Privileged Access Management (PAM) / IAM Engineer

The Fountain Group
Dallas, TX, United States
26 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
$135,200.0 - $156,000.0
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Microsoft Azure Cloud Computing Cloud Computing Security CompTIA Security+ Cyber Security Computer Networks Databases Continuous Integration Linux Disaster Recovery
+14 more
Identity and Access Management Key Management Password Management Session Management Systems Integration Scripting Google Cloud Enterprise Software Applications Cloud Platform System Cyberark Multi-Cloud Infrastructure Automation Frameworks Hashicorp Network Server

Job description

  • The Privileged Access Management (PAM) Engineer is responsible for the planning, design, implementation, delivery, and ongoing support of enterprise PAM capabilities. This role focuses on protecting privileged accounts, credentials, secrets, and privileged sessions across on-premises, hybrid, and multi-cloud environments. The PAM Engineer will help mature the organization’s PAM program by ensuring solutions are secure, scalable, reliable, and aligned with information security requirements., * Design, implement, administer, and maintain enterprise Privileged Access Management solutions across on-premises, hybrid, and multi-cloud environments.
  • Enforce least privilege access models and support secure privileged account lifecycle management.
  • Automate credential rotation, password management, secrets management, and privileged access workflows.
  • Configure and support privileged session management, monitoring, recording, and audit capabilities.
  • Integrate PAM platforms with enterprise systems, including identity providers, directories, cloud platforms, infrastructure, applications, databases, and security tools.
  • Develop technical specifications, implementation plans, operational procedures, and support documentation for PAM capabilities.
  • Troubleshoot PAM-related issues, incidents, access failures, platform performance concerns, and integration challenges.
  • Support compliance, audit, and risk management activities by maintaining accurate records, reporting, and evidence of privileged access controls.
  • Partner with IAM, Information Security, Infrastructure, Cloud, Application, and Operations teams to identify privileged access risks and implement secure solutions.
  • Assist in defining PAM standards, policies, processes, and roadmap activities under the direction of IAM leadership.

Requirements

  • 5+ years of experience that includes a minimum of 1+ years of PAM experience (at engineer level)
  • Hands-on experience supporting Privileged Access Management, Identity and Access Management, information security, or related security engineering functions.
  • Experience with enterprise PAM platforms such as CyberArk, BeyondTrust, Delinea, Bravura Security, HashiCorp Vault, or similar technologies.
  • Strong understanding of privileged account management, service account governance, secrets management, password vaulting, credential rotation, and access control principles.
  • Experience integrating PAM solutions with directories, authentication services, servers, databases, applications, APIs, and cloud platforms.
  • Working knowledge of Windows, Linux/Unix, databases, networking concepts, and common enterprise infrastructure patterns.
  • Ability to develop clear technical documentation, operational runbooks, process flows, and stakeholder communications.
  • Strong analytical, troubleshooting, collaboration, and communication skills., * Experience with PAM modernization, platform upgrades, disaster recovery planning, and operational resiliency improvements.
  • Familiarity with cloud security and secrets management across Microsoft Azure, AWS, Google Cloud, or similar cloud environments.
  • Experience with automation, scripting, APIs, CI/CD pipelines, or infrastructure-as-code practices.
  • Knowledge of security frameworks, audit requirements, regulatory expectations, and compliance-driven access controls.
  • Relevant certifications such as CISSP, Security+, CyberArk, BeyondTrust, Delinea, Microsoft Azure, AWS, or other security and cloud certifications.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.thefountaingroup.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

5:24 min

Demonstrating database encryption at rest with HashiCorp Vault

Alex Soto Alex Soto · LIVE

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · WWC 2023

2:39 min

Generating dynamic application secrets using HashiCorp Vault engines

Alex Soto Alex Soto · LIVE

Videos

See all

Related articles

See all