Privilege Access Management Engineer

HUB International

Chicago (IL)

On-site

USD 100,000 - 120,000

Full time

30 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Comprehensive benefits package

Job summary

HUB International is seeking a Security Identity PAM Engineer to implement and mature HUB's privileged access management platforms. You will focus on automation, integration, and customization of identity services across the organization.

The role requires deep IAM knowledge and hands-on experience with Delinea Secret Server, Admin by Request, Keeper, and SailPoint ISC integrations, with a Chicago reporting line. Travel up to 10% may be needed.

Qualifications

  • Bachelor's degree in technology or applicable experience.
  • 3+ years in Identity and Access Management roles.
  • 5+ years with cloud infrastructure (AWS, GCP, Azure) and O365.
  • Experience with SAML, OID, OAuth, SCIM, MFA.
  • Experience with Active Directory / MS Entra ID.
  • Experience with PowerShell, Python, shell scripting, XML, JSON, REST/SOAP.
  • Working knowledge of Active Directory, MS Entra ID, and Okta.
  • Knowledge of information security identity standards and regulatory requirements.
  • 3+ years with Delinea/Thycotic Secret Server including vaulting and rotation.
  • Experience with Admin by Request for endpoint privilege management.
  • Experience with Keeper for secrets vaulting and access provisioning.
  • Just-in-time privileged access provisioning and least-privilege enforcement.

Responsibilities

  • Implement, maintain, and develop HUB's Privileged Access Management platforms.
  • Automate, integrate, and customize identity services.
  • Provide 24/7 incident response for security events.
  • Ensure PAM tooling is operational and highly available.
  • Contribute to identity operations KPIs and reporting.
  • Maintain knowledge of IAM standards, governance, and best practices.
  • Collaborate with teams on security operations, project status, and outcomes.
  • Lead and assist in planning and executing projects with technical leadership.
  • Contribute to security requirements, standards, and reference architectures.
  • Integrate PAM platforms with SailPoint ISC and ITSM systems.

Skills

IAM concepts
SAML/OIDC/OAuth/SCIM
Active Directory / MS Entra ID
PowerShell/Python/Shell/XML/JSON/REST
Privileged access concepts
Just-in-time access

Education

Bachelor's degree

Tools

Delinea/Secret Server
Admin by Request
Keeper Secrets Manager
SailPoint ISC
Okta

Job description

At HUB International, we are a team of entrepreneurs. We believe in protecting and supporting the aspirations of individuals, families, and businesses. We help our clients evaluate their risks and develop solutions tailored to their needs. We believe in empowering our employees to learn, grow, and make a difference. Our structure enables our teams to maintain their own unique, regional culture while leveraging support and resources from our corporate centers of excellence.

HUB is a global insurance and employee benefits broker, providing a boundaryless array of business insurance, employee benefits, risk services, personal insurance, retirement, and private wealth management products and services. With over $5 billion in revenue and almost 20,000 employees in 600 offices throughout North America, HUB has grown substantially, in part due to our industry leading success in mergers and acquisitions

ABOUT THIS ROLE

The Security Identity PAM Engineer is responsible for implementing, maintaining, and developing HUB's Privileged Access Management platforms. This role focuses on automation, integration, and customization ensuring robust and scalable identity services across the organization. The ideal candidate will have strong knowledge of IAM concepts, with the ability to improve and strengthen HUB's privileged access foundations.

