Sr. Security Engineer

Amazon.com, Inc.
New York, United States of America
13 days ago

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 237K

Job location

New York, United States of America

Tech stack

Microsoft Active Directory
Amazon Web Services (AWS)
Azure
Cloud Computing
CompTIA Security+
Computer Security
DevOps
Python
Key Management
Lightweight Directory Access Protocols (LDAP)
PCI Data Security Standards
Powershell
Broadcom
Zero Trust Network Access
Session Management
Security Information and Event Management
Systems Integration
Scripting (Bash/Python/Go/Ruby)
Google Cloud Platform
Cloud Platform System
Cyberark
System Availability
Information Technology
Sentry
Hashicorp
REST
Terraform
User Administration

Job description

Design, implement, and maintain enterprise PAM solutions including privileged account vaulting, session management, just-in-time access, and secrets management.

  • Administer and operate PAM platforms (e.g., CyberArk, CA PAM) across on-premises and cloud environments, ensuring high availability and security policy enforcement.
  • Develop and maintain automation for PAM onboarding, account provisioning, rotation, and reconciliation using PowerShell, Python, REST APIs, and Terraform.
  • Collaborate with IT, Cloud, DevOps, and application teams to integrate PAM controls into CI/CD pipelines, cloud platforms, and third-party systems.
  • Define and enforce privileged account policies aligned with TWDC security standards, regulatory requirements, and industry best practices.
  • Lead PAM-related risk assessments, access reviews, and audit response activities.
  • Troubleshoot complex PAM platform issues, driving root cause analysis and permanent remediation.
  • Mentor junior engineers and contribute to team documentation, runbooks, and architectural standards.
  • Identify opportunities to reduce the privileged access attack surface through improved tooling, automation, and process improvements.
  • Support knowledge sharing across the PAM team by leading technical discussions, reviewing peers' work, and contributing to team learning initiatives Priyanka Yadav

Requirements

1.) Minimum 5-7 years in Cybersecurity or Identity & Access Management (IAM) 2-3 years need to be focused on Privileged Access Management (PAM) 2.) Hands-on administration of enterprise PAM platforms such as CyberArk (EPV, PSM, PVWA, CPM, CCP) or CA PAM (Broadcom Privileged Access Manager) 3.) Versed in integrating PAM solutions with enterprise directories (Active Directory, LDAP) and cloud platforms (AWS, Azure, GCP) 4.) Proficient in scripting and automation with PowerShell and/or Python for PAM workflows 5.) Demonstrated experience supporting compliance and audit processes (SOX, PCI-DSS, or similar frameworks) 6.) BS degree in any STEM field (Science, Technology, Engineering, or Mathematics) Nice-to-Haves:

  • Experience with DevOps secrets management tools such as HashiCorp Vault, AWS Secrets Manager, or Azure Key Vault.
  • Familiarity with Infrastructure as Code (Terraform) for PAM platform deployment and configuration.
  • Experience with SIEM integrations and PAM telemetry for privileged session monitoring.
  • Knowledge of Zero Trust architecture principles as applied to privileged access.
  • Experience with service account lifecycle management and non-human identity (NHI) programs.
  • Relevant certifications such as: CyberArk Defender/Sentry, CompTIA Security+, CISSP, or equivalent are highly desirable.
  • Master's degree in Information Technology, Information Security, Computer Science, or Business related field or equivalent validated work experience

About the company

We are looking for a Senior Security Engineer (PAM) to join Disney's Global Information Security - Identity and Access Management (IAM) group. This group is responsible for providing a Core IAM ecosystem of products and platforms in use across the company by cast members, employees, and partners within Disney's business segments (ESPN, Parks, Studios, Disney Streaming) and corporate functions. Our vision is to provide modern Identity and Access Management capabilities and services that are simple, seamless, and secure to protect our workforce, our data, and our brands.., Jones Lang LaSalle + Jersey City, NJ + $90,209 per year JLL empowers you to shape a brighter way. Our people at JLL are shaping the future of real estate for a better world by combining world class services, advisory and technology fo…, © 2026 Careerjet All rights reserved

Apply for this position