Privileged Access Management (PAM) Engineer
InterSources Inc
Title: Privileged Access Management (PAM) Engineer
Location: NYC NY
On-site/Remote/Hybrid: Hybrid 3 days onsite/2 days remote.
Duration: 12 Months
Total Work Hours: 37.5 Hours
Interview Process: 1-2 Rounds
NOTE: **PLEASE NOTE THIS POSITION WILL ALLOW CONSULTANT TO WORK A HYBRID REMOTE SCHEDULE.
UPON START DATE CONSULTANT WILL BE REQUIRED TO WORK FIRST MONTH FULLY ONSITE. ONCE WORK CAPABILITY IS ESTABLISHED, CONSULTANT WILL BE ALLOWED TO WORK A HYBRID REMOTE SCHEDULE CONSISTING OF 3 DAYS ONSITE/ 2 DAYS REMOTE. ASLO HOURS PER WEEK IS 37.5 NO OVERTIME**
Position Summary:
Role Overview
We are seeking a skilled Privileged Access Management (PAM) Engineer to join our cybersecurity team. This role will focus on securing privileged identities across Active Directory (AD), Entra ID, Linux, and major cloud platforms (Azure, AWS, and GCP). The PAM Engineer will design, implement, and maintain controls that ensure administrators and endpoints only have the access they need-at the right time and with the least privilege possible.
The ideal candidate will have strong expertise in vaulting platforms, endpoint privilege management, and zero-trust principles, with a proven track record of reducing attack surfaces and improving identity hygiene.
KEY RESPONSIBILITIES Privileged Identity Security
- Administer and enhance the corporate vaulting platform to manage privileged credentials across AD, Entra, Linux, and cloud platforms (Azure, AWS, GCP).
- Implement credential randomization for local/built-in administrator accounts, service accounts, and cloud root/admin accounts.
- Ensure time-bound, approval-based access for administrators following least privilege and just-in-time (JIT) principles.
Endpoint Privilege Management
- Implement and maintain endpoint least-privilege policies across Windows, Linux, and macOS environments.
- Replace standing local admin rights with controlled privilege elevation workflows.
- Apply application control and privilege granularity to reduce risks from malware, ransomware, and insider threats.
- Partner with desktop engineering teams to improve usability while enforcing strong endpoint controls.
Identity Hardening & Hygiene
- Lead local administrator cleanup projects and enforce removal of unauthorized admin rights.
- Harden Entra ID and cloud tenant hygiene by monitoring stale accounts, privileged roles, and excessive permissions.
- Apply ITDR (Identity Threat Detection & Response) practices to detect and mitigate suspicious privileged activity across on-prem and cloud platforms.
Security Architecture & Standards
- Contribute to enterprise Zero Trust architecture initiatives for hybrid and multi-cloud environments.
- Align privileged access controls with NIST standards and organizational policies.
- Drive adoption of passwordless authentication, MFA, and SSO for both on-prem and cloud privileged identities.
Cloud Identity & Access
- Manage and monitor privileged roles and accounts in Azure AD (Entra ID), AWS IAM, and GCP IAM.
- Implement least-privilege design for cloud workloads, service principals, keys, and secrets.
- Integrate cloud platform identities with PAM vaulting, session recording, and access approval workflows.
Identity Lifecycle Management
- Collaborate with IGA teams to automate provisioning, deprovisioning, and recertification of privileged accounts across on-prem and cloud.
- Ensure privileged entitlements are tied to clear business justification and ownership.
Documentation & Governance
- Create and maintain technical runbooks, architecture diagrams, and operational procedures.
- Provide reporting on privileged access usage, endpoint privilege management, hygiene metrics, and compliance results.
- Partner with audit, compliance, and risk teams to demonstrate control effectiveness.
Required Qualifications
- 3-5+ years of experience in PAM, IAM, or related security engineering roles.
- Hands-on experience with AD, Entra ID, Linux, and at least one major cloud platform (Azure, AWS, or GCP).
- Strong knowledge of vaulting technologies and endpoint privilege management practices (least privilege, privilege elevation, application control).
