Identity and Access Management Engineer - PAM

Aon plc

Chicago (IL)

Hybrid

USD 92,000 - 130,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

401(k) plan
Employee stock purchase plan
Comprehensive health benefits
Paid time off
Paid holidays

Job summary

Aon is seeking a Privileged Access Management (PAM) Engineer to strengthen identity and privileged-access security capabilities. You will engineer, implement and support PAM solutions with a strong focus on CyberArk Cloud, onboarding applications, managing credentials, and enforcing access policies.

You will collaborate with architecture and engineering teams to advance IAM strategy, develop automation with PowerShell or Python, troubleshoot PAM and authentication issues, and keep technical

Qualifications

  • 3+ years of relevant experience in privileged access or identity security.
  • Hands-on CyberArk experience, especially CyberArk Cloud.
  • Experience with PAM operational activities and API-based credential access.
  • Experience with endpoint privilege management technologies.
  • Hands-on experience with Windows and/or Linux infrastructure.
  • Working knowledge of Active Directory and GPOs.
  • Understanding of IAM concepts and PKI.
  • Experience scripting with PowerShell or Python.
  • Familiarity with SIEM data and security queries.
  • Ability to document technical concepts clearly.

Responsibilities

  • Engineer, implement and support PAM technologies.
  • Onboard applications, accounts and credentials into PAM platforms.
  • Maintain CyberArk and endpoint privilege policies.
  • Develop automation with PowerShell or Python to improve privileged-access processes.
  • Troubleshoot PAM, authentication and access issues; identify root causes.
  • Document configurations and platform evolutions; keep docs current.
  • Collaborate with architecture and engineering teams to advance IAM strategy.

Skills

Privileged access security
CyberArk Cloud
Windows/Linux administration
PowerShell scripting
Python scripting
Active Directory
SIEM familiarity
Agile environment
Documentation skills
Technical communication

Education

Bachelor's degree in CS/IT/Cybersecurity

Tools

CyberArk Cloud
BeyondTrust EPM
CyberArk EPM
AD/Windows tooling

Job description

Aon is looking for a Privileged Access Management (PAM) Engineer to help strengthen and evolve our identity and privileged-access security capabilities.

In this role, you will engineer, implement and support PAM solutions, with a strong focus on CyberArk Cloud. You will work with engineering, architecture and business partners to onboard applications, maintain access policies, automate processes and deliver secure, scalable solutions.

Aon is in the business of better decisions

At Aon, we shape decisions for the better to protect and enrich the lives of people around the world.

As an organization, we are united through trust as one engaged team and we are passionate about helping our colleagues and clients succeed.

What the day will look like
  • Engineer, implement and support security technologies focused on Privileged Access Management.
  • Implement and integrate PAM solutions, with a strong focus on CyberArk Cloud, and support endpoint privilege capabilities using technologies such as BeyondTrust or CyberArk EPM.
  • Onboard applications, accounts and credentials into PAM platforms while maintaining appropriate access controls and security policies.
  • Maintain and enhance CyberArk policies and support endpoint privilege policies for workstation environments.
  • Contribute to the architectural design of access controls, user entitlements, application credentials and user access policies.
  • Partner with architecture and engineering teams to advance the Identity and Access Management strategy and related roadmap.
  • Develop automation using scripting languages such as PowerShell or Python to improve privileged-access processes and capabilities.
  • Configure and support API or programmatic access to managed credentials.
  • Troubleshoot PAM, authentication and access issues, identify root causes and implement practical solutions.
  • Use relevant security and SIEM data to support troubleshooting, monitoring and informed decision-making.
  • Keep technical documentation current as platforms, configurations and environments evolve.
  • Contribute to new PAM capabilities and product features while working within an Agile delivery environment.
  • Communicate technical concepts clearly and collaborate effectively with engineering, architecture and business partners.
How this opportunity is different

You will help protect critical systems and identities by improving how privileged access is designed, managed and secured. Through thoughtful engineering, automation and collaboration, you will help make PAM capabilities more secure, scalable and effective for the teams that rely on them.

