Senior Security Engineer (PAM)

Software Resources
Burbank, CA, United States
3 months ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$187,200.0 - $201,760.0
Working hours
Regular working hours
Job source

Tech stack

Secure Shell (SSH) Microsoft Access Active Directory Amazon Web Services Microsoft Azure Cloud Computing CompTIA Security+ Cyber Security DevOps Identity and Access Management Information Security Management Python (Programming Language)
+20 more
Key Management Lightweight Directory Access Protocols (LDAP) PCI Data Security Standards Windows PowerShell Role-Based Access Control Broadcom Zero Trust Network Access Session Management Security Information and Event Management Data Streaming Google Cloud Cloud Platform System Cyberark System Availability Information Technology Sentry Hashicorp Restful APIs Terraform User Administration

Job description

We are looking for a Senior Security Engineer - PAM to join the Global Information Security - Identity and Access Management (IAM) group. This group is responsible for providing a Core IAM ecosystem of products and platforms in use across the company by cast members, employees, and partners within our business segments (Sports, Parks, Studios, Streaming) and corporate functions. Our vision is to provide modern Identity and Access Management capabilities and services that are simple, seamless, and secure to protect our workforce, our data, and our brands.

What You’ll Do:

  • Design, implement, and maintain enterprise PAM solutions including privileged account vaulting, session management, just-in-time access, and secrets management.
  • Administer and operate PAM platforms (e.g., CyberArk, CA PAM) across on-premises and cloud environments, ensuring high availability and security policy enforcement.
  • Develop and maintain automation for PAM onboarding, account provisioning, rotation, and reconciliation using PowerShell, Python, REST APIs, and Terraform.
  • Collaborate with IT, Cloud, DevOps, and application teams to integrate PAM controls into CI/CD pipelines, cloud platforms, and third-party systems.
  • Define and enforce privileged account policies aligned with security standards, regulatory requirements, and industry best practices.
  • Lead PAM-related risk assessments, access reviews, and audit response activities.
  • Troubleshoot complex PAM platform issues, driving root cause analysis and permanent remediation.
  • Mentor junior engineers and contribute to team documentation, runbooks, and architectural standards.
  • Identify opportunities to reduce the privileged access attack surface through improved tooling, automation, and process improvements.
  • Support knowledge sharing across the PAM team by leading technical discussions, reviewing peers’ work, and contributing to team learning initiatives.

Requirements

Do you have experience in SSH?, Do you have a Bachelor’s degree?, * Minimum of 5+ years of experience in cybersecurity or identity and access management, with at least 3 years focused on Privileged Access Management.

  • Hands-on experience administering enterprise PAM platforms such as CyberArk (EPV, PSM, PVWA, CPM, CCP) or CA PAM (Broadcom Privileged Access Manager).
  • Proficiency in scripting and automation with PowerShell and/or Python for PAM workflows.
  • Experience integrating PAM solutions with enterprise directories (Active Directory, LDAP) and cloud platforms (AWS, Azure, GCP).
  • Strong understanding of PAM concepts: credential vaulting, session recording, just-in-time access, least privilege, secrets management, and SSH key management.
  • Demonstrated experience supporting compliance and audit processes (SOX, PCI-DSS, or similar frameworks).
  • Ability to work effectively across cross-functional teams in a large enterprise environment., * Experience with DevOps secrets management tools such as HashiCorp Vault, AWS Secrets Manager, or Azure Key Vault.
  • Familiarity with Infrastructure as Code (Terraform) for PAM platform deployment and configuration.
  • Experience with SIEM integrations and PAM telemetry for privileged session monitoring.
  • Knowledge of Zero Trust architecture principles as applied to privileged access.
  • Experience with service account lifecycle management and non-human identity (NHI) programs.
  • Relevant certifications such as: CyberArk Defender/Sentry, CompTIA Security+, CISSP, or equivalent are highly desirable.
  • Master’s degree in Information Technology, Information Security, Computer Science, or Business related field or equivalent validated work experience

Required Education: BA/BS Degree Comp Sci/IS or related field

Benefits & conditions

4.44.4 out of 5 stars Burbank, CA 91521 Hybrid work $90 - $97 an hour - Contract, Pulled from the full job description

  • AD&D insurance
  • Health insurance
  • 401(k) matching
  • Vision insurance
  • Dental insurance
  • Life insurance
  • Disability insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

54 sec

Overview of enterprise Java and generative AI

Timo Salm Timo Salm · WWC 2025

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

1:22 min

Overview of the Sentry error and performance monitoring platform

Priscila Oliveira · WWC 2023

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:05 min

Session overview and setup for building AI applications

Sandra Ahlgrimm Sandra Ahlgrimm +1 · WWC 2024

Videos

See all

Related articles

See all