- Proficiency with authentication methods: MFA, SSO, passwordless, Kerberos, and certificate-based access.
- Familiarity with NIST 800-63B, Zero Trust frameworks, ITDR, and cloud security standards (CIS, CSA, etc.).
- Strong scripting/automation skills (PowerShell, Python, Bash, Terraform, etc.).
- Excellent documentation and communication abilities.
Preferred Qualifications
- Experience securing privileged access in multi-cloud environments (Azure, AWS, GCP).
- Knowledge of Entra ID Conditional Access, PIM, AWS IAM policies, and GCP IAM roles.
- Experience integrating PAM solutions with CI/CD pipelines, DevOps tools, or ITSM workflows.
Success in This Role Looks Like
- Reduction of standing local administrator rights and adoption of endpoint least-privilege controls.
- Demonstrated adoption of MFA, passwordless, vault-based workflows, and privilege elevation.
- Improved audit and compliance posture with clear reporting of privileged activity and endpoint control enforcement.
- Measurable reduction in attack surface through consistent identity hygiene and lifecycle management.
bout Us:
InterSources Inc , is a Small, Woman, and Minority-Owned Business Enterprise, ISO/IEC 27001, SOC 2 Type 2 certified company with massive 18+ years of diversified experience in providing IT Consulting Services, Artificial Intelligence, Data Analysis, Application Development, Cloud Services, Cybersecurity, Digital Marketing, ERP Management, Custom Software Development, Web Development, UI/ UX Design, System Integration, QA Support etc. We make reasonable accommodations for clients and employees, and we do not discriminate based on any protected attribute including race, religion, color, national origin, gender sexual orientation, gender identity, age, or marital status. We also are a Google Cloud and Oracle partner company.
Location: NYC NY
On-site/Remote/Hybrid: Hybrid 3 days onsite/2 days remote.
Duration: 12 Months
Total Work Hours: 37.5 Hours
Interview Process: 1-2 Rounds
NOTE: **PLEASE NOTE THIS POSITION WILL ALLOW CONSULTANT TO WORK A HYBRID REMOTE SCHEDULE.
UPON START DATE CONSULTANT WILL BE REQUIRED TO WORK FIRST MONTH FULLY ONSITE. ONCE WORK CAPABILITY IS ESTABLISHED, CONSULTANT WILL BE ALLOWED TO WORK A HYBRID REMOTE SCHEDULE CONSISTING OF 3 DAYS ONSITE/ 2 DAYS REMOTE. ASLO HOURS PER WEEK IS 37.5 NO OVERTIME**
Position Summary:
Role Overview
We are seeking a skilled Privileged Access Management (PAM) Engineer to join our cybersecurity team. This role will focus on securing privileged identities across Active Directory (AD), Entra ID, Linux, and major cloud platforms (Azure, AWS, and GCP). The PAM Engineer will design, implement, and maintain controls that ensure administrators and endpoints only have the access they need-at the right time and with the least privilege possible.
The ideal candidate will have strong expertise in vaulting platforms, endpoint privilege management, and zero-trust principles, with a proven track record of reducing attack surfaces and improving identity hygiene.
KEY RESPONSIBILITIES Privileged Identity Security
- Administer and enhance the corporate vaulting platform to manage privileged credentials across AD, Entra, Linux, and cloud platforms (Azure, AWS, GCP).
- Implement credential randomization for local/built-in administrator accounts, service accounts, and cloud root/admin accounts.
- Ensure time-bound, approval-based access for administrators following least privilege and just-in-time (JIT) principles.
Endpoint Privilege Management
- Implement and maintain endpoint least-privilege policies across Windows, Linux, and macOS environments.
- Replace standing local admin rights with controlled privilege elevation workflows.
- Apply application control and privilege granularity to reduce risks from malware, ransomware, and insider threats.
- Partner with desktop engineering teams to improve usability while enforcing strong endpoint controls.
Identity Hardening & Hygiene
- Lead local administrator cleanup projects and enforce removal of unauthorized admin rights.
- Harden Entra ID and cloud tenant hygiene by monitoring stale accounts, privileged roles, and excessive permissions.
