Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

IT Engineer, Privileged Access Management (PAM)

ArchWell Health

IT Engineer, Privileged Access Management (PAM)

The Privileged Access Management (PAM) Engineer reports to the Information Security Manager and is responsible for designing, implementing, and operating enterprise PAM capabilities using Microsoft Security technologies and related platforms. This role secures privileged identities and access to critical systems, enforces least-privilege and Zero Trust principles, and supports regulatory and audit requirements.

The PAM Engineer collaborates closely with IAM, Security Operations, Infrastructure, and Application teams to reduce organizational risk while maintaining a secure and user-friendly access model. The role may support security operations and incident response activities when privileged access is involved.

Core PAM Engineering
  • Design, implement, and maintain PAM solutions across cloud and hybrid environments using Microsoft Entra ID, Privileged Identity Management (PIM), Conditional Access, and related Microsoft security tooling
  • Onboard and manage privileged user, service, and application accounts, including credential vaulting, rotation, and lifecycle management
  • Configure and maintain Just-In-Time (JIT) access and privileged role workflows
  • Ensure all in-scope systems, applications, vendors, and integrations are protected by PAM controls
  • Ensure availability, reliability, and security of PAM platforms and services
Monitoring, Detection & Incident Support
  • Monitor PAM-related alerts and logs using Microsoft Sentinel and Defender XDR
  • Support investigation and response to incidents involving privileged account misuse or compromise
  • Collaborate with Security Operations and MSSPs to enhance PAM monitoring and detection use cases
Governance, Risk & Compliance Support
  • Support periodic access reviews and privileged role attestations
  • Maintain PAM documentation, standards, runbooks, and operational procedures
  • Provide input to security policies, standards, and annual review processes under the guidance of IT and Security leadership
  • Support audits and compliance reporting related to privileged access
Integration & Enablement
  • Integrate PAM controls with IAM, endpoint, cloud, SIEM, and application platforms
  • Partner with application owners and business stakeholders to define privileged access roles and requirements
  • Provide technical guidance and training to stakeholders on PAM processes and best practices
Automation & Continuous Improvement
  • Develop automation and scripting for PAM account management, reporting, and operational efficiency
  • Track PAM KPIs and apply metric driven improvements to reduce risk and operational friction
  • Evaluate emerging Microsoft security features and recommend roadmap enhancements
Required Technical Skills
  • Hands-on experience with Microsoft Entra ID, Privileged Identity Management (PIM), Conditional Access, and Microsoft Defender products
  • Strong understanding of privileged access models, least-privilege principles, and Zero Trust security architecture
  • Experience managing identities and access within Microsoft 365 and Azure environments
  • Experience with Windows platforms, Active Directory, and authentication/authorization concepts
  • Scripting or automation experience (PowerShell preferred)
  • Familiarity with SIEM/XDR platforms (Microsoft Sentinel and Defender XDR preferred)
  • Technical documentation and runbook development skills
Professional & Behavioral Skills
  • Strong communication skills with the ability to explain technical concepts to non-technical audiences
  • Proven ability to collaborate across security, IT, and business teams
  • Strong analytical, troubleshooting, and problem-solving skills
  • Ability to operate effectively in fast-paced and regulated environments
  • Continuous-learning mindset with adaptability to evolving security technologies
Education & Experience
  • Bachelor's degree in computer science, Information Technology, or a related field preferred
  • 3+ years of experience in Microsoft Windows and Microsoft 365 environments with direct responsibility for identity or security controls
  • 2+ years of hands-on experience with Microsoft Azure, Entra ID, Defender, and Purview portals
  • Experience supporting hybrid (cloud and on-premises) environments
  • Experience with application authentication (IdP) and authorization (IdM) concepts
  • Experience working across multiple concurrent projects in a dynamic environment
Preferred Experience & Certifications
  • Microsoft Certified: Identity and Access Administrator Associate
  • Microsoft Certified: Security Operations Analyst Associate
  • CISSP or equivalent security certification
  • Additional Microsoft Security certifications
  • Experience with IAM, Active Directory, Windows Server, SQL Server, or networking fundamentals (DNS, DHCP, LAN/WAN)

At ArchWell Health, we're creating a community of caring designed to help our members stay healthy and engaged. By focusing on a strong provider-patient relationship, routine wellness, and staying active, our members enjoy a higher level of care and better quality of life after the age of 60. Everything we do is for seniors. We believe seniors should be heard, listened to, and given ample time by their physicians to live well later in life.

