Experience: 12+ Years
A PAM + Kubernetes Engineer/Architect is responsible for designing, deploying, configuring, and securing privileged access solutions (like BeyondTrust PAM) in cloud-native environments — especially Kubernetes clusters. You ensure privileged accounts, secrets, and elevated access controls are secure, audited, and compliant while enabling secure workflows across teams and infrastructure.
Responsibilities:
Privileged Access Management
Design, implement, and manage PAM solutions such as BeyondTrust (Password Safe, Privileged Remote Access, etc.).
Configure vaulting, credential rotation, session recording, and governance workflows.
Integrate PAM with ITSM (e.g., ServiceNow), SIEM (e.g., Splunk), and identity systems.
Define and enforce least-privilege and just-in-time (JIT) access policies.
Provide secure access controls for Kubernetes clusters (developers, operators, automation, bots).
Manage secrets securely within Kubernetes environments (e.g., protecting API keys and credentials).
Monitor privileged actions and audit logs across Kubernetes workloads.
Develop scripts/automation (PowerShell, Bash, Python) for provisioning and integration.
Key Skills and Technologies:
BeyondTrust PAM platform (Password Safe, Privileged Remote Access, etc.) – deployment, administration, integration.
Understanding of PAM concepts: least privilege, JIT access, credential vaulting, session monitoring.
Privileged account lifecycle management and access governance.
Kubernetes security principles and RBAC (Role-Based Access Control).
Integrating PAM with Kubernetes clusters for granular access control.
Containerization and orchestration (Docker, Kubernetes).
Cloud platforms such as AWS, Azure, Google Cloud Platform (optional but often required).
Strong foundational knowledge of identity management (IAM), SAML, OAuth, OIDC.
Integration with SIEM/ITSM tools (Splunk, QRadar, ServiceNow).
Zero Trust Security model understanding.
PowerShell, Bash, Python for automation and toolchain integration.
Familiarity with Infrastructure as Code tools (Terraform, Ansible) often a plus.