> Markdown version of [/jobs/ext/211775-sr-security-engineer](https://www.wearedevelopers.com/jobs/ext/211775-sr-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Security Engineer - **Company:** Amazon.com, Inc. - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $175,100.0 - $236,900.0 - **Contract:** Temporary to permanent - **Skills:** Active Directory, Amazon Web Services, Microsoft Azure, Cloud Computing, CompTIA Security+, Cyber Security, DevOps, Python (Programming Language), Key Management, Lightweight Directory Access Protocols (LDAP), PCI Data Security Standards, Windows PowerShell, Broadcom, Zero Trust Network Access, Session Management, Security Information and Event Management, Systems Integration, Scripting, Google Cloud, Cloud Platform System, Cyberark, System Availability, Information Technology, Sentry, Hashicorp, Restful APIs, Terraform, User Administration - **Published:** May 17, 2026 - **Apply:** https://www.careerjet.com/jobad/useb0bbfb5839f49c4fef6a314a1ebd733 ## About the Role 1.) Minimum 5-7 years in Cybersecurity or Identity & Access Management (IAM) **2-3 years need to be focused on Privileged Access Management (PAM)** 2.) Hands-on administration of enterprise PAM platforms such as CyberArk (EPV, PSM, PVWA, CPM, CCP) or CA PAM (Broadcom Privileged Access Manager) 3.) Versed in integrating PAM solutions with enterprise directories (Active Directory, LDAP) and cloud platforms (AWS, Azure, GCP) 4.) Proficient in scripting and automation with PowerShell and/or Python for PAM workflows 5.) Demonstrated experience supporting compliance and audit processes (SOX, PCI-DSS, or similar frameworks) 6.) BS degree in any STEM field (Science, Technology, Engineering, or Mathematics) Nice-to-Haves: - Experience with DevOps secrets management tools such as HashiCorp Vault, AWS Secrets Manager, or Azure Key Vault. - Familiarity with Infrastructure as Code (Terraform) for PAM platform deployment and configuration. - Experience with SIEM integrations and PAM telemetry for privileged session monitoring. - Knowledge of Zero Trust architecture principles as applied to privileged access. - Experience with service account lifecycle management and non-human identity (NHI) programs. - Relevant certifications such as: CyberArk Defender/Sentry, CompTIA Security+, CISSP, or equivalent are highly desirable. - Master's degree in Information Technology, Information Security, Computer Science, or Business related field or equivalent validated work experience ## Description Design, implement, and maintain enterprise PAM solutions including privileged account vaulting, session management, just-in-time access, and secrets management. - Administer and operate PAM platforms (e.g., CyberArk, CA PAM) across on-premises and cloud environments, ensuring high availability and security policy enforcement. - Develop and maintain automation for PAM onboarding, account provisioning, rotation, and reconciliation using PowerShell, Python, REST APIs, and Terraform. - Collaborate with IT, Cloud, DevOps, and application teams to integrate PAM controls into CI/CD pipelines, cloud platforms, and third-party systems. - Define and enforce privileged account policies aligned with TWDC security standards, regulatory requirements, and industry best practices. - Lead PAM-related risk assessments, access reviews, and audit response activities. - Troubleshoot complex PAM platform issues, driving root cause analysis and permanent remediation. - Mentor junior engineers and contribute to team documentation, runbooks, and architectural standards. - Identify opportunities to reduce the privileged access attack surface through improved tooling, automation, and process improvements. - Support knowledge sharing across the PAM team by leading technical discussions, reviewing peers' work, and contributing to team learning initiatives Priyanka Yadav ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From Doubt to Confidence: How Sentry Uses Verdaccio to Bulletproof SDK Releases](https://www.wearedevelopers.com/videos/739-from-doubt-to-confidence-how-sentry-uses-verdaccio-to-bulletproof-sdk-releases) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Debugging in the Dark](https://www.wearedevelopers.com/videos/1658-debugging-in-the-dark) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The top 200 passwords of 2024 can be cracked in less than a second](https://www.wearedevelopers.com/magazine/502-the-top-200-passwords-of-2024-can-be-cracked-in-less-than-a-second) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)