- Apply ITDR (Identity Threat Detection & Response) practices to detect and mitigate suspicious privileged activity across on-prem and cloud platforms.
Security Architecture & Standards
- Contribute to enterprise Zero Trust architecture initiatives for hybrid and multi-cloud environments.
- Align privileged access controls with NIST standards and organizational policies.
- Drive adoption of passwordless authentication, MFA, and SSO for both on-prem and cloud privileged identities.
Cloud Identity & Access
- Manage and monitor privileged roles and accounts in Azure AD (Entra ID), AWS IAM, and GCP IAM.
- Implement least-privilege design for cloud workloads, service principals, keys, and secrets.
- Integrate cloud platform identities with PAM vaulting, session recording, and access approval workflows.
Identity Lifecycle Management
- Collaborate with IGA teams to automate provisioning, deprovisioning, and recertification of privileged accounts across on-prem and cloud.
- Ensure privileged entitlements are tied to clear business justification and ownership.
Documentation & Governance
- Create and maintain technical runbooks, architecture diagrams, and operational procedures.
- Provide reporting on privileged access usage, endpoint privilege management, hygiene metrics, and compliance results.
- Partner with audit, compliance, and risk teams to demonstrate control effectiveness.
Required Qualifications
- 3-5+ years of experience in PAM, IAM, or related security engineering roles.
- Hands-on experience with AD, Entra ID, Linux, and at least one major cloud platform (Azure, AWS, or GCP).
- Strong knowledge of vaulting technologies and endpoint privilege management practices (least privilege, privilege elevation, application control).
- Proficiency with authentication methods: MFA, SSO, passwordless, Kerberos, and certificate-based access.
- Familiarity with NIST 800-63B, Zero Trust frameworks, ITDR, and cloud security standards (CIS, CSA, etc.).
- Strong scripting/automation skills (PowerShell, Python, Bash, Terraform, etc.).
- Excellent documentation and communication abilities.
Preferred Qualifications
- Experience securing privileged access in multi-cloud environments (Azure, AWS, GCP).
- Knowledge of Entra ID Conditional Access, PIM, AWS IAM policies, and GCP IAM roles.
- Experience integrating PAM solutions with CI/CD pipelines, DevOps tools, or ITSM workflows.
Success in This Role Looks Like
- Reduction of standing local administrator rights and adoption of endpoint least-privilege controls.
- Demonstrated adoption of MFA, passwordless, vault-based workflows, and privilege elevation.
- Improved audit and compliance posture with clear reporting of privileged activity and endpoint control enforcement.
- Measurable reduction in attack surface through consistent identity hygiene and lifecycle management.
bout Us:
InterSources Inc , is a Small, Woman, and Minority-Owned Business Enterprise, ISO/IEC 27001, SOC 2 Type 2 certified company with massive 18+ years of diversified experience in providing IT Consulting Services, Artificial Intelligence, Data Analysis, Application Development, Cloud Services, Cybersecurity, Digital Marketing, ERP Management, Custom Software Development, Web Development, UI/ UX Design, System Integration, QA Support etc. We make reasonable accommodations for clients and employees, and we do not discriminate based on any protected attribute including race, religion, color, national origin, gender sexual orientation, gender identity, age, or marital status. We also are a Google Cloud and Oracle partner company.