Objectives of this Role
  • Manages and is responsible for the successful completion of all tasks in assigned projects.
  • Contribute to Security Support and Identity Operations Team focused on maintaining the security integrity of HUB's PAM suite of applications.
  • Available 24/7 for any critical security incident response that may arise which requires immediate resolution.
  • Work to ensure security identity tooling within HUB environments is operational and operating at needed levels of service and availability.
  • Contribute to identity operations KPIs to measure operational performance.
  • Maintain current knowledge of relevant information security identity, authentication, authorization, and governance technology and techniques, bringing forth ideas for modernization and improvement.
  • Ensure identity operations practices provide a sound foundation that utilizes tools and processes for rapid identification of security events to address and mitigate risks.
  • Engage with peers regularly on security operations functions, project status, activities, and achievements.
  • Contribute to "Continuous Improvement" efforts, in respect to HUB's information security identity tooling and systems.
  • Assist in planning, organizing, and executing multiple responsibilities to achieve project goals and provide technical leadership to move operational projects to completion.
  • Contribute to security requirements, standards, procedures, and reference architectures to comply with policies and technical standards.
Daily and Monthly Responsibilities
  • Contribute with analysis, governance, and certification operations related to identity management.
  • Contribute to weekly and monthly posture and identity operations reporting.
  • Create and maintain technical documentation, including solution architecture, process flows, and configuration guides.
  • Troubleshoot PAM-related issues and ensure high availability and performance of identity services.
  • Contribute to the analysis and recommendation of upgrades, changes, implementation specific to the support and scaling of HUB's security identity operations.
  • Implement, administer, and maintain HUB's privileged access management platforms, including Delinea/Thycotic Secret Server, Admin by Request, and Keeper.
  • Manage credential vaulting, automated secret rotation, and session recording/monitoring within Secret Server.
  • Manage the lifecycle of, and certification campaigns for, HUB's privileged credentials and secrets
  • Design and maintain endpoint privilege elevation workflows and approval chains using Admin by Request.
  • Administer role-based access and shared credential structures within Keeper.
  • Integrate PAM platforms with SailPoint ISC to unify privileged account discovery and access certification.
Skills and Qualifications
  • Bachelor's degree in technology or applicable experience.
  • Related certifications (e.g., GSEC, CISSP, GIAC, AWS) preferred.
  • 3+ Years of experience within Identity and Access Management roles.
  • 5+ years of experience with cloud infrastructure (AWS, GCP, Azure) and O365 services and technology.
  • Experience with, but not excluded to: SAML, OID, oAuth, SCIM, MFA.
  • Experience working with and managing Active Directory / MS Entra ID.
  • Experience with PowerShell, python, shell scripting, XML, JSON, REST/SOAP.
  • Working knowledge of Active Directory, MS Entra ID, and Okta.
  • Knowledge of information security identity standards, principles, and practices required.
  • Knowledge of industry security standards, guidelines, and regulatory/compliance requirements related to information security such as ISO 27001, NIST 800-53, SOC2, PCI, SOX, etc.
  • 3+ years of hands-on experience with Delinea/Thycotic Secret Server, including vaulting, secret rotation, policy configuration, discovery, and reporting.
  • Experience with Admin by Request for endpoint privilege management, including elevation request/approval workflows and application control policies.
  • Experience with Keeper (Keeper Secrets Manager / Keeper Enterprise) for secrets vaulting, credential sharing, and access provisioning.
  • Knowledge of just-in-time (JIT) privileged access provisioning and least-privilege enforcement, including removal of standing local admin rights.
  • Experience with privileged session management, session recording/monitoring, and break-glass/emergency access account procedures.
  • Experience managing service account and application-to-application (A2A) credential rotation via PAM platform APIs.
  • Ability to integrate PAM platforms (Secret Server, Admin by Request, Keeper) with SailPoint ISC and ITSM/ticketing systems for unified governance and audit reporting.
  • Prioritization, decision making, critical thinking, communication, and relationship building skills.
  • Ability to work independently and in a team environment.
  • This position reports into Chicago.
  • Willingness to travel up to 10% of working time.
JOIN OUR TEAM

Do you believe in the power of innovation, collaboration, and transformation? Do you thrive in a supportive and client focused work environment? Are you looking for an opportunity to help build and drive change in a rapidly growing and evolving organization? When you join HUB International, you will be part of a community of learners and doers focused on our Core Values: entrepreneurship, teamwork, integrity, accountability, and service.

The expected salary range for this position is $ 100,000 to $120,000 and will be impacted by factors such as the successful candidate's skills, experience and working location, as well as the specific position's business line, scope and level. HUB International is proud to offer comprehensive benefit and total compensation packages which could include health/dental/vision/life/disability insurance, FSA, HAS and 401(k) accounts, paid-time-off benefits such as vacation, sick, personal, floating holidays and company holidays. In addition, eligible annual bonuses, equity and commissions may be available for some positions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IAM Architect
IAM Architect

HUB International • Chicago (IL)

Hybrid
USD 120,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+3
Manager of Security Incident Response
Manager of Security Incident Response

HUB International • Chicago (IL)

On-site
USD 130,000 - 150,000
Senior Information Technology Project Manager
Senior Information Technology Project Manager

HUB International • Chicago (IL)

On-site
USD 120,000 - 140,000
Privileged Access Engineer – PAM & IAM Automation
Privileged Access Engineer – PAM & IAM Automation

HUB International • Chicago (IL)

On-site
USD 100,000 - 120,000
Comprehensive benefits package
Manager, Security Incident Response
Manager, Security Incident Response

HUB International • Chicago (IL)

On-site
USD 130,000 - 150,000
Health/dental/vision insurance
401(k) with company match
Paid time off
Benefit Technology Specialist I, Employee Benefits
Benefit Technology Specialist I, Employee Benefits

Hub International • San Diego (CA)

Hybrid
USD 60,000 - 70,000
Insurance Due Diligence Advisor, Private Equity and M&A
Insurance Due Diligence Advisor, Private Equity and M&A

HUB International • Center Square (PA)

On-site
USD 125,000 - 175,000
Health insurance
Dental insurance
Vision insurance
+2
Insurance Due Diligence Advisor, Private Equity and M&A
Insurance Due Diligence Advisor, Private Equity and M&A

HUB International • Chicago (IL)

On-site
USD 125,000 - 175,000
Health/dental/vision
401(k) and matching
Bonuses and commissions
Senior Risk Consultant
Senior Risk Consultant

HUB International • Chicago (IL)

On-site
USD 135,000 - 150,000
Health insurance
401(k) plan
Paid time off
Insurance Due Diligence Advisor, Private Equity and M&A
Insurance Due Diligence Advisor, Private Equity and M&A

HUB International • Miami (FL)

On-site
USD 125,000 - 175,000
Health/dental/vision/life insurance
401(k) and paid time off
Bonuses, equity and commissions for 일부