Senior Engineer - Privileged Access Management
$150k - $170kAHEAD
AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digital transformation. At AHEAD, we prioritize creating a culture of belonging, where all perspectives and voices are represented, valued, respected, and heard. We create spaces to empower everyone to speak up, make change, and drive the culture at AHEAD. We are an equal opportunity employer, and do not discriminate based on an individual's race, national origin, color, gender, gender identity, gender expression, sexual orientation, religion, age, disability, marital status, or any other protected characteristic under applicable law, whether actual or perceived. We embrace all candidates that will contribute to the diversification and enrichment of ideas and perspectives at AHEAD. AHEAD is searching for a Senior Privileged Access Management (PAM) Engineer to be a part of our Managed Services team. This individual will lead the design, implementation, and ongoing operations of multi-tenant PAM solutions for our MSP customers, with a primary focus on the BeyondTrust platform. The Senior PAM Engineer will architect secure privileged access workflows, implement enterprise-grade BeyondTrust capabilities (such as password vaulting, session management, and least-privilege endpoint controls), integrate PAM with customer identity and ITSM platforms, and serve as the subject matter expert for privileged access across our managed services portfolio. This role requires deep technical expertise in PAM concepts and BeyondTrust technologies, strong security and infrastructure fundamentals, and the ability to lead cross-functional initiatives with customers and internal teams. The ideal candidate will have extensive experience designing and operating PAM solutions in multi-customer environments, strong scripting and automation skills, and a consulting mindset suited to Managed Services delivery. Duties & Responsibilities Lead architecture and design of multi-tenant BeyondTrust PAM services for MSP customers, including onboarding of new tenants and standardization of service offerings. Architect secure privileged access workflows for infrastructure, applications, databases, cloud platforms, and network devices, aligned to least-privilege principles and regulatory requirements. Implement and maintain BeyondTrust Password Safe and related components, including: Discovery and onboarding of privileged accounts and systems Password rotation policies and check-in/check-out workflows Session brokering, recording, and real-time monitoring Approval workflows and just-in-time (JIT) access Implement and maintain BeyondTrust Privilege Management for endpoints and servers (Windows and Linux/Unix), including policy design, deployment, and tuning to minimize user/admin friction while enforcing least privilege. Design and maintain highly available and secure BeyondTrust infrastructure, including clustering, scaling, upgrades, patching, and disaster recovery strategies across customer environments. Integrate PAM with identity and security platforms, including: Active Directory / Entra ID / LDAP and other directories for authentication and group-based access MFA/SSO platforms using SAML/OIDC/OAuth2 SIEM and logging platforms for monitoring and alerting on privileged activity ServiceNow and other ITSM tools for request, approval, and ticket correlation workflows Develop and maintain automation and tooling (e.g., PowerShell, Python, REST APIs) to: Accelerate onboarding and lifecycle management of privileged accounts and systems Enforce configuration standards and policies at scale Generate reports and dashboards for compliance and operational KPIs Lead end-to-end customer onboarding to the PAM service, including: Requirements gathering, use case definition, and risk assessment Designing onboarding playbooks and standard reference architectures Coordinating with internal and customer teams to implement and validate PAM controls Define and maintain standardized PAM policies and baselines across customer environments, including credential management, access approval patterns, session monitoring, and privileged elevation rules. Conduct security and risk assessments of existing privileged access practices, recommend remediation plans, and track execution to closure. Serve as subject matter expert and escalation point for PAM-related incidents and service requests, including troubleshooting BeyondTrust platform issues and complex access problems. Collaborate with security, infrastructure, network, and application teams (internal and customer) to ensure PAM controls are aligned with broader security architecture and