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Privileged Access Management (PAM) Engineer in New York, NY vacancy
$135k - $230k
...Summary/Purpose: We are looking for a highly skilled PAM Engineer with proven experience in Delinea Secret Server, Server Suite, and Delinea Just Enough Privilege (JEP) to manage and enhance our privileged access management infrastructure. This role involves...SuggestedWork experience placementWork from homeVisa sponsorshipWork visaMonday to Friday$150k - $170k
...contribute to the diversification and enrichment of ideas and perspectives at AHEAD. AHEAD is searching for a Senior Privileged Access Management (PAM) Engineer to be a part of our Managed Services team. This individual will lead the design, implementation, and ongoing...SuggestedWork at officeRemote work$160k - $240k
A global financial services company in New York is seeking a Senior Software Engineer for its Identity & Privileged Access Management team. The ideal candidate will design scalable identity and access control services and engineer automation for managing credentials across...Suggested- ...respectfully. JOB OVERVIEW The Identity and Access Management (IAM) Engineer is tasked to design, implement, and... ...and certifications Enforce least-privilege access principles Support compliance... ...(IGA) Privileged Access Management (PAM) Okta Jumpcloud Familiarity with...SuggestedLive inLocal areaRemote work
$150k - $170k
AHEAD seeks a Senior Privileged Access Management (PAM) Engineer to lead multi-tenant PAM solutions for our Managed Services team. This role involves architecting and implementing secure privileged access workflows and BeyondTrust capabilities. The ideal candidate will...Suggested- ...Experience : 7+ years of dedicated Identity and Access Management (IAM) engineering experience within an enterprise environment. Platform... ...lifecycle automation and access governance [3, 4]. Privileged Infrastructure : Hands-on experience operating BeyondTrust...
$158k - $279k
...Roku is seeking a senior-level Identity Engineer to enhance its Zero‑Trust architecture... ...hands‑on experience in identity and access management (IAM) and securing cloud environments... ...based access control (RBAC). Enhance privileged access management and implement scalable...Work at officeLocal areaRemote workMonday to ThursdayFlexible hours- ...hour mealtime The Identity and Access Management (IAM) team seeks a highly motivated Engineer with the following... ...modernization of our critical IAM/PAM infrastructure. The IAM... ...Governance and Administration (IGA) and Privileged Access Management. This...Full timeWork at officeRemote work
$170k - $190k
...Britive is the leader in Cloud‑Native Privileged Access Management (CPAM), delivering the industry’s... ...securing access without slowing down engineering teams. About You You are an experienced... ...IAM) and Privileged Access Management (PAM), including hands‑on familiarity with...For contractorsFor subcontractorRemote workHome officeFlexible hours$90 - $100 per hour
Job Title: Identity and Access Management (IAM) Engineer Labor Category: Specialist 3 Location: 2 Metrotech Center, Brooklyn NY, 11201 (2 Days onsite 3 days remote) Scheduled Work Hours: Normal business hours, Monday through Friday, 35 hours/week (not including mandatory...Hourly payContract workRemote workMonday to Friday$140k - $160k
Customer Success Engineer - US Location: USA - 100% remote. Akeyless... ...integrates Vaultless Secrets Management with Certificate Lifecycle Management, Next‑Gen Privileged Access Management (Secure Remote Access... ...Privileged Access Management (PAM), Hardware Security Modules (...Remote work- Job Title Identity and Access Management (IAM) Engineer Job Details Location: Brooklyn, NY - Hybrid (3 Days onsite/2 Remote) Employment Type: Full Time Duration: 1 Year with Extensions Start Date: 8/1/26 Hourly Rate: W2: $70-$83 per hour Application Deadline: 6/2...Hourly payFull timeLocal areaRemote work
- Keeper Security is hiring a Windows Systems Software Engineer to join our Privileged Access Management (PAM) engineering team. This is a 100% remote position, with an opportunity to work a hybrid schedule for candidates based in the Chicago, IL or El Dow, CA metro areas...Temporary workLocal areaRemote work
- Vizlogic Digital Solutions is seeking CyberArk PAM Engineers with 4-7 years of experience in CyberArk Privilege Cloud and PAM implementation. Candidates should have... ...on Windows/Linux administration and service account management. #J-18808-Ljbffr Vizlogic Digital Solutions
- ...Support the design and implementation of Privileged Access Management systems. Will be part of a team that is responsible for design, deployment, configuration, and maintenance of CyberArk Suite in a global environment. Development - creating new plug-ins and connectors...
$51.46 per hour
...vertically integrated investment manager with expertise in a wide... .... Job Summary The Engineer will be responsible for assisting... ...operational understanding of systems; accessibility and understanding of the... ...receive other benefits and privileges of employment, please...For contractorsLocal areaImmediate startWeekend work$260k - $270k
...customers and exabytes of data under management, Qumulo powers mission‑... ...workloads anywhere real‑time access to massive file datasets is... ..., post supervisors, pipeline engineers, and IT teams running editorial... ...Working knowledge of MAM, PAM, or workflow orchestration platforms...Local areaRemote workFlexible hours- ...Technologies is looking for a highly skilled CyberArk PAM Engineer / Architect with over 15 years of experience in... ...will be responsible for designing, implementing, and managing CyberArk solutions for securing privileged accounts across various environments. The ideal...
