- Company Name
- V Group Inc.
- Job Title
- Privileged Access Management Engineer
- Job Description
-
Job Title: Privileged Access Management Engineer
Role Summary: Design, implement, and maintain privileged identity controls for Active Directory, Entra ID, Linux, and major cloud platforms (Azure, AWS, GCP) to enforce least‑privilege, just‑in‑time access, and zero‑trust principles.
Expectations: Deliver a secure, auditable privileged access framework that reduces attack surface, improves identity hygiene, and aligns with NIST standards and enterprise Zero Trust architecture.
Key Responsibilities:
- Administer corporate PAM/vaulting platform to manage privileged credentials across AD, Entra ID, Linux, and cloud environments.
- Implement credential randomization for local/built‑in admin accounts, service accounts, and cloud root/admin accounts.
- Enforce time‑bound, approval‑based access for administrators; design JIT workflows.
- Deploy endpoint least‑privilege policies on Windows, Linux, and macOS; replace standing local admin rights with controlled elevation.
- Apply application control and privilege granularity to mitigate malware, ransomware, and insider threat risks.
- Partner with desktop engineering to balance usability and strong endpoint controls.
- Lead local administrator cleanup projects; remove unauthorized admin rights.
- Harden Entra ID and cloud tenants by monitoring stale accounts, privileged roles, and excessive permissions.
- Apply Identity Threat Detection & Response (ITDR) practices to detect and mitigate suspicious privileged activity.
- Contribute to enterprise Zero Trust initiatives for hybrid and multi‑cloud environments.
- Align privileged access controls with NIST 800‑63B and organizational policies.
- Drive adoption of passwordless authentication, MFA, and SSO for on‑prem and cloud privileged identities.
- Manage privileged roles and accounts in Azure AD, AWS IAM, and GCP IAM; design least‑privilege access for workloads, service principals, keys, and secrets.
- Integrate cloud identities with PAM vaulting, session recording, and approval workflows.
- Collaborate with IGA teams to automate provisioning, deprovisioning, and recertification of privileged accounts.
- Produce technical runbooks, architecture diagrams, operational procedures, and compliance reports.
- Partner with audit, compliance, and risk teams to demonstrate control effectiveness.
Required Skills:
- 3–5+ years in PAM, IAM, or related security engineering roles.
- Hands‑on experience with AD, Entra ID, Linux, and at least one major cloud platform (Azure, AWS, or GCP).
- Proficiency with vaulting technologies and endpoint privilege management (least privilege, privilege elevation, application control).
- Expertise in authentication methods: MFA, SSO, passwordless, Kerberos, certificate‑based access.
- Knowledge of NIST 800‑63B, Zero Trust frameworks, ITDR, and cloud security standards (CIS, CSA).
- Strong scripting/automation skills (PowerShell, Python, Bash, Terraform).
- Excellent documentation and communication abilities.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent work experience).
- Certifications are a plus: CISSP, CISM, CCSP, Azure Security Engineer, AWS Security Specialty, GIAC, or comparable credentials.