Systems Engineer II - PAM
Core
Engineers and supports privileged and non-human identity controls across enterprise and cloud platforms, implementing lifecycle controls for service accounts, secrets, and certificates.
Role type
Systems Engineer II (Privileged Access Management)
Builds
Privileged Access Management (PAM) solutions, secrets management platforms, and certificate lifecycle automation.
Domain
Financial services security, cloud infrastructure, identity and access management (IAM)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
PAM platforms (Delinea, CyberArk), Secrets management tools (Vault, Secret Server), AWS IAM, Enterprise PKI/certificate management, Active Directory service accounts, RBAC/least privilege principles, JIT access concepts, Service/workload identity security, Scripting (PowerShell, Python, Bash), REST APIs, Network troubleshooting (TCP/IP, DNS, firewall)
Preferred skills
Dynamic secrets management, Workload identity, Cross-account trust design, Federated authentication, IGA platform governance, DevSecOps/CI/CD integration, Regulated environment compliance (PCI, SOX, NIST, ISO)
Technologies
Delinea, CyberArk, Vault, Secret Server, AWS IAM, Active Directory, PowerShell, Python, Bash
Responsibilities
Engineer and support PAM solutions including vaulting, session control, and Just-In-Time (JIT) privileged access; Administer secrets management platforms including credential onboarding and automated rotation; Support lifecycle management of non-human identities (provisioning, governance, deprovisioning); Support enterprise certificate lifecycle management (issuance, renewal, revocation); Participate in design, testing, and implementation of automation workflows; Provide operational support including system configuration, troubleshooting, and incident response; Produce reporting and analytics on privileged access and certificate health; Maintain technical documentation, policies, and operational runbooks; Collaborate with Security, Infrastructure, Cloud, DevOps, Audit, and external partners to resolve issues and support compliance.
Seniority
Mid-level, hands-on IC