operational requirements. Develop and maintain comprehensive documentation, including: Platform architectures and configuration standards Customer-specific runbooks and operational procedures Onboarding and migration playbooks Knowledge base articles and FAQs for internal and customer use Provide mentoring and guidance to team members on PAM concepts, BeyondTrust best practices, and secure operations in a managed services context. Communicate with customers and internal stakeholders with transparency, providing regular status updates, risk/issue visibility, and technical recommendations. Complete training and certification as assigned to further skills and knowledge, including PAM and BeyondTrust-specific certifications where applicable. Other job duties as assigned Education & Experience Minimum Required – A college degree or equivalent in Information Systems, Computer Science, Cybersecurity, or a related field. Unique education, specialized experience, skills, knowledge, training, or certification may be substituted for formal education. Minimum of 7 years of related experience in IT operations, infrastructure engineering, or cybersecurity, with significant hands‑on responsibility for privileged access controls in enterprise environments. 3+ years of direct experience designing, implementing, and operating PAM solutions (BeyondTrust strongly preferred; experience with platforms such as CyberArk or Delinea is a plus). Experience delivering services in a managed services or consulting capacity, including direct customer engagement and multi‑tenant or multi‑customer environments. Demonstrated experience leading technical initiatives, driving cross‑functional projects, and mentoring junior team members. Experience working with regulated or compliance‑driven environments (e.g., SOX, PCI DSS, HIPAA, ISO 27001) and supporting audit and evidence collection for privileged access controls. Knowledge, Skills & Abilities Excellent written and verbal communication skills and ability to build and maintain collaborative, positive working relationships at all levels (technical and business stakeholders). Strong understanding of information security principles, including least privilege, separation of duties, identity and access management, and secure system design. Deep knowledge of PAM concepts and practices, including privileged account discovery, credential vaulting, session management, just-in-time access, and privileged elevation. Hands‑on experience with BeyondTrust products in production environments, ideally including: BeyondTrust Password Safe (or BeyondInsight platform) BeyondTrust Privilege Management for Windows and Unix BeyondTrust Remote Support or similar tools Strong understanding of authentication and authorization protocols (e.g., Kerberos, NTLM, LDAP, RADIUS, SAML, OAuth2/OIDC, API key management) and their application in PAM architectures. Experience integrating PAM platforms with: Active Directory / Entra ID / LDAP and group-based access models MFA/SSO solutions SIEM and logging tools for monitoring privileged activity ServiceNow or similar ITSM systems for request and approval workflows Strong scripting and automation skills (e.g., PowerShell, Python, Bash) and experience using REST APIs to integrate and automate PAM workflows. Experience with Windows and Linux operating systems, including server and workstation platforms, and common administrative tools used by privileged users. Knowledge of enterprise IT systems including Active Directory, networking, firewalls, storage, compute, virtualization, and cloud services, and how privileged access is managed across these domains. Familiarity with monitoring and observability platforms (e.g., Elastic, LogicMonitor or similar) to track PAM infrastructure health and performance. Experience working in Scrum/Agile environments and contributing to structured delivery processes, including backlog grooming, sprint planning, and tracking work against clear acceptance criteria. Strong analytical and problem‑solving skills, with the ability to troubleshoot complex issues across application, infrastructure, and security layers. Demonstrated ability to prioritize and manage multiple concurrent efforts in a fast‑paced managed services environment. $150,000 - $170,000 a year Why AHEAD Through our daily work and internal groups like Moving Women AHEAD and RISE AHEAD, we value and benefit from diversity of people, ideas, experience, and everything in between. We fuel growth by stacking our office with top‑notch technologies in a multi-million-dollar lab, by encouraging cross department training and development, sponsoring certifications and credentials for continued learning. Employment Benefits Medical, Dental, and Vision Insurance 401(k) Paid company holidays Paid time off Paid parental and caregiver leave Plus more! See benefits for additional details. #J-18808-Ljbffr AHEAD
