IT Engineer, Privileged Access Management (PAM)
ArchWell Health
IT Engineer, Privileged Access Management (PAM)
The Privileged Access Management (PAM) Engineer reports to the Information Security Manager and is responsible for designing, implementing, and operating enterprise PAM capabilities using Microsoft Security technologies and related platforms. This role secures privileged identities and access to critical systems, enforces least-privilege and Zero Trust principles, and supports regulatory and audit requirements.
The PAM Engineer collaborates closely with IAM, Security Operations, Infrastructure, and Application teams to reduce organizational risk while maintaining a secure and user-friendly access model. The role may support security operations and incident response activities when privileged access is involved.
Core PAM Engineering
- Design, implement, and maintain PAM solutions across cloud and hybrid environments using Microsoft Entra ID, Privileged Identity Management (PIM), Conditional Access, and related Microsoft security tooling
- Onboard and manage privileged user, service, and application accounts, including credential vaulting, rotation, and lifecycle management
- Configure and maintain Just-In-Time (JIT) access and privileged role workflows
- Ensure all in-scope systems, applications, vendors, and integrations are protected by PAM controls
- Ensure availability, reliability, and security of PAM platforms and services
Monitoring, Detection & Incident Support
- Monitor PAM-related alerts and logs using Microsoft Sentinel and Defender XDR
- Support investigation and response to incidents involving privileged account misuse or compromise
- Collaborate with Security Operations and MSSPs to enhance PAM monitoring and detection use cases
Governance, Risk & Compliance Support
- Support periodic access reviews and privileged role attestations
- Maintain PAM documentation, standards, runbooks, and operational procedures
- Provide input to security policies, standards, and annual review processes under the guidance of IT and Security leadership
- Support audits and compliance reporting related to privileged access
Integration & Enablement
- Integrate PAM controls with IAM, endpoint, cloud, SIEM, and application platforms
- Partner with application owners and business stakeholders to define privileged access roles and requirements
- Provide technical guidance and training to stakeholders on PAM processes and best practices
Automation & Continuous Improvement
- Develop automation and scripting for PAM account management, reporting, and operational efficiency
- Track PAM KPIs and apply metric driven improvements to reduce risk and operational friction
- Evaluate emerging Microsoft security features and recommend roadmap enhancements
Required Technical Skills
- Hands-on experience with Microsoft Entra ID, Privileged Identity Management (PIM), Conditional Access, and Microsoft Defender products
- Strong understanding of privileged access models, least-privilege principles, and Zero Trust security architecture
- Experience managing identities and access within Microsoft 365 and Azure environments
- Experience with Windows platforms, Active Directory, and authentication/authorization concepts
- Scripting or automation experience (PowerShell preferred)
- Familiarity with SIEM/XDR platforms (Microsoft Sentinel and Defender XDR preferred)
- Technical documentation and runbook development skills
Professional & Behavioral Skills
- Strong communication skills with the ability to explain technical concepts to non-technical audiences
- Proven ability to collaborate across security, IT, and business teams
- Strong analytical, troubleshooting, and problem-solving skills
- Ability to operate effectively in fast-paced and regulated environments
- Continuous-learning mindset with adaptability to evolving security technologies
Education & Experience
- Bachelor's degree in computer science, Information Technology, or a related field preferred
- 3+ years of experience in Microsoft Windows and Microsoft 365 environments with direct responsibility for identity or security controls
- 2+ years of hands-on experience with Microsoft Azure, Entra ID, Defender, and Purview portals
- Experience supporting hybrid (cloud and on-premises) environments
- Experience with application authentication (IdP) and authorization (IdM) concepts
- Experience working across multiple concurrent projects in a dynamic environment
Preferred Experience & Certifications
- Microsoft Certified: Identity and Access Administrator Associate
- Microsoft Certified: Security Operations Analyst Associate
- CISSP or equivalent security certification
- Additional Microsoft Security certifications
- Experience with IAM, Active Directory, Windows Server, SQL Server, or networking fundamentals (DNS, DHCP, LAN/WAN)
At ArchWell Health, we're creating a community of caring designed to help our members stay healthy and engaged. By focusing on a strong provider-patient relationship, routine wellness, and staying active, our members enjoy a higher level of care and better quality of life after the age of 60. Everything we do is for seniors. We believe seniors should be heard, listened to, and given ample time by their physicians to live well later in life.