Our value-based care model is designed to prevent illnesses while keeping members healthy and happy in every aspect of their life. We deliver best-in-class primary care at comfortable, accessible neighborhood centers where older adults can feel at home and become part of a vibrant, wellness-focused community. We're passionate about caring for older adults and united by the belief that caring has the power to change everything for our members.

ArchWell Health is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to their race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other protected classification.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the IT Engineer, Privileged Access Management (PAM) in United States vacancy
  •  ...IT Engineer, Privileged Access Management (PAM) Job Summary The Privileged Access Management (PAM) Engineer reports to the Information Security Manager and is responsible for designing, implementing, and operating enterprise PAM capabilities using Microsoft Security... 
    Suggested

    ArchWell Health

    Nashville, TN
    3 days ago
  •  ...Description Job Description We are looking for a Senior IT Engineer — Identity & Access Management to lead secure identity strategy and implementation...  ...speed. • Establish role-based access models, least-privilege controls, and access review practices that align with... 
    Suggested
    Permanent employment
    Contract work

    Robert Half

    Ada, MI
    10 days ago
  • $130k - $150k

     ...integrates Vaultless Secrets Management with Certificate Lifecycle Management, Next Gen Privileged Access Management (Secure Remote Access...  ...looking for a Senior Support Engineer with strong system...  ...Privileged Access Management (PAM), Hardware Security Modules (HSM... 
    Suggested
    Remote work

    Akeyless

    United States
    4 days ago
  •  ...Student Aid is seeking a qualified candidate for a GS-14 position in the Office of Federal Student Aid, focusing on IT management and Identity and Access Management programs. The ideal candidate will have experience managing diverse teams, utilizing Agile methodology, and... 
    Suggested
    Work at office

    US Federal Student Aid

    San Francisco, CA
    1 day ago
  • $120k - $155k

     ...the pioneer in democratizing access to and education about alternative...  ...transact with leading asset managers on a massive scale through a...  ...someone who is the visible face of IT at CAIS headquarters. This...  ...them to manage, maintain, and engineer solutions in the Microsoft ecosystem... 
    Suggested
    Work at office

    CAIS

    New York, NY
    1 day ago
  • Job Title: IT Project Engineer Reports to: Project Engineering Manager Type: Full-Time, Salaried, Exempt Employee Shift: Hybrid...  ...considerations, including access controls, logging, data protection...  ...Access controls Least privilege and role‑based access Logging and... 
    Full time
    Work at office
    Shift work

    Atlas Technica

    New York, NY
    3 days ago
  • Position Name: Junior Project Engineer Reports to: Project Engineer...  ...'s mission is to shoulder IT management, user support, and cybersecurity...  ...Teams, Intune, Conditional Access) Entra ID (Azure AD),...  ...Conditional Access, and least privilege access models. Why Join Atlas... 
    Work at office

    Atlas Technica, LLC

    New York, NY
    4 days ago
  •  ...Description Job Description IT Infrastructure and Support Manager Trigo Quality Solutions...  ..., infrastructure engineering, and senior-level support...  ...connectivity, and secure remote access (VPN) Maintain and...  ...offboarding processes, and system privileges Ensure compliance with... 
    Work experience placement
    Work at office
    Local area
    Remote work
    Flexible hours

    TRIGO Global Quality Solutions

    Springfield, IL
    9 days ago
  • IT Operations & Trust Engineer - Standard Template Labs About Us: Standard Template...  ...Service and Configuration Management. Backed by leading investors...  .../offboarding, MFA, and access control through centralized...  ...such as MFA enforcement, privileged access audits, and device... 
    Full time
    Work at office
    Local area

    Standard Template Labs

    New York, NY
    3 days ago
  •  ...coordinate with auditors and manage evidence collection....  ...intelligence. Regional IT Leadership, Advisory &...  ...on due diligence. Access & Identity Management Govern...  ...including least-privilege, RBAC, and user lifecycle...  ...periodic access reviews and PAM controls. Manage MFA... 
    Local area
    Flexible hours

    Teijin Automotive Technologies, Inc.

