Privileged Access Management (PAM) / IAM Engineer

The Fountain Group

Mesquite (TX)

Hybrid

USD 89,544 - 103,320

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
Vision insurance
Dental insurance
Life insurance
Disability insurance

Job summary

The Fountain Group in Dallas, TX is seeking a PAM Engineer to lead the planning, design, and delivery of enterprise Privileged Access Management capabilities. You will safeguard privileged accounts, credentials, and sessions across on-premises, hybrid, and multi-cloud environments.

Responsibilities include implementing PAM solutions, enforcing least privilege, rotating credentials, and integrating PAM with IAM, infrastructure, and security tools.

Qualifications

  • 5+ years of experience, including at least 1+ year in PAM at engineer level.
  • Hands-on experience with PAM platforms and IAM/security engineering functions.
  • Experience integrating PAM with directories, auth services, servers, databases and cloud platforms.
  • Ability to develop clear technical documentation and runbooks.

Responsibilities

  • Design, implement, and maintain enterprise PAM across on-premises, hybrid, and multi-cloud environments.
  • Enforce least privilege, lifecycle management, and secure credential rotation.
  • Automate secrets management and privileged session workflows.
  • Configure session monitoring, recording, and audit capabilities.
  • Collaborate with IAM, Security, Infrastructure, Cloud, and DevOps teams.
  • Produce technical specs, implementation plans, and support documentation.
  • Troubleshoot PAM issues and support audit activities.

Skills

PAM experience
Identity and Access Management
Security engineering
Technical documentation
Analytical thinking
Troubleshooting
Cross-team collaboration
Strong communication

Education

CISSP
Security+
CyberArk certification

Tools

CyberArk
BeyondTrust
Delinea
HashiCorp Vault
Bravura Security

Job description

Pay: $65-75/hour W2. Our company offers our consultants a suite of benefits after a qualification period including health, vision, dental, life and disability insurance. Hybrid Role in Dallas: 3 days onsite / 2 days work from home. W2 candidates highly preferred.

Role Overview

The Privileged Access Management (PAM) Engineer is responsible for the planning, design, implementation, delivery, and ongoing support of enterprise PAM capabilities. This role focuses on protecting privileged accounts, credentials, secrets, and privileged sessions across on-premises, hybrid, and multi-cloud environments. The PAM Engineer will help mature the organization's PAM program by ensuring solutions are secure, scalable, reliable, and aligned with information security requirements.

Key Responsibilities
  • Design, implement, administer, and maintain enterprise Privileged Access Management solutions across on-premises, hybrid, and multi-cloud environments.
  • Enforce least privilege access models and support secure privileged account lifecycle management.
  • Automate credential rotation, password management, secrets management, and privileged access workflows.
  • Configure and support privileged session management, monitoring, recording, and audit capabilities.
  • Integrate PAM platforms with enterprise systems, including identity providers, directories, cloud platforms, infrastructure, applications, databases, and security tools.
  • Develop technical specifications, implementation plans, operational procedures, and support documentation for PAM capabilities.
  • Troubleshoot PAM-related issues, incidents, access failures, platform performance concerns, and integration challenges.
  • Support compliance, audit, and risk management activities by maintaining accurate records, reporting, and evidence of privileged access controls.
  • Partner with IAM, Information Security, Infrastructure, Cloud, Application, and Operations teams to identify privileged access risks and implement secure solutions.
  • Assist in defining PAM standards, policies, processes, and roadmap activities under the direction of IAM leadership.
Required Qualifications
  • 5+ years of experience that includes a minimum of 1+ years of PAM experience (at engineer level).
  • Hands-on experience supporting Privileged Access Management, Identity and Access Management, information security, or related security engineering functions.
  • Experience with enterprise PAM platforms such as CyberArk, BeyondTrust, Delinea, Bravura Security, HashiCorp Vault, or similar technologies.
  • Strong understanding of privileged account management, service account governance, secrets management, password vaulting, credential rotation, and access control principles.
  • Experience integrating PAM solutions with directories, authentication services, servers, databases, applications, APIs, and cloud platforms.
  • Working knowledge of Windows, Linux/Unix, databases, networking concepts, and common enterprise infrastructure patterns.
  • Ability to develop clear technical documentation, operational runbooks, process flows, and stakeholder communications.
  • Strong analytical, troubleshooting, collaboration, and communication skills.
Preferred Qualifications
  • Experience with PAM modernization, platform upgrades, disaster recovery planning, and operational resiliency improvements.
  • Familiarity with cloud security and secrets management across Microsoft Azure, AWS, Google Cloud, or similar cloud environments.
  • Experience with automation, scripting, APIs, CI/CD pipelines, or infrastructure-as-code practices.
  • Knowledge of security frameworks, audit requirements, regulatory expectations, and compliance-driven access controls.
  • Relevant certifications such as CISSP, Security+, CyberArk, BeyondTrust, Delinea, Microsoft Azure, AWS, or other security and cloud certifications.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Privileged Access Management (PAM) Engineer
Privileged Access Management (PAM) Engineer

Veriipro • Dallas (TX)

On-site
USD 120,000 - 170,000
PAM Engineer
PAM Engineer

Talon Professional Services • New York (NY)

Hybrid
USD 120,000 - 150,000
IAM/Privileged Access Management Architect
IAM/Privileged Access Management Architect

InterSources Inc • New York (NY)

Hybrid
USD 120,000 - 160,000
Security Engineer
Security Engineer

Insight Global • United States

On-site
Medical, dental, and vision insurance
HSA, FSA, and DCFSA account options
401k retirement account