Our value-based care model is designed to prevent illnesses while keeping members healthy and happy in every aspect of their life. We deliver best-in-class primary care at comfortable, accessible neighborhood centers where older adults can feel at home and become part of a vibrant, wellness-focused community. We're passionate about caring for older adults and united by the belief that caring has the power to change everything for our members.
ArchWell Health is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to their race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other protected classification.
- ...IT Engineer, Privileged Access Management (PAM) Job Summary The Privileged Access Management (PAM) Engineer reports to the Information Security Manager and is responsible for designing, implementing, and operating enterprise PAM capabilities using Microsoft Security...Suggested
- ...Description Job Description We are looking for a Senior IT Engineer — Identity & Access Management to lead secure identity strategy and implementation... ...speed. • Establish role-based access models, least-privilege controls, and access review practices that align with...SuggestedPermanent employmentContract work
$130k - $150k
...integrates Vaultless Secrets Management with Certificate Lifecycle Management, Next Gen Privileged Access Management (Secure Remote Access... ...looking for a Senior Support Engineer with strong system... ...Privileged Access Management (PAM), Hardware Security Modules (HSM...SuggestedRemote work- ...Student Aid is seeking a qualified candidate for a GS-14 position in the Office of Federal Student Aid, focusing on IT management and Identity and Access Management programs. The ideal candidate will have experience managing diverse teams, utilizing Agile methodology, and...SuggestedWork at office
$120k - $155k
...the pioneer in democratizing access to and education about alternative... ...transact with leading asset managers on a massive scale through a... ...someone who is the visible face of IT at CAIS headquarters. This... ...them to manage, maintain, and engineer solutions in the Microsoft ecosystem...SuggestedWork at office- Job Title: IT Project Engineer Reports to: Project Engineering Manager Type: Full-Time, Salaried, Exempt Employee Shift: Hybrid... ...considerations, including access controls, logging, data protection... ...Access controls Least privilege and role‑based access Logging and...Full timeWork at officeShift work
- Position Name: Junior Project Engineer Reports to: Project Engineer... ...'s mission is to shoulder IT management, user support, and cybersecurity... ...Teams, Intune, Conditional Access) Entra ID (Azure AD),... ...Conditional Access, and least privilege access models. Why Join Atlas...Work at office
- ...Description Job Description IT Infrastructure and Support Manager Trigo Quality Solutions... ..., infrastructure engineering, and senior-level support... ...connectivity, and secure remote access (VPN) Maintain and... ...offboarding processes, and system privileges Ensure compliance with...Work experience placementWork at officeLocal areaRemote workFlexible hours
- IT Operations & Trust Engineer - Standard Template Labs About Us: Standard Template... ...Service and Configuration Management. Backed by leading investors... .../offboarding, MFA, and access control through centralized... ...such as MFA enforcement, privileged access audits, and device...Full timeWork at officeLocal area
- ...coordinate with auditors and manage evidence collection.... ...intelligence. Regional IT Leadership, Advisory &... ...on due diligence. Access & Identity Management Govern... ...including least-privilege, RBAC, and user lifecycle... ...periodic access reviews and PAM controls. Manage MFA...Local areaFlexible hours
- ...Macrotek Services Macrotek designs and implements advanced AV, access control, surveillance, and low voltage systems tailored to meet... ...high-quality, reliable solutions that are thoughtfully engineered for long-term performance, ease of use, and seamless integration...
