PAM Engineer
Hybrid Remote Washington, DC
Description

We're hiring a PAM Engineer to lead privileged access management across our enterprise. You'll administer our PAM platform, enforce least-privilege and JIT access, integrate with Entra ID and Active Directory, and support the compliance and ATO requirements that come with federal work.  


Key Responsibilities

  • Lead the design, implementation, and ongoing management of PAM solutions—ensuring security, scalability, and operational efficiency across hybrid environments
  • Deploy and administer enterprise PAM platforms (Keeper, CyberArk, or Delinea) across on-premises and cloud environments
  • Manage and secure privileged accounts—service accounts, admin accounts, and shared credentials—through vaulting, rotation, and session monitoring
  • Develop and enforce least-privilege access policies and Just-In-Time (JIT) access workflows across the enterprise
  • Design, implement, and operate privileged session management (PSM) and privileged threat analytics capabilities
  • Establish and maintain emergency "break-glass" privileged access procedures
  • Integrate PAM solutions with Entra ID, Active Directory, and other identity providers to enable centralized privileged access governance
  • Develop automation scripts and workflows using PowerShell or Python to streamline PAM operations and account lifecycle management
  • Perform regular access certifications, entitlement reviews, and audit reporting to support compliance requirements
  • Collaborate with security operations teams to monitor privileged account activity and respond to anomalous behavior
  • Translate stakeholder requirements into actionable PAM processes and technical configurations
  • Enforce strong authentication methods such as certificate-based or FIDO2 wherever possible
Requirements
  • 5+ years of experience in identity and access management, with at least 3 years focused on privileged access management
  • Hands-on experience administering an enterprise PAM platform (CyberArk, Delinea, Keeper, or equivalent)
  • Strong understanding of least-privilege principles, Zero Trust architecture, and privileged access best practices
  • Experience integrating PAM solutions with Entra ID, Active Directory, and SIEM platforms (e.g., Sentinel, Splunk)
  • Proficiency in PowerShell or Python for automation and PAM task management
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field—or equivalent hands-on experience
  • Ability to obtain a Public Trust clearance
  • U.S. citizenship (required for federal contract)

Preferred Qualifications

  • Direct experience with Keeper (our platform)
  • Familiarity with NIST SP 800-53, FISMA, and federal identity guidelines as they relate to privileged access
  • Knowledge of federal compliance frameworks including FedRAMP and applicable CISA guidance
  • Experience supporting ATO processes and documenting PAM controls within System Security Plans (SSPs)
  • Experience in cloud/GovCloud environments (Azure, AWS)
  • Relevant certifications (e.g., CISSP, Security+, CyberArk Defender/Sentry)
Salary Description
$130,000 - 160,000