- Company Name
- TekWissen ®
- Job Title
- Privileged Access Management - Beyond Trust Engineer
- Job Description
-
**Job Title**
Privileged Access Management – BeyondTrust Engineer
**Role Summary**
Lead the design, deployment, and ongoing management of the enterprise‑wide Privileged Access Management (PAM) platform using BeyondTrust. Act as the primary technical specialist for PAM architecture, integration, policy development, and security compliance across Windows, macOS, and Linux environments. Provide expert support, troubleshooting, and continuous improvement to secure privileged accounts and meet regulatory requirements.
**Expectations**
- Deliver a 6‑month assignment with a focus on successful rollout, configuration, and optimization of BeyondTrust Password Safe and Endpoint Privilege Manager.
- Demonstrate measurable improvements in access governance, audit readiness, and operational efficiency.
- Produce actionable documentation, training materials, and best‑practice guidance for internal teams.
**Key Responsibilities**
- Architect and deploy enterprise‑wide PAM solutions, ensuring alignment with existing infrastructure and security frameworks.
- Configure password vaults, endpoint privilege management, and session management across multi‑platform environments.
- Develop and enforce privilege elevation policies, credential rotation schedules, and access request workflows.
- Integrate PAM with ITSM, SIEM, vulnerability scanners, directory services, and identity providers (SAML, OIDC, LDAP, etc.).
- Provide advanced troubleshooting, performance tuning, and onboarding support for privileged accounts.
- Maintain audit trails, session recordings, and governance controls to satisfy PCI‑DSS and other compliance mandates.
- Document architecture, procedures, and training materials for end users and support staff.
- Monitor platform health, evaluate new features, and implement best practices to enhance security posture.
**Required Skills**
- 4–6+ years of hands‑on experience with enterprise PAM platforms (BeyondTrust, CyberArk, Delinea, etc.) in large‑scale deployments.
- Vendor‑certified expertise (e.g., BeyondTrust Certified Implementation Engineer, CyberArk Certified Delivery Engineer).
- Strong knowledge of privileged account discovery, credential management, password rotation, session monitoring, and access request workflows.
- Proficiency in Windows Server administration, Active Directory, Group Policy, and PowerShell scripting.
- Linux/Unix system administration and shell scripting (Bash, Python) for cross‑platform deployments.
- Networking fundamentals: TCP/UDP protocols, ports, certificates, load balancing, and hardening.
- Experience with cloud platforms (AWS, Azure) and containerization (Docker, Kubernetes).
- Understanding of identity and access protocols (SAML, OIDC, OAuth, SCIM, LDAP) and their integration with PAM.
- Familiarity with ITSM (ServiceNow, Jira), SIEM (Splunk, QRadar), and security tools (vulnerability scanners, endpoint detection).
- Knowledge of zero‑trust, least privilege principles, and DevOps practices (CI/CD, Terraform, Ansible).
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Systems, or related field.
- Professional certifications: BeyondTrust Certified Implementation Engineer or equivalent; CyberArk Certified Delivery Engineer or similar; optional Delinea certified professional.