$25.15 - $42.75 per hour
...expert teams of physicists, engineers, data scientists and problem... ...Marketing, Spares Supply Chain management, Field Operations,... ...training and certification. May access and determine the problems existing... ...receive other benefits and privileges of employment. Please...Hourly payMinimum wageWork experience placementWorldwideFlexible hours$53.9k - $84.2k
...This is a hands-on, waterfront engineering role embedded directly in... ...board US Navy ships including accessing high and confined spaces and... ..., engineering, and management expertise in a culture grounded... ...receive other benefits and privileges of employment, please contact...Full timeContract workPart timeLocal areaRemote workRelocation package$85k - $100k
...the globe. With $75B+ in assets under management, the firm constructs customized investment... .... Position Description The IT Support Engineer, located in Boston, supports a fast-... ...offboarding tasks, including device setup, access control, and provisioning. Deliver...Temporary workWork at officeLocal areaRemote workWorldwideFlexible hours- ...IT Support Engineer II We're seeking a dynamic Level 2 IT Support Engineer to join our modern... ...Advanced Technical Support Escalation Management: Handle complex Level 2 tickets... ...networking equipment including UniFi access points and switches Surveillance Systems...ApprenticeshipLocal areaRemote workFlexible hours
- ...Customer Support Engineer - Tier 1 All roles at JumpCloud® are... ...JumpCloud® is the AI-powered unified IT management platform designed to secure... ...identity, device, and access management, JumpCloud provides... ...Pluggable Authentication Modules (PAM), pkg management (Yum, RPM,...Full timeImmediate startRemote workShift work
- ...fast. About This Role We are hiring an IT Support Engineer to own frontline IT support and... ...intersection of support, identity, device management, and internal enablement. You'll be working... ...resolution for hardware, software, access, and network issues Provide high-...Remote workFlexible hours
$100k - $120k
...Sr. IT Support Engineer Palo Alto Area | Hybrid ******************************************... ...private equity, hedge fund, investment management firms, and family offices. We strive... ...complex issues related to identity, access, collaboration, and endpoint management...Full timeMonday to Friday- ...transforming the multi-trillion dollar wealth management industry by building an AI platform for... ...advice better, more affordable, and accessible to all. If you're passionate about... ...re looking for someone to own all things IT related for our Culver City office!...Work at officeImmediate start
$59.5k - $70.5k
...technology company into a national managed services provider, while... ...Job Overview Service Desk Engineers will be utilized in many different... ...and support of our Managed IT clients' networks. Service... ...positions within Impact may involve access to information, technology,...Work experience placementWork at officeRemote workNight shiftAfternoon shift$105k - $115k
...virtual clinic for Substance Use Management. Our program provides... ...and health plans to deliver accessible, affordable, and effective treatment... ...it happen! About Pelago Engineering: Our engineering team operates... ...Role: Pelago is hiring an IT Operations Engineer to help scale...Full timeWork at officeFlexible hours3 days per week- Identity and Access Management (IAM) Support Analyst Looking for an Identity and Access Management professional with 7+ years in IAM, IGA, Detection & Response. Location: Hybrid Roles - Must be able to work 1 day a week Onsite in San Francisco, CA 94105. Duration: 5+ months...Contract work1 day per week
$104.7k - $178k
...action on what data. Veza's Access Graph platform maps an organization... ...access permissions under management, global enterprises... ...Resorts trust Veza to manage privileged access monitoring, non-human... ...environments, and AI agents. For engineers joining Veza today, this...Work at officeRemote workFlexible hours- ...integrated solutions to manage everything from business... ...About the team Corporate IT drives our IT support, IT engineering and business engineering... ...applications, identity and access management. We design, build... ...- this works with privileged information and with some...Worldwide
$150.03k - $224.25k
...Job Summary The Senior Manager, IT Engineer Business Intelligence Power BI - Field Reporting is the most-senior member of the engineering... ...HIPAA). Implement and enforce policies for identity and access management, encryption, and network security. Participate...Temporary workLocal areaWorldwideFlexible hoursShift work- ...seeking an Information Technology Specialist in Brentwood, Maryland to support their nursing staff with critical IT operations. You will manage user access, administrative tasks in Microsoft 365, and provide Level 1 support, ensuring smooth operations during high-volume...Weekend work
$150.03k - $224.25k
...Senior Manager, IT Engineer Business Intelligence Power BI - Field Reporting The Senior Manager, IT Engineer Business Intelligence Power... ...GDPR, HIPAA). Implement and enforce policies for identity and access management, encryption, and network security. Participate in...Temporary workLocal areaWorldwideFlexible hoursShift work$112.6k - $160.9k
...Service Desk Manager The Service Desk Manager is responsible for... ...Service Desk operations, user access governance, and overall operational... ...Point of Contact (SPOC) for IT service requests, ensures SLA... ..., and enforcement of least‑privilege principles. • Demonstrated experience...Remote work- ...Senior Technical Support Manager Omilia is a leader in enterprise... ..., onboard and ramp new engineers on OCP. Contribute to the enhancement... ...and GDPR. Reinforce least-privilege access, careful logging practices... ...just take a user's word for it. Partner with engineers on high...Remote workWorldwideShift work
- ...experience level. Role Summary The IT Service Desk Supervisor is responsible... ...left adoption, knowledge maturity, and access management process adherence. The Supervisor... ...access-related work complies with least privilege principles, documented approvals, and...Hourly payPermanent employmentContract workShift workNight shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Engineer, Privileged Access Management (PAM). Be the first to apply!
- linux support engineer United States
- IT software developer United States
- junior application support engineer United States
- .net support engineer United States
- java support engineer United States
- sales support engineer United States
- support engineer United States
- IT developer United States
- IT data engineer United States
- technical support engineer United States


