Privileged Access Management (PAM) Engineer
Location: Dallas, TX — Hybrid, 3 days/week onsite
Duration: 6+ Months Contract
Position Overview
We are seeking an experienced Privileged Access Management (PAM) Engineer to support enterprise security and identity initiatives. The ideal candidate will have hands-on experience implementing and supporting PAM solutions, managing privileged and service accounts, securing credentials and secrets, and integrating PAM platforms with enterprise infrastructure, applications, directories, and cloud environments.
The candidate should have strong troubleshooting and analytical skills, along with the ability to create technical documentation, operational runbooks, and process documentation.
Required Qualifications
- Hands-on experience supporting Privileged Access Management (PAM), Identity and Access Management (IAM), Information Security, or related security engineering functions.
- Experience with enterprise PAM platforms such as CyberArk, BeyondTrust, Delinea, Bravura Security, HashiCorp Vault, or similar technologies.
- Strong understanding of:
- Privileged account management
- Service account governance
- Secrets management
- Password vaulting
- Credential rotation
- Access control and least-privilege principles
- Experience integrating PAM solutions with:
- Active Directory and enterprise directories
- Authentication services
- Windows and Linux/Unix servers
- Databases
- Enterprise applications
- APIs
- Cloud platforms
- Working knowledge of Windows, Linux/Unix, databases, networking concepts, and common enterprise infrastructure patterns.
- Ability to develop clear technical documentation, operational runbooks, process flows, and stakeholder communications.
- Strong analytical, troubleshooting, collaboration, and communication skills.
Preferred Qualifications
- Experience with PAM modernization, platform upgrades, migration initiatives, disaster recovery planning, and operational resiliency improvements.
- Familiarity with cloud security and secrets management across Microsoft Azure, AWS, Google Cloud, or similar cloud environments.
- Experience with automation, scripting, APIs, CI/CD pipelines, or Infrastructure-as-Code practices.
- Knowledge of security frameworks, audit requirements, regulatory expectations, and compliance-driven access controls.
- Experience supporting PAM environments in large enterprise organizations.
- Relevant certifications such as:
- CISSP
- CompTIA Security+
- CyberArk certifications
- BeyondTrust certifications
- Delinea certifications
- Microsoft Azure certifications
- AWS certifications
- Other relevant security or cloud certifications
Key Responsibilities
- Design, implement, configure, and support enterprise PAM solutions.
- Manage privileged accounts, service accounts, credentials, secrets, and password rotation policies.
- Support PAM integrations with Active Directory, servers, databases, applications, APIs, and cloud environments.
- Troubleshoot PAM-related authentication, connectivity, credential, and integration issues.
- Participate in PAM modernization, upgrades, migrations, and platform enhancements.
- Develop and maintain technical documentation, architecture/process flows, and operational runbooks.
- Support security audits, compliance requirements, access reviews, and remediation activities.
- Implement and maintain least-privilege and privileged-access controls in accordance with enterprise security policies.
- Collaborate with security, infrastructure, application, cloud, and IAM teams to resolve complex access-management issues.
- Support disaster recovery, business continuity, and operational resiliency initiatives for PAM services.
- Identify opportunities to automate PAM processes using scripting, APIs, CI/CD, or Infrastructure-as-Code.
- Communicate technical issues, risks, recommendations, and project status effectively to technical and business stakeholders.
Ideal Candidate
The strongest candidates will have hands-on enterprise PAM engineering experience, particularly with CyberArk, BeyondTrust, Delinea, or HashiCorp Vault, combined with strong knowledge of privileged account management, credential rotation, secrets management, infrastructure integration, and cloud security.
Local Dallas-area candidates who can work onsite 3 days per week are strongly preferred.