    Auburn Hills, MI
    5 days ago
  •  ...Macrotek Services Macrotek designs and implements advanced AV, access control, surveillance, and low voltage systems tailored to meet...  ...high-quality, reliable solutions that are thoughtfully engineered for long-term performance, ease of use, and seamless integration... 

    MacroTek Services LLC

    Atlanta, GA
    9 days ago
  • $25.15 - $42.75 per hour

     ...expert teams of physicists, engineers, data scientists and problem...  ...Marketing, Spares Supply Chain management, Field Operations,...  ...training and certification. May access and determine the problems existing...  ...receive other benefits and privileges of employment. Please... 
    Hourly pay
    Minimum wage
    Work experience placement
    Worldwide
    Flexible hours

    KLA

    Boise, ID
    4 days ago
  • $53.9k - $84.2k

     ...This is a hands-on, waterfront engineering role embedded directly in...  ...board US Navy ships including accessing high and confined spaces and...  ..., engineering, and management expertise in a culture grounded...  ...receive other benefits and privileges of employment, please contact... 
    Full time
    Contract work
    Part time
    Local area
    Remote work
    Relocation package

    Noblis

    Pascagoula, MS
    5 days ago
  • $85k - $100k

     ...the globe. With $75B+ in assets under management, the firm constructs customized investment...  .... Position Description The IT Support Engineer, located in Boston, supports a fast-...  ...offboarding tasks, including device setup, access control, and provisioning. Deliver... 
    Temporary work
    Work at office
    Local area
    Remote work
    Worldwide
    Flexible hours

    Partners Capital

    Boston, MA
    5 days ago
  •  ...IT Support Engineer II We're seeking a dynamic Level 2 IT Support Engineer to join our modern...  ...Advanced Technical Support Escalation Management: Handle complex Level 2 tickets...  ...networking equipment including UniFi access points and switches Surveillance Systems... 
    Apprenticeship
    Local area
    Remote work
    Flexible hours

    KSB SE & Co. KGaA

    Richmond, VA
    2 days ago
  •  ...Customer Support Engineer - Tier 1 All roles at JumpCloud® are...  ...JumpCloud® is the AI-powered unified IT management platform designed to secure...  ...identity, device, and access management, JumpCloud provides...  ...Pluggable Authentication Modules (PAM), pkg management (Yum, RPM,... 
    Full time
    Immediate start
    Remote work
    Shift work

    JumpCloud

    United States
    2 days ago
  •  ...fast. About This Role We are hiring an IT Support Engineer to own frontline IT support and...  ...intersection of support, identity, device management, and internal enablement. You'll be working...  ...resolution for hardware, software, access, and network issues Provide high-... 
    Remote work
    Flexible hours

    LiveKit

    San Francisco, CA
    2 days ago
  • $100k - $120k

     ...Sr. IT Support Engineer Palo Alto Area | Hybrid ******************************************...  ...private equity, hedge fund, investment management firms, and family offices. We strive...  ...complex issues related to identity, access, collaboration, and endpoint management... 
    Full time
    Monday to Friday

    Halcyon Financial Technology

    Palo Alto, CA
    1 day ago
  •  ...transforming the multi-trillion dollar wealth management industry by building an AI platform for...  ...advice better, more affordable, and accessible to all. If you're passionate about...  ...re looking for someone to own all things IT related for our Culver City office!... 
    Work at office
    Immediate start

    Altruist

    Los Angeles, CA
    3 days ago
  • $59.5k - $70.5k

     ...technology company into a national managed services provider, while...  ...Job Overview Service Desk Engineers will be utilized in many different...  ...and support of our Managed IT clients' networks. Service...  ...positions within Impact may involve access to information, technology,... 
    Work experience placement
    Work at office
    Remote work
    Night shift
    Afternoon shift

