑end PAM implementation for a global retail technology ecosystem.
- Maintain high‑availability, secure, and compliant privileged access controls.
- Troubleshoot complex PAM issues and optimize performance.
- Author technical documentation, procedures, and training materials.
**Key Responsibilities:**
- Serve as primary technical expert for PAM architecture, deployment, configuration, and optimization.
- Design and execute PAM deployments across large‑scale heterogeneous environments.
- Develop and enforce privilege elevation policies, credential rotation schedules, and access request workflows.
- Integrate PAM with ITSM, SIEM, vulnerability scanners, directory services, and cloud infrastructure.
- Provide expert support for privileged account onboarding, performance tuning, and incident response.
- Ensure audit trail, session recording, and privileged account governance meet PCI DSS and other regulatory requirements.
- Monitor platform performance, evaluate new features, and recommend best practices for continuous improvement.
**Required Skills:**
- 4‑6+ years managing enterprise PAM platforms (BeyondTrust, CyberArk, Delinea).
- Deep expertise in privileged account discovery, credential management, password rotation, session monitoring, and access request workflows.
- Proficiency in Windows Server, Active Directory, Group Policy, PowerShell; Linux/Unix administration, Bash.
- Networking knowledge (TCP/UDP, SSL/TLS, load balancing).
- Experience with cloud platforms (AWS, Azure) and container orchestration (Docker, Kubernetes).
- Understanding of identity protocols (SAML, OIDC, OAuth, SCIM, LDAP) and PAM integration.
- Scripting: PowerShell, Bash, Python; Configuration Management: Terraform, Ansible.
- Integration with ITSM (ServiceNow, Jira), SIEM (Splunk, QRadar), and vulnerability scanners.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Technology, or related field (or equivalent work experience).
- Vendor certification preferred: BeyondTrust Certified Implementation Engineer; CyberArk Certified Delivery Engineer; or similar PAM certification.
---