- Company Name
- Levy Global
- Job Title
- IAM Engineer – Privileged Access & Secrets Management
- Job Description
-
**Job Title:** IAM Engineer – Privileged Access & Secrets Management
**Role Summary:**
Senior IAM Engineer responsible for designing, implementing, and operating enterprise privileged access management (PAM) systems, automating privileged account provisioning and credential lifecycles, and managing secrets across applications and infrastructure. Works closely with infrastructure, application, security, and compliance teams to enforce least‑privilege, just‑in‑time access, and secure secrets hygiene in regulated environments.
**Expectations:**
- Operate as a senior individual contributor with full ownership of PAM and secrets initiatives.
- Deliver automated, auditable privileged access onboarding, rotation, and deprovisioning pipelines.
- Ensure continuous improvement of IAM processes through documentation, automation, and governance.
- Provide rapid response to privileged access incidents and audit requirements.
**Key Responsibilities:**
1. Own and operate enterprise PAM platforms (e.g., CyberArk Vault, PSM/PSMP, CPM, Privilege Cloud).
2. Design, deploy, and maintain privileged access controls for Windows, Unix/Linux, and application environments.
3. Automate onboarding of privileged and service accounts, credential rotation, and reconciliation; enforce least privilege and JIT principles.
4. Monitor privileged sessions, investigate access‑related incidents, and support incident response.
5. Manage non‑human credentials: capture, rotate, and retrieve secrets for applications, services, and automation workflows.
6. Collaborate with engineering to eliminate hard‑coded secrets and improve secrets hygiene.
7. Integrate secrets management into CI/CD pipelines and support cloud (AWS, Azure) workloads.
8. Partner with infrastructure, application, and security teams to implement RBAC, access policy alignment, and secure access models across on‑prem and cloud platforms.
9. Maintain documentation, standards, operating procedures, and evidence for audits.
10. Drive governance, audit readiness, and continuous improvement of IAM/PAM processes.
**Required Skills:**
- Deep expertise in Privileged Access Management (PAM) platforms, especially CyberArk (Vault, PSM/PSMP, CPM, Privilege Cloud).
- Hands‑on experience automating privileged account onboarding and credential lifecycle using scripting, configuration management, or orchestration tools.
- Strong understanding of least privilege, just‑in‑time access, and privileged account risk management.
- Background in regulated or high‑security environments with proven governance and audit support.
- Comfortable forming and maintaining strong collaboration across infrastructure, application, security, and compliance domains.
**Nice to Have:**
- Experience with secrets management platforms and CI/CD integrations.
- Cloud experience (AWS, Azure).
- Scripting/automation proficiency (PowerShell, REST APIs, Python).
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field.
- Relevant certifications (e.g., CySA+, PMP, CISSP, CCSP, or equivalent PAM/identity security expertise) are desirable.