$160k - $240k
A global financial services company in New York is seeking a Senior Software Engineer for its Identity & Privileged Access Management team. The ideal candidate will design scalable identity and access control services and engineer automation for managing credentials across...Senior$158k - $279k
...About role Roku is seeking a senior-level Identity Engineer to enhance its Zero-Trust architecture... ...-on experience in identity and access management (IAM) and securing cloud environments... ...access control (RBAC). Enhance privileged access management and implement scalable...SeniorWork at officeLocal areaRemote workMonday to ThursdayFlexible hours- ...A leading cybersecurity company is seeking a Senior Technical Product Manager to lead the evolution of their Privileged Access Management platform. This 100% remote position involves collaborating with engineering and cross-functional teams to deliver secure, scalable...SeniorRemote work
- ...A leading cybersecurity firm is seeking a Senior QA Analyst for remote work focused on Privileged Access Management (PAM). This role involves developing test strategies for integrations in cloud environments including AWS and Azure. The ideal candidate has over 5 years...SeniorRemote work
$135k - $230k
...Summary/Purpose: We are looking for a highly skilled PAM Engineer with proven experience in Delinea Secret Server, Server Suite, and Delinea Just Enough Privilege (JEP) to manage and enhance our privileged access management infrastructure. This role involves installing,...SuggestedWork experience placementWork from homeVisa sponsorshipWork visaMonday to Friday- ...Senior QA Analyst, Privileged Access Management Remote, US Description Keeper is hiring a talented Senior QA Analyst to join our Privileged Access Management... ...across environments, and collaborate closely with engineering, product, and security teams to ensure Keeper’s PAM...SeniorTemporary workRemote work
$160k - $240k
...Senior Software Engineer - Identity & Privileged Access Management Location: New York Business Area: Engineering and CTO Ref #: 10047610 Description & Requirements Our Team: Bloomberg’s Platform Security organization is responsible for securing the infrastructure, systems...SeniorTemporary workFor contractorsWork experience placementRemote work$169k - $232k
...you an experienced and driven product manager who's passionate about securing the world... ...? Join Okta as we expand Okta's Privileged Access Management (OPA) product-built for scale... ...experience and functional specifications, to engineering teams. Technical Collaboration:...SeniorLocal areaWorldwideFlexible hours- ...Description Keeper Security is seeking a Senior Technical Product Manager to lead and evolve KeeperPAM, our next-generation Privileged Access Management platform designed for today’s... ...codes, collaborates, and ships like an engineer. This is a 100% remote position, with an...SeniorTemporary workRemote work
- ...technology organisations as it continues to expand its security engineering function. We’re looking to speak with highly technical... ...Operating system security, platform hardening, authentication, privileged access, infrastructure security, systems engineering and large‑...Senior
$150k - $170k
AHEAD seeks a Senior Privileged Access Management (PAM) Engineer to lead multi-tenant PAM solutions for our Managed Services team. This role involves architecting and implementing secure privileged access workflows and BeyondTrust capabilities. The ideal candidate will...Senior- Keeper Security is hiring a Windows Systems Software Engineer to join our Privileged Access Management (PAM) engineering team. This is a 100% remote... ...generous PTO plan that celebrates your commitment and seniority (including paid Bereavement/Jury Duty, etc.) Above‑...SeniorTemporary workLocal areaRemote work
- ...collaboratively and respectfully. JOB OVERVIEW The Identity and Access Management (IAM) Engineer is tasked to design, implement, and maintain enterprise... ...access reviews and certifications Enforce least-privilege access principles Support compliance initiatives (SOX,...Live inLocal areaRemote work
- ...and responsibilities As a Product Sales SME for Identity and Access Management within IBM's Automation Platform, you will utilize your deep... ..., Verify Governance, Verify Identity Protection, and Verify Privilege, to deliver solutions that meet client needs. Provide...