    Impact Networking

    Lake Forest, IL
    3 days ago
  • $105k - $115k

     ...virtual clinic for Substance Use Management. Our program provides...  ...and health plans to deliver accessible, affordable, and effective treatment...  ...it happen! About Pelago Engineering: Our engineering team operates...  ...Role: Pelago is hiring an IT Operations Engineer to help scale... 
    Full time
    Work at office
    Flexible hours
    3 days per week

    Pelago

    New York, NY
    4 days ago
  • Identity and Access Management (IAM) Support Analyst Looking for an Identity and Access Management professional with 7+ years in IAM, IGA, Detection & Response. Location: Hybrid Roles - Must be able to work 1 day a week Onsite in San Francisco, CA 94105. Duration: 5+ months... 
    Contract work
    1 day per week

    Motion Recruitment

    California, MO
    5 days ago
  • $104.7k - $178k

     ...action on what data. Veza's Access Graph platform maps an organization...  ...access permissions under management, global enterprises...  ...Resorts trust Veza to manage privileged access monitoring, non-human...  ...environments, and AI agents. For engineers joining Veza today, this... 
    Work at office
    Remote work
    Flexible hours

    ServiceNow

    Santa Clara, CA
    3 days ago
  •  ...integrated solutions to manage everything from business...  ...About the team Corporate IT drives our IT support, IT engineering and business engineering...  ...applications, identity and access management. We design, build...  ...- this works with privileged information and with some... 
    Worldwide

    Airwallex

    San Francisco, CA
    1 day ago
  • $150.03k - $224.25k

     ...Job Summary The Senior Manager, IT Engineer Business Intelligence Power BI - Field Reporting is the most-senior member of the engineering...  ...HIPAA). Implement and enforce policies for identity and access management, encryption, and network security. Participate... 
    Temporary work
    Local area
    Worldwide
    Flexible hours
    Shift work

    Otsuka Pharmaceutical Co., Ltd.

    Princeton, NJ
    5 days ago
  •  ...seeking an Information Technology Specialist in Brentwood, Maryland to support their nursing staff with critical IT operations. You will manage user access, administrative tasks in Microsoft 365, and provide Level 1 support, ensuring smooth operations during high-volume... 
    Weekend work

    IntellaTriage

    Brentwood, MD
    3 days ago
  • $150.03k - $224.25k

     ...Senior Manager, IT Engineer Business Intelligence Power BI - Field Reporting The Senior Manager, IT Engineer Business Intelligence Power...  ...GDPR, HIPAA). Implement and enforce policies for identity and access management, encryption, and network security. Participate in... 
    Temporary work
    Local area
    Worldwide
    Flexible hours
    Shift work

    Otsuka Pharmaceutical

    Princeton, NJ
    2 days ago
  • $112.6k - $160.9k

     ...Service Desk Manager The Service Desk Manager is responsible for...  ...Service Desk operations, user access governance, and overall operational...  ...Point of Contact (SPOC) for IT service requests, ensures SLA...  ..., and enforcement of least‑privilege principles. • Demonstrated experience... 
    Remote work

    Hanmi Bank

    Los Angeles, CA
    7 days ago
  •  ...Senior Technical Support Manager Omilia is a leader in enterprise...  ..., onboard and ramp new engineers on OCP. Contribute to the enhancement...  ...and GDPR. Reinforce least-privilege access, careful logging practices...  ...just take a user's word for it. Partner with engineers on high... 
    Remote work
    Worldwide
    Shift work

    Omilia - Conversational Intelligence

    United States
    4 days ago
  •  ...experience level. Role Summary The IT Service Desk Supervisor is responsible...  ...left adoption, knowledge maturity, and access management process adherence. The Supervisor...  ...access-related work complies with least privilege principles, documented approvals, and... 
    Hourly pay
    Permanent employment
    Contract work
    Shift work
    Night shift

    Genesis10

    Omaha, NE
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to IT Engineer, Privileged Access Management (PAM). Be the first to apply!