Skills and experience that will lead to success
  • 3+ years of relevant experience in privileged access, identity security or related security engineering.
  • Hands-on experience implementing, developing or supporting CyberArk, with experience in CyberArk Cloud strongly preferred for this role.
  • Experience with PAM operational activities such as credential onboarding, access administration, policy configuration and API-based credential access.
  • Experience with endpoint privilege management technologies such as BeyondTrust EPM or CyberArk EPM.
  • Hands-on experience supporting Windows and/or Linux infrastructure.
  • Working knowledge of Active Directory, including users, computers, groups, Group Policy and trusts.
  • Understanding of broader Identity and Access Management concepts such as authentication, access certification and public key infrastructure.
  • Experience developing automation with scripting tools such as PowerShell, Python or comparable languages.
  • Familiarity with SIEM technologies and querying security data.
  • Understanding of web traffic and the ability to troubleshoot authentication flows.
  • Experience contributing to technical projects in an Agile environment.
  • Ability to create clear technical documentation and communicate effectively with technical and nontechnical stakeholders.
Preferred Experience
  • Experience with both CyberArk and BeyondTrust technologies.
  • Exposure to emerging privileged-access use cases involving non-human identities (NHI) or AI-related security scenarios.
  • Broader experience across Identity and Access Management platforms and security technologies.
Education:

Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field, or equivalent years of relevant industry experience.

For positions in San Francisco and Los Angeles, we will consider for employment qualified applicants with arrest and conviction record in accordance with local Fair Chance ordinances.

Aon is not accepting unsolicited resumes from search firms for this position. If you are a search firm, you will not be compensated in any way for your submission of a candidate, even if Aon hires that candidate.

Nothing in this job description restricts management's right to assign or reassign duties and responsibilities to this job at any time.

Pay Transparency Laws:

The salary range for this position (intended for U.S. applicants) is [$92000 to $130000] annually. The actual salary will vary based on applicant’s education, experience, skills, and abilities, as well as internal equity and alignment with market data. The salary may also be adjusted based on applicant’s geographic location.

A summary of all the benefits offered for this position:

Aon offers a comprehensive package of benefits for full-time and regular part-time colleagues, including, but not limited to:

  • a 401(k) savings plan with employer contributions
  • an employee stock purchase plan
  • consideration for long-term incentive awards at Aon’s discretion
  • medical, dental and vision insurance, various types of leaves of absence, paid time off, including 12 paid holidays throughout the calendar year, 15 days of paid vacation per year, paid sick leave as provided under state and local paid sick leave laws, short-term disability and optional long-term disability, health savings account, health care and dependent care reimbursement accounts,employee and dependent life insurance and supplemental life and AD&D insurance
  • optional personal insurance policies, adoption assistance, tuition assistance, commuter benefits, and an employee assistance program that includes free counseling sessions

Eligibility for benefits is governed by the applicable plan documents and policies.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Identity and Access Management Engineer - PAM
Identity and Access Management Engineer - PAM

Aon plc • Northern (KY)

Hybrid
USD 92,000 - 130,000
401(k) savings plan with employer
Employee stock purchase plan
Long-term incentive awards
+2
Identity and Access Management Engineer - PAM
Identity and Access Management Engineer - PAM

RiseMe • Illinois

Hybrid
USD 92,000 - 130,000
Identity and Access Management Engineer - PAM
Identity and Access Management Engineer - PAM

Aon • Chicago (IL)

On-site
USD 92,000 - 130,000
Identity and Access Management Engineer (Authentication)
Identity and Access Management Engineer (Authentication)

RiseMe • Illinois

Hybrid
USD 92,000 - 130,000
401(k) plan
Employee stock purchase plan
Medical, dental, vision insurance
+6
Identity and Access Management Engineer (Authentication)
Identity and Access Management Engineer (Authentication)

Aon • Chicago (IL)

On-site
USD 92,000 - 130,000
401(k) plan
Employee stock purchase plan
Medical, dental and vision insurance
+1
Identity and Access Management Engineer (Authentication)
Identity and Access Management Engineer (Authentication)

Aon plc • Northern (KY)

Hybrid
USD 92,000 - 130,000
401(k) plan
Employee stock purchase plan
Medical, dental and vision insurance
+2
Identity and Access Management Engineer (Authentication)
Identity and Access Management Engineer (Authentication)

Aon plc • Chicago (IL)

On-site
USD 92,000 - 130,000
401(k) plan
Employee stock purchase plan
Long-term incentive
+4
PAM Engineering Lead
PAM Engineering Lead

WTW • Minneapolis (MN)

On-site
USD 130,000 - 170,000
Health benefits
401(k) plan with company contribution
Paid time off
Identity Security Specialist Solutions Engineer
Identity Security Specialist Solutions Engineer

AHEAD • Chicago (IL)

Remote
USD 120,000 - 180,000
Medical Insurance
Dental Insurance
Vision Insurance
+3
Director - Offensive Security & Assurance
Director - Offensive Security & Assurance

Aon • Utah

On-site
USD 133,000 - 175,000
401(k) employer contributions
Employee stock purchase plan
Paid holidays
+5