Privileged Access Management (PAM) Engineer

Samsung SDS America

San Jose (CA)

On-site

USD 150,000 - 175,000

Full time

27 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical benefits
401K match
Wellness program
Parental leave
Paid Holidays
Paid Time Off

Job summary

Samsung SDS America is seeking an experienced Privileged Access Management (PAM) Engineer to design, implement, administer, secure, and continuously improve enterprise privileged-access capabilities. The role emphasizes CyberArk, Windows, and Linux infrastructure, authentication services and enterprise identity management.

The ideal candidate has 7+ years in IT infrastructure and cybersecurity, with strong AD/Linux experience, privileged accounts, and security controls. Onsite in San Jose, CA.

Qualifications

  • 7+ years of IT infrastructure and cybersecurity experience.
  • Extensive hands-on experience implementing, administering, and supporting CyberArk PAM in an enterprise environment.
  • Deep enterprise-level Microsoft Active Directory experience, including forests, domains, Domain Controllers, Sites, OUs, GPOs, and privileged-access security.
  • Strong understanding of IAM, PAM, authentication, authorization, MFA, SSO, and least-privilege security concepts.
  • Hands-on experience with Windows and Linux server administration and security hardening.
  • Strong scripting and automation capabilities using PowerShell and/or Python.
  • Experience working with REST APIs and automation frameworks; CyberArk API experience strongly preferred.
  • Working knowledge of Microsoft Entra ID/Azure AD, AWS IAM, LDAP, SAML, RADIUS, and/or TACACS+.
  • Experience integrating PAM or identity platforms with SIEM, MFA, ticketing, and security-monitoring solutions.

Responsibilities

  • Design, implement, administer and improve CyberArk PAM environment and related components.
  • Onboard, manage and secure privileged accounts across Windows, Linux, databases, and network devices.
  • Configure CyberArk safes, policies, rotations, and session monitoring.
  • Troubleshoot CyberArk authentication, onboarding, and session management issues.
  • Integrate CyberArk with AD/LDAP, SIEM, MFA, and IAM platforms.
  • Support CyberArk upgrades, migrations, DR, and lifecycle activities.
  • Design IAM/PAM processes aligned with Zero Trust and least-privilege.
  • Identify and remediate high-risk privileged accounts.

Skills

CyberArk PAM
Active Directory
PowerShell
Python
IAM concepts
Troubleshooting
Scripting

Education

Bachelor's degree in Computer Science or related field

Tools

CyberArk Digital Vault
CyberArk CPM
CyberArk PVWA
CyberArk PSM
CyberArk PSM for SSH
CyberArk CCP
CyberArk AAM
CyberArk EPV

Job description

Samsung SDS America is a leading provider of enterprise technology and digital transformation services, helping organizations modernize infrastructure, strengthen cybersecurity, and adopt cloud, AI, and data-driven technologies. As part of Samsung SDS, a global technology and logistics organization with operations across 40 countries, Samsung SDS America combines enterprise-scale technology expertise with deep experience supporting complex business enviroments.

Our teams operate at the intersection of technology, security, and business transformation—helping customers design, implement, and operate secure enterprise environments at scale. This role provides an opportunity to contribute directly to that mission by protecting some of an organization's most sensitive assets: privileged identities, credentials, administrative access, and the infrastructure they control.

Position Overview

Samsung SDS America is seeking an experienced Privileged Access Management (PAM) Engineer to design, implement, administer, secure, and continuously improve enterprise privileged-access capabilities.

This position has a strong emphasis on CyberArk, Windows and Linux infrastructure, authentication services, privileged-account security, and enterprise identity management. The engineer will be responsible for both the technical operation of the PAM environment and the development of security controls, automation, integrations, and governance processes that reduce the risk associated with privileged access.

The ideal candidate brings7+ years of hands-on IT infrastructure and cybersecurity experience, including significant experience supporting large-scale Microsoft Active Directory and Linux environments, privileged and service accounts, authentication infrastructure, and enterprise security controls. The successful candidate will be comfortable operating at both the engineering and operational levels—designing solutions, troubleshooting complex issues, automating repetitive processes, and partnering with infrastructure, security, application, and business teams.

This position is full time onsite at our offices in San Jose, CA.

