Cybersecurity Engineer - PAM
Active Directory
Azure
Azure Active Directory
CI/CD
Cloud
Cloud Platforms
Credential Management
Cyberark
Cybersecurity Tools
Data Security
DevOps
DevSecOps
Identity and Access Management
Information Security
Information Technology (IT)
InfoSec
Key Vault
Privileged Access Management
Secret Management
Security
Security Automation
Security Compliance
Security Operations
Job Description
The Cybersecurity Engineer specializing in Privileged Access Management (PAM) and Secrets Management will design, implement, and support PAM and Secret lifecycle solutions across hybrid cloud environments from an onsite location in Buffalo, NY.
Responsibilities
- Design, implement, administer, and optimize enterprise PAM solutions to enforce least privilege and secure privileged access.
- Manage credential vaulting, privileged session control, access policy enforcement, credential rotation, and audit logging.
- Implement and support secrets management using Azure Key Vault for secure storage and lifecycle management of application secrets, certificates, and encryption keys.
- Develop and maintain controls that enable just-in-time access, credential rotation, and continuous privileged session monitoring.
- Ensure PAM deployments comply with security, compliance, audit, and regulatory requirements.
- Integrate PAM and secrets management capabilities into CI/CD pipelines and modern DevOps workflows.
- Develop automation with PowerShell, REST APIs, and other scripting technologies to streamline onboarding, credential management, provisioning, and lifecycle operations.
- Create reusable automation for onboarding privileged accounts, password rotation, access workflows, and platform integrations.
- Collaborate with DevOps, cloud, and application development teams to embed security controls into cloud-native and enterprise applications.
- Design and support secure PAM integrations across hybrid infrastructure including Windows, Linux, Active Directory, Entra ID, and Microsoft Azure.
- Support a highly available, resilient, and scalable PAM platform architecture.
- Implement authentication, authorization, logging, monitoring, and security controls across enterprise environments.
- Troubleshoot complex identity and privileged access issues while maintaining operational excellence.
- Partner with infrastructure, identity, cloud, application, and security teams to strengthen privileged access security.
- Participate in security architecture reviews and advise on improvements to privileged access controls.
- Support internal and external audits by providing documentation, reporting, and evidence of security controls.
- Develop operational procedures, standards, and technical documentation for PAM services.
Requirements
- This opportunity is not open to C2C relationships or visa sponsorship.
- Local candidates only.
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent professional experience.
- Demonstrated expert-level experience designing, implementing, and supporting Privileged Access Management and Secrets Management solutions within large enterprise environments.
- Strong hands-on experience with CyberArk Privileged Access Management, including:
- Credential vaulting
- Privileged session management
- Access policy management
- Credential lifecycle automation
- Audit logging
- Experience implementing and administering Azure Key Vault.
- Experience automating security processes using PowerShell and REST APIs.
- Solid understanding of least privilege, privileged identity security, credential rotation, and privileged access governance.
- Experience supporting Windows and Linux server environments.
- Strong knowledge of Active Directory and Microsoft Entra ID.
- Experience integrating security controls into DevOps and CI/CD pipelines.
- Excellent analytical, troubleshooting, communication, and collaboration skills.
Technologies
- CyberArk
- Azure Key Vault
- PowerShell
- REST APIs
- Active Directory
- Microsoft Entra ID
- Microsoft Azure
- Windows
- Linux
- GitLab
- Ansible
- CyberArk Cloud or DevOps Extensions (CDE)
Preferred Qualifications
- Experience with CyberArk Cloud or DevOps Extensions (CDE).
- Experience with GitLab and Ansible.
- Experience integrating PAM solutions with cloud-native applications and infrastructure.
- Experience supporting highly regulated environments such as financial services, healthcare, or government.
- Knowledge of enterprise authentication, authorization, logging, monitoring, and security architecture best practices.
- Industry certifications such as CyberArk Defender/Sentry, Microsoft Azure Security, CISSP, Security+ or related credentials are preferred.