SonicJobs Logo
Left arrow iconBack to search

PAM Engineer

RedMatter Solutions LLC
Posted 21 hours ago, valid for 13 days
Location

Washington, DC, US

Salary

$130,000 - $160,000 per year

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • We are seeking a PAM Engineer with over 5 years of experience in identity and access management, including at least 3 years in privileged access management.
  • The role involves administering PAM platforms, enforcing least-privilege access, and integrating with Entra ID and Active Directory.
  • Candidates should have hands-on experience with enterprise PAM solutions like CyberArk, Delinea, or Keeper, and proficiency in PowerShell or Python for automation.
  • The position requires the ability to obtain a Public Trust clearance and U.S. citizenship due to federal contract requirements.
  • The salary for this position is competitive and commensurate with experience.

Description

We're hiring a PAM Engineer to lead privileged access management across our enterprise. You'll administer our PAM platform, enforce least-privilege and JIT access, integrate with Entra ID and Active Directory, and support the compliance and ATO requirements that come with federal work.  


Key Responsibilities

  • Lead the design, implementation, and ongoing management of PAM solutions—ensuring security, scalability, and operational efficiency across hybrid environments
  • Deploy and administer enterprise PAM platforms (Keeper, CyberArk, or Delinea) across on-premises and cloud environments
  • Manage and secure privileged accounts—service accounts, admin accounts, and shared credentials—through vaulting, rotation, and session monitoring
  • Develop and enforce least-privilege access policies and Just-In-Time (JIT) access workflows across the enterprise
  • Design, implement, and operate privileged session management (PSM) and privileged threat analytics capabilities
  • Establish and maintain emergency "break-glass" privileged access procedures
  • Integrate PAM solutions with Entra ID, Active Directory, and other identity providers to enable centralized privileged access governance
  • Develop automation scripts and workflows using PowerShell or Python to streamline PAM operations and account lifecycle management
  • Perform regular access certifications, entitlement reviews, and audit reporting to support compliance requirements
  • Collaborate with security operations teams to monitor privileged account activity and respond to anomalous behavior
  • Translate stakeholder requirements into actionable PAM processes and technical configurations
  • Enforce strong authentication methods such as certificate-based or FIDO2 wherever possible

Requirements

  • 5+ years of experience in identity and access management, with at least 3 years focused on privileged access management
  • Hands-on experience administering an enterprise PAM platform (CyberArk, Delinea, Keeper, or equivalent)
  • Strong understanding of least-privilege principles, Zero Trust architecture, and privileged access best practices
  • Experience integrating PAM solutions with Entra ID, Active Directory, and SIEM platforms (e.g., Sentinel, Splunk)
  • Proficiency in PowerShell or Python for automation and PAM task management
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field—or equivalent hands-on experience
  • Ability to obtain a Public Trust clearance
  • U.S. citizenship (required for federal contract)

Preferred Qualifications

  • Direct experience with Keeper (our platform)
  • Familiarity with NIST SP 800-53, FISMA, and federal identity guidelines as they relate to privileged access
  • Knowledge of federal compliance frameworks including FedRAMP and applicable CISA guidance
  • Experience supporting ATO processes and documenting PAM controls within System Security Plans (SSPs)
  • Experience in cloud/GovCloud environments (Azure, AWS)
  • Relevant certifications (e.g., CISSP, Security+, CyberArk Defender/Sentry)



Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.