- Salary
- $130k – $160k/yr
- Location
- Washington, DC
- Workplace
- Hybrid
- Department
- Engineering
- Experience
- 5+ years
- Education
- Bachelor
- Source
- Paylocity
Description
Description
We're hiring a PAM Engineer to lead privileged access management across our enterprise. You'll administer our PAM platform, enforce least-privilege and JIT access, integrate with Entra ID and Active Directory, and support the compliance and ATO requirements that come with federal work.
Key Responsibilities
- Lead the design, implementation, and ongoing management of PAM solutions—ensuring security, scalability, and operational efficiency across hybrid environments
- Deploy and administer enterprise PAM platforms (Keeper, CyberArk, or Delinea) across on-premises and cloud environments
- Manage and secure privileged accounts—service accounts, admin accounts, and shared credentials—through vaulting, rotation, and session monitoring
- Develop and enforce least-privilege access policies and Just-In-Time (JIT) access workflows across the enterprise
- Design, implement, and operate privileged session management (PSM) and privileged threat analytics capabilities
- Establish and maintain emergency "break-glass" privileged access procedures
- Integrate PAM solutions with Entra ID, Active Directory, and other identity providers to enable centralized privileged access governance
- Develop automation scripts and workflows using PowerShell or Python to streamline PAM operations and account lifecycle management
- Perform regular access certifications, entitlement reviews, and audit reporting to support compliance requirements
- Collaborate with security operations teams to monitor privileged account activity and respond to anomalous behavior
- Translate stakeholder requirements into actionable PAM processes and technical configurations
- Enforce strong authentication methods such as certificate-based or FIDO2 wherever possible
Requirements
- 5+ years of experience in identity and access management, with at least 3 years focused on privileged access management
- Hands-on experience administering an enterprise PAM platform (CyberArk, Delinea, Keeper, or equivalent)
- Strong understanding of least-privilege principles, Zero Trust architecture, and privileged access best practices
- Experience integrating PAM solutions with Entra ID, Active Directory, and SIEM platforms (e.g., Sentinel, Splunk)
- Proficiency in PowerShell or Python for automation and PAM task management
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field—or equivalent hands-on experience
- Ability to obtain a Public Trust clearance
- U.S. citizenship (required for federal contract)
Preferred Qualifications
- Direct experience with Keeper (our platform)
- Familiarity with NIST SP 800-53, FISMA, and federal identity guidelines as they relate to privileged access
- Knowledge of federal compliance frameworks including FedRAMP and applicable CISA guidance
- Experience supporting ATO processes and documenting PAM controls within System Security Plans (SSPs)
- Experience in cloud/GovCloud environments (Azure, AWS)
- Relevant certifications (e.g., CISSP, Security+, CyberArk Defender/Sentry)