- ...LoansIntel is seeking a Senior Software Engineer focused on Identity & Access in New York. You will develop the core infrastructure for authentication and... ...mindset, and familiarity with cross-platform device management. The role offers competitive benefits including 100...Senior
$105k - $162k
...customers and our colleagues. The team is responsible for managing cybersecurity, IT risks and vulnerabilities, physical... ...key initiatives across MetLife. Opportunity We seek a Senior Consultant – Privileged Access Management (PAM) who can help align security solutions...SeniorTemporary workLocal area- ...United States Digital Space LLC in New York is seeking a Senior Software Engineer focused on Identity & Access. Your role involves building foundational systems for authentication and authorization, ensuring secure access for users across multiple platforms. The ideal...SeniorWork at office
- ...Directory, DNS, DHCP, and Group Policy. Design, implement, and manage Windows Server Clustering for application and database high... ...administrative tools and utilities. Maintain system security through access controls, backups, and firewalls. Collaborate with...Senior
$161k - $189k
...Process Mining technology, is looking for an experienced Senior Vulnerability Management Engineer to join our elite Security Engineering Team. This... ...70-20-10 learning framework, mentorship programs, and access to a dedicated learning platform. Holistic Well-being:...SeniorFull timeWork at officeLocal areaImmediate startRemote workWorldwideFlexible hours- ...Senior Developer – Identity & Access Management (IAM) We are seeking an experienced Senior IAM Developer to design... ...genuine coding instincts who can engineer scalable identity capabilities,... ...provisioning, access governance, privileged access workflows, and...Senior
- Vytwo is looking for a Senior IAM Engineer to support and optimize Identity and Access Management operations. In this fully remote position, you will lead the design and implementation of IAM systems, focusing on security and operational efficiency. The ideal candidate...SeniorRemote job
- ...s Client is currently seeking an Application Management Specialist to join their team in New York/Dallas... ...policy enforcement) following MCP protocol. Engineer robust guardrails for safety, compliance, and least‑privilege access. Productionize LLMs: Build evaluation...SeniorHourly payRemote work
- A leading telehealth solutions provider in the United States seeks a Staff IAM Engineer to lead their Identity & Access Management program. This position involves mentoring a team, designing IAM solutions, and ensuring compliance with healthcare regulations like HIPAA....Senior
$130k - $175k
...in! As a leading product feed management platform, Feedonomics works... ...journey, we ally with Sales Engineering, SalesOps, Global Operations,... ...a joy to sell. The Role The Senior Sales Engineer plays an integral... ...employee assistance programs, access to a wellness app, and...SeniorHourly payImmediate startRemote work$124.8k - $156k
...Therapeutics & Innovations group as a Senior Agentic Systems Engineer to build Artificial Intelligence (AI... ...multi‑agent delegation, session management, and streaming interfaces Design and... ...HITL) workflows, and tenant‑aware data access Deploy and operate containerized...SeniorImmediate startRemote workWorldwide- top-tier hedge fund is seeking a highly skilled Senior IAM Engineer to strategically shape the future of its identity and access management infrastructure. This permanent position , based onsite in New York, NY , offers a high-impact engineering role at the crucial intersection...SeniorPermanent employment
$190.4k - $238k
...leader in AI-powered data security and management. Aided by an extensive ecosystem of partners... ...driven and technically strong Sr. Sales Engineer to support SLED sales engagements and... ...resilience, immutable storage, encryption, and access controls. Familiarity with competitive...SeniorHourly payFull timeWork at office2 days per week3 days per week$104k - $210k
...the role of Forward Deployed Engineer to join our Engineering Hub... ...software functionality while managing technical debt. Apply security... ...and driving discovery with senior stakeholders. Experience... ...performance philosophy. We provide access to flexible global resources...SeniorTemporary workWork experience placementWorldwideFlexible hours$260k - $270k
...than 1,100 customers and exabytes of data under management, Qumulo powers mission‑critical workloads anywhere real‑time access to massive file datasets is non‑negotiable.... ...directors, post supervisors, pipeline engineers, and IT teams running editorial, VFX, rendering...SeniorLocal areaRemote workFlexible hours- ...and software, while also performing asset management for software and hardware.IT Client... ...Management is responsible for end user compute engineering, virtualization, and real-time... ...savings account (HSA)* 401k savings plan* Access to wages before pay day with myFlexPay*...SeniorTemporary workWork experience placementLocal areaImmediate startFlexible hoursNight shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Engineer - Privileged Access Management. Be the first to apply!
- senior learning manager New York, NY
- senior data management analyst New York, NY
- senior app developer New York, NY
- senior manager insurance New York, NY
- senior game producer New York, NY
- senior retail sales associate New York, NY
- senior packaging engineer New York, NY
- senior inventory manager New York, NY
- senior sustainability consultant New York, NY
- senior manager quality engineering New York, NY

