PAM Engineer
Role details
Job location
Tech stack
Job description
We are seeking a PAM Engineer to support and enhance privileged access controls across enterprise Linux environments. The ideal candidate will have strong hands-on experience with CyberArk Endpoint Privilege Manager (EPM) for Linux, SSH key lifecycle management, and Linux access security. This role will focus on securing privileged access, enforcing least-privilege principles, and supporting enterprise authentication and identity management initiatives., * Administer and support CyberArk Endpoint Privilege Manager (EPM) for Linux, including policy creation, privilege elevation controls, and endpoint security configurations.
- Manage the full SSH key lifecycle, including provisioning, rotation, auditing, governance, and key retirement.
- Implement and maintain privileged access controls and least-privilege security models across Linux environments.
- Collaborate with security, infrastructure, and identity management teams to support enterprise access management initiatives.
- Develop and maintain PAM-related standards, procedures, and operational best practices.
- Support Linux authentication and access management processes within enterprise environments.
- Perform security assessments and recommend improvements to strengthen privileged access controls.
- Assist with Linux system hardening and compliance initiatives.
- Automate administrative and operational tasks using Bash, Python, Ansible, or similar tools.
- Troubleshoot and resolve issues related to privileged access, authentication, and access control mechanisms.
Requirements
Technical Skills
- Strong hands-on experience with CyberArk Endpoint Privilege Manager (EPM) for Linux.
- Experience managing SSH key lifecycle management, including key provisioning, rotation, governance, and auditing.
- Experience implementing and supporting Privileged Access Management (PAM) controls in enterprise environments.
- Strong Linux administration experience, preferably with RHEL, Rocky Linux, CentOS, Oracle Linux, or Ubuntu.
- Experience with PAM framework configuration, sudo policies, and Linux privilege management.
- Familiarity with Active Directory integrations, SSSD, LDAP, and Kerberos.
- Experience with automation tools such as Bash, Python, Ansible, or Puppet.
- Understanding of Linux hardening, security best practices, and access control frameworks.
Preferred Qualifications
- Experience with broader CyberArk PAM solutions.
- Experience supporting enterprise IAM and privileged access governance programs.
- Knowledge of Zero Trust and least-privilege security principles.
- Experience working in large-scale enterprise or regulated environments.