Responsibilities
Priveleged Access Management/CyberArk
  • Design, implement, administer, and continuously improve the enterprise CyberArk PAM environment, including Digital Vault, CPM, PVWA, PSM, PSM for SSH, CCP, AAM, and EPV
  • Onboard, manage, and secure privileged, service, and application accounts across Active Directory, Linux/Unix, databases, network devices, cloud platforms, applications, and infrastructure appliances
  • Configure CyberArk safes, platforms, policies, access controls, password rotation, reconciliation, and privileged-session monitoring/recording
  • Troubleshoot CyberArk authentication, connectivity, account onboarding, password rotation, reconciliation, and session-management issues
  • Integrate CyberArk with Active Directory, LDAP, SIEM, MFA, ticketing, IAM, and other enterprise security platforms
  • Support CyberArk upgrades, migrations, high availability, disaster recovery, and platform lifecycle activities
  • Design and maintain IAM/PAM processes aligned with Zero Trust and least-privilege principles
  • Identify and remediate excessive, dormant, orphaned, shared, unmanaged, and otherwise high-risk privileged accounts
  • Manage privileged identities including Domain/Enterprise Admins, local administrators, service accounts, application accounts, database accounts, and network administrator accounts
  • Integrate PAM and identity services with Microsoft Entra ID/Azure AD, AWS IAM, LDAP, SAML, RADIUS, TACACS+, MFA, and SSO
Automation & Security Operations
  • Develop automation using PowerShell, Python, CyberArk REST APIs, Microsoft Graph/API, and other scripting technologies
  • Automate privileged-account discovery and onboarding, password management, access reviews, service-account inventory, and compliance reporting
  • Integrate PAM events with SIEM and security-monitoring platforms and support investigation of privileged-access events
  • Support security audits, compliance requirements, incident response, vulnerability remediation, and privileged-credential compromise investigations
Infrastructure & Support
  • Support secure Windows and Linux infrastructure and apply enterprise security-hardening standards
  • Troubleshoot identity, authentication, infrastructure, and connectivity issues across complex enterprise environments
  • Apply fundamental networking knowledge, including TCP/IP, DNS, DHCP, routing, and firewall concepts
  • Collaborate with cybersecurity, infrastructure, network, cloud, application, and business teams to resolve complex technical issues and continuously strengthen privileged-access security
Requirements
  • 7+ years of professional experience in IT infrastructure, cybersecurity, identity management, systems engineering, or a related discipline
  • Extensive hands‑on experience implementing, administering, and supporting CyberArk PAM in an enterprise environment
  • Strong experience with CyberArk components such as Digital Vault, CPM, PVWA, PSM, PSM for SSH, CCP, AAM, and EPV
  • Demonstrated experience onboarding and managing privileged accounts across Windows/Active Directory, Linux/Unix, databases, network devices, applications, and service accounts
  • Deep enterprise‑level Microsoft Active Directory experience, including forests, domains, Domain Controllers, Sites, OUs, GPOs, and privileged‑access security
  • Strong understanding of IAM, PAM, authentication, authorization, MFA, SSO, and least‑privilege security concepts
  • Hands‑on experience with Windows and Linux server administration and security hardening
  • Strong scripting and automation capabilities using PowerShell and/or Python
  • Experience working with REST APIs and automation frameworks; CyberArk API experience strongly preferred
  • Working knowledge of Microsoft Entra ID/Azure AD, AWS IAM, LDAP, SAML, RADIUS, and/or TACACS+
  • Experience integrating PAM or identity platforms with SIEM, MFA, ticketing, and security‑monitoring solutions
  • Strong understanding of enterprise networking fundamentals, including TCP/IP, DNS, and DHCP
  • Experience supporting security audits, compliance programs, vulnerability remediation, and incident‑response activities
  • Strong troubleshooting, analytical, documentation, and problem‑solving skills
  • Ability to work effectively with infrastructure engineering, cybersecurity, application, cloud, and business teams
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related discipline is preferred
Preferred Qualifications
  • CyberArk certification or demonstrated equivalent expertise
  • Experience with CyberArk architecture, upgrades, migrations, disaster recovery, and high‑availability implementations
  • Experience with CyberArk REST APIs and automated account onboarding
  • Experience managing large‑scale service‑account and application‑credential environments
  • Experience implementing Zero Trust security architectures
  • Familiarity with privileged‑access workstation (PAW) concepts and Microsoft security‑tiering methodologies
  • Experience integrating PAM with cloud and hybrid identity environments
  • Experience developing automated security controls, compliance reporting, and access‑review processes
  • Experience working within large, global, or highly regulated enterprise environments
Benefits

