IAM PAM ENGINEER
Hybrid in New York, NY, US • Posted 1 day ago • Updated 1 day ago.png%3Fformat%3Dwebp&w=828&q=75)

Neotecra, Inc
Dice Job Match Score™
🛠️ Calibrating flux capacitors...
Job Details
Skills
- PAM
- Security Engineering
- Security Architecture
- SailPoint
- Multi-factor Authentication
- Identity Management
- Cloud Security
Summary
Role Overview
We are seeking a skilled Privileged Access Management (PAM) Engineer to join our cybersecurity team. This role will focus on securing privileged identities across Active Directory (AD), Entra ID, Linux, and major cloud platforms (Azure, AWS, and Google Cloud Platform). The PAM Engineer will design, implement, and maintain controls that ensure administrators and endpoints only have the access they need—at the right time and with the least privilege possible.
The ideal candidate will have strong expertise in vaulting platforms, endpoint privilege management, and zero-trust principles, with a proven track record of reducing attack surfaces and improving identity hygiene.
KEY RESPONSIBILITIES
Privileged Identity Security
- Administer and enhance the corporate vaulting platform to manage privileged credentials across AD, Entra, Linux, and cloud platforms (Azure, AWS, Google Cloud Platform).
- Implement credential randomization for local/built-in administrator accounts, service accounts, and cloud root/admin accounts.
- Ensure time-bound, approval-based access for administrators following least privilege and just-in-time (JIT) principles.
Endpoint Privilege Management
- Implement and maintain endpoint least-privilege policies across Windows, Linux, and macOS environments.
- Replace standing local admin rights with controlled privilege elevation workflows.
- Apply application control and privilege granularity to reduce risks from malware, ransomware, and insider threats.
- Partner with desktop engineering teams to improve usability while enforcing strong endpoint controls.
Identity Hardening & Hygiene
- Lead local administrator cleanup projects and enforce removal of unauthorized admin rights.
- Harden Entra ID and cloud tenant hygiene by monitoring stale accounts, privileged roles, and excessive permissions.
- Apply ITDR (Identity Threat Detection & Response) practices to detect and mitigate suspicious privileged activity across on-prem and cloud platforms.
Security Architecture & Standards
- Contribute to enterprise Zero Trust architecture initiatives for hybrid and multi-cloud environments.
- Align privileged access controls with NIST standards and organizational policies.
- Drive adoption of passwordless authentication, MFA, and SSO for both on-prem and cloud privileged identities.
Cloud Identity & Access
- Manage and monitor privileged roles and accounts in Azure AD (Entra ID), AWS IAM, and Google Cloud Platform IAM.
- Implement least-privilege design for cloud workloads, service principals, keys, and secrets.
- Integrate cloud platform identities with PAM vaulting, session recording, and access approval workflows.
Identity Lifecycle Management
- Collaborate with IGA teams to automate provisioning, deprovisioning, and recertification of privileged accounts across on-prem and cloud.
- Ensure privileged entitlements are tied to clear business justification and ownership.
Documentation & Governance
- Create and maintain technical runbooks, architecture diagrams, and operational procedures.
- Provide reporting on privileged access usage, endpoint privilege management, hygiene metrics, and compliance results.
- Partner with audit, compliance, and risk teams to demonstrate control effectiveness.
Required Qualifications
- 3–5+ years of experience in PAM, IAM, or related security engineering roles.
- Hands-on experience with AD, Entra ID, Linux, and at least one major cloud platform (Azure, AWS, or Google Cloud Platform).
- Strong knowledge of vaulting technologies and endpoint privilege management practices (least privilege, privilege elevation, application control).
- Proficiency with authentication methods: MFA, SSO, passwordless, Kerberos, and certificate-based access.
- Familiarity with NIST 800-63B, Zero Trust frameworks, ITDR, and cloud security standards (CIS, CSA, etc.).
- Strong scripting/automation skills (PowerShell, Python, Bash, Terraform, etc.).
- Excellent documentation and communication abilities.
Preferred Qualifications
- Experience securing privileged access in multi-cloud environments (Azure, AWS, Google Cloud Platform).
- Knowledge of Entra ID Conditional Access, PIM, AWS IAM policies, and Google Cloud Platform IAM roles.
- Experience integrating PAM solutions with CI/CD pipelines, DevOps tools, or ITSM workflows.
- Industry certifications are a Plus (SailPoint, CISSP, CISM, CCSP, Azure Security Engineer, AWS Security Specialty, GIAC, etc.).
Success in This Role Looks Like
- Reduction of standing local administrator rights and adoption of endpoint least-privilege controls.
- Demonstrated adoption of MFA, passwordless, vault-based workflows, and privilege elevation.
- Improved audit and compliance posture with clear reporting of privileged activity and endpoint control enforcement.
- Measurable reduction in attack surface through consistent identity hygiene and lifecycle management.
- Dice Id: 10109859
- Position Id: 8883513
- Posted 1 day ago
Company Info
About Neotecra, Inc
Neotecra is a leading provider of staffing, consulting, and solutions in the disciplines of information technology, engineering, administrative, finance and accounting. We give our clients the power to address their challenges and gain a competitive edge in the global market.
Our client base includes a wide spectrum of companies ranging from small start up companies to Fortune 1000 industry leaders. We develop a strong relationship with our clients and are committed to provide the highest level of customer satisfaction.
Leadership
Neotecra was founded by an experienced group of professionals based in the U.S and India with diverse and wide ranging experience in the areas of finance, project management, software architecture & development and human resource management. The leadership group is small, tight-knit and focused on attaining client objectives.
Team
Our constantly expanding team consists of talented professionals with experience gained from developing and delivering client focused solutions. We have formed our team with deliberate care so that as a client, you get what you see. Our skills cover a variety of hardware, software and operating environments and are constantly upgraded to meet the latest challenges in technology. Our consultants embed a balanced combination of technical, analytical and communication skills. We lay great stress on ongoing professional development and utilize a number of tools to hone our skills.
Capabilities
Neotecra is committed to providing innovative software solutions to its clients and recognizes the importance of technology. Our seasoned software professionals have expertise in a wide range of technologies including:
- Cyber security
- Cloud
- Business Intelligence
- Data Analytics
- Mobile/ Web Development
- AI and Machine Learning
Services include on-site and off-site development, project consultancy, requirements gathering and system architecture. We undertake long-term projects on a contract basis with reputable clients. Our goal is to clearly understand our client's need and provide them with real and lasting solutions that meet and exceed their expectations.
Our Commitment
At Neotecra, we understand that delivering client-focused solutions involves not only development of the optimal solution using the most appropriate tools and technologies but also implementation of the solutions developed in the client environment. Given the fact that product and project life cycles are constantly growing shorter, we understand that setting and meeting aggressive implementation schedules is a must for realizing planned payoffs for projects. Further, maintaining the highest standards of quality is a prerequisite for avoiding time and cost overruns. We are committed to devote all resources towards meeting your targets. We spend considerable time in the planning and design stages and then provide appropriate resources to the engagement.
Similar Jobs
It looks like there aren't any Similar Jobs for this job yet.
Search all similar jobs