$184k - $230k
...Principal Engineer, Identity and Access Management At Early Warning, we've powered and protected the U.S. financial system for over thirty years... ...Infrastructure (PKI), identity and access management platforms, privileged access management, active directory, and network...Hourly payFor contractorsWork experience placementWork at officeImmediate startVisa sponsorshipWork visaFlexible hours- Job Title: IT Project Engineer Reports to: Project Engineering Manager Type: Full-Time, Salaried, Exempt Employee Shift... ...considerations, including access controls, logging, data protection... ...Conditional Access controls Least privilege and role‑based access Logging and...Full timeWork at officeShift work
- Position Name: Junior Project Engineer Reports to: Project Engineer... ...'s mission is to shoulder IT management, user support, and cybersecurity... ..., Teams, Intune, Conditional Access) Entra ID (Azure AD),... ...Conditional Access, and least privilege access models. Why Join Atlas...Work at office
- ...technology organisations as it continues to expand its security engineering function. We’re looking to speak with highly technical... ...Operating system security, platform hardening, authentication, privileged access, infrastructure security, systems engineering and large‑...
- ...tech solutions provider seeks a Systems Specialist to drive accessibility improvements through technology. This remote-friendly position... ...creating innovation roadmaps, implementing AI solutions, and managing technical vendor relationships. Candidates should have 3-5 years...Remote jobFlexible hours
- ...Description Job Description Electrical Engineer Ensign Engineering, P.C., is a NYC... ...should be motivated and have the ability to manage all facets of a project. We offer a... ...New York metropolitan area gives us ready access to an extensive pool of experienced...Contract workFor contractorsImmediate startFlexible hours
- ...preferred) Good experience in implementation and integration of Cyber-Ark's Privileged Identity Management (PIM) Suite Experience with PAM Operational tasks - Defining Access Control, User Entitlements, Manage Applications Credentials, User Access Policy Management...Remote work
- ...IAM Engineer Location: Brooklyn, NY - 11201 Duration: 1 year Job Description: Part of Infrastructure Resilience Identity and Access Management team that is tasked with providing support for multiple highly critical projects for agencies that require uptime of 24...
$53.01 per hour
...this job involves: Develop your engineering career at JLL! The Operating... ...Time Off and Company Holidays ~ Early access to earned wages through Daily Pay... ...provider of real estate and investment management services. We take our responsibility to...Hourly payDaily paidWork experience placementWork at officeMonday to Friday$91.2k - $114k
...innovation and the future of digital wealth management by building tech-forward solutions that help simplify, automate, and facilitate access to financial markets for all. Our robust... ...ABOUT THIS ROLE We are seeking a Sales Engineer to serve as a key technical expert and...Work experience placementWork at officeWork from home3 days per week$130k - $175k
...Feedonomics comes in! As a leading product feed management platform, Feedonomics works with... ...clients. In this journey, we ally with Sales Engineering, SalesOps, Global Operations, Marketing,... ...offering employee assistance programs, access to a wellness app, and diversity and...Hourly payImmediate startRemote work$120k
...This is a client-facing, hands‑on engineering role focused on delivering Modern Work transformation... ...collaboration, identity, and endpoint management platforms. You will work directly with... ...frameworks including Conditional Access, authentication, data protection, retention...Temporary workRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Privileged Access Management (PAM) Engineer. Be the first to apply!
Related searches
- identity management New York, NY
- director of inventory management New York, NY
- head of program management New York, NY
- asset management intern New York, NY
- director of materials management New York, NY
- marine resource management New York, NY
- utilization management nurse New York, NY
- international management trainee New York, NY
- threat and vulnerability management engineer New York, NY
- head of supply chain management New York, NY