Samsung SDSA offers a comprehensive suite of programs to support our employees:

  • Top‑notch medical, dental, vision and prescription coverage
  • Wellness program
  • Parental leave
  • 401K match and savings plan
  • Flexible spending accounts
  • Life insurance
  • Paid Holidays
  • Paid Time off
  • Additional benefits

Samsung SDS America, Inc. is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity or expression, national origin, disability, status as a protected veteran, marital status, genetic information, medical condition, or any other characteristic protected by law.

We are committed to providing reasonable accommodations to participate in the job application or interview process for candidates with disabilities. Please let your recruiter know if you need an accommodation at any point during the interview process.

The base pay range for this role depends on appropriate skills, experience, and technical level. The base salary range is USD $150,000-175,000.

Individual base pay depends on various factors, in addition to primary work location, such as complexity and responsibility of role, job duties/requirements, and relevant experience and skills.

Certain roles are eligible for additional rewards, including annual bonus. U.S.-based employees have access to medical, dental, and vision insurance, a 401(k) plan and company match, short-term and long-term disability coverage, basic life insurance, and wellbeing benefits, among others. U.S.-based employees also receive, per calendar year, up to 10 scheduled paid holidays, and Paid Time Off.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Privileged Access Management (PAM) Engineer
Privileged Access Management (PAM) Engineer

Samsung SDS • San Jose (CA), Northern (KY)

Hybrid
USD 150,000 - 175,000
Medical coverage
Wellness program
401K match
+5
PAM Engineer: CyberArk & IAM Specialist
PAM Engineer: CyberArk & IAM Specialist

Samsung SDS America • San Jose (CA)

On-site
USD 150,000 - 175,000
Medical benefits
401K match
Wellness program
+3
Senior PAM Engineer – CyberArk & IAM Automation
Senior PAM Engineer – CyberArk & IAM Automation

Samsung SDS • San Jose (CA), Northern (KY)

Hybrid
USD 150,000 - 175,000
Medical coverage
Wellness program
401K match
+5
PAM Lead Engineer - Remote
PAM Lead Engineer - Remote

Experian • Austin (TX)

Remote
USD 180,000 - 240,000
Great compensation package and bonus plan
Core benefits including medical, dental, vision, and matching 401K
Flexible time off including volunteer and vacation
+2
Technical Architect - Privileged Access Management
Technical Architect - Privileged Access Management

Jabil • Saint Petersburg (FL)

On-site
USD 100,000 - 181,000
Short-term incentive
Health, dental, vision insurance
4 weeks paid parental leave
+2
Senior Manager, Privileged Access Management – PAM
Senior Manager, Privileged Access Management – PAM

Jobtailor • Town of Florida (NY)

On-site
USD 140,000 - 185,000
Privileged Access Management (PAM) Senior Specialist (CyberArk and HashiCorp Vault experience r[...]
Privileged Access Management (PAM) Senior Specialist (CyberArk and HashiCorp Vault experience r[...]

National Black MBA Association • United States

On-site
USD 135,000 - 182,000
Discretionary incentive
Benefits eligible
Privileged Access Engineer (PAM) with AI Capabilities
Privileged Access Engineer (PAM) with AI Capabilities

Tata Consultancy Services • Alpharetta (GA)

On-site
USD 120,000 - 130,000
Comprehensive Medical Coverage
Performance Bonus
Time Off Benefits
PAM Engineer (CyberArk/hashivault)
PAM Engineer (CyberArk/hashivault)

TEKsystems • Town of Texas (WI)

Hybrid
USD 90,000 - 103,000
Medical, dental & vision
Critical Illness, Accident, and Hosp.
401(k) Retirement Plan
+6
Privileged Access Management (PAM) Engineer - CyberArk Specialist | Cross-Border Banking and Ma[...]
Privileged Access Management (PAM) Engineer - CyberArk Specialist | Cross-Border Banking and Ma[...]

Techfellow Limited • Woodbridge Township (NJ)

Hybrid
USD 127,000 - 150,000