> Markdown version of [/jobs/ext/2472991-lead-specialist-privileged-access-management-pam-engineer](https://www.wearedevelopers.com/jobs/ext/2472991-lead-specialist-privileged-access-management-pam-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Specialist, Privileged Access Management (PAM) Engineer - **Company:** Kpmg LLP - **Location:** McLean, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Active Directory, Application Integration Architecture, Multi-Factor Authentication, Identity and Access Management, Security Information and Event Management, Single Sign-On, Enterprise Software Applications, Okta, Cyberark, Sentry, SailPoint - **Published:** August 1, 2026 - **Apply:** https://www.kpmguscareers.com/jobdetail/?jobId=135871 ## About the Role * A minimum of five years of experience engineering and managing privileged access management (PAM) solutions including two years in a leadership capacity; U.S. Federal government consulting experience preferred * Bachelor's degree from an accredited college/university * Foundational knowledge of comprehensive ICAM principals, architectures, and federal frameworks e.g. FICAM), extending beyond PAM to include end-to-end identify lifecycle management * Understanding of privileged access management (PAM) concepts and DoD cybersecurity frameworks; CyberArk preferred * Experience with large-scale PAM implementation, lifecycle management, and integration with enterprise systems (e.g. Active Directory, SIEM, ITSM, and IGA Platforms like SailPoint or Okta) * Experience leading cross-functional teams in highly regulated environments * Preferred certifications: CyberArk Defender, Sentry or Guardian; DoD 8570 IAM/IAT Level II or higher a plus * Ability to travel as required to support firm engagements * Applicant must possess a U.S. Government Secret clearance ## Description * Lead the architecture, deployment, and management of CyberArk Privileged Access Management (PAM) solutions to support DoD application integration into ZT environment * Drive alignment between PAM strategies and overarching initiatives, ensuring seamless integration with Identify Governance and Administration (IGA, Single Sign-On (SSO, Multi-Factor Authentication (AFA), and directory services * Oversee workflows for onboarding privileged accounts, conduct comprehensive risk assessments, and maintain strict compliance with DoD and client security standards * Identify and build automations to accelerate integration of applications into PAM platform * Partner with cross-functional teams to enable ZT capability deployment, successfully optimizing CyberArk best practices * Develop and maintain automation scripts, policies, and custom connectors required for enterprise scalability * Troubleshoot and resolve technical issues, ensuring highly stable PAM operations and remediation of incidents * Provide strategic leadership in the design and implementation of privileged access auditing, reporting, and alerting mechanisms * Mentor and review work of junior PAM engineers, and analysts * Support documentation and reporting efforts for project management, roadmap tracking and overall ZT maturation ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [From Doubt to Confidence: How Sentry Uses Verdaccio to Bulletproof SDK Releases](https://www.wearedevelopers.com/videos/739-from-doubt-to-confidence-how-sentry-uses-verdaccio-to-bulletproof-sdk-releases) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Debugging in the Dark](https://www.wearedevelopers.com/videos/1658-debugging-in-the-dark) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Snowball Effect of Open Source](https://www.wearedevelopers.com/videos/523-the-snowball-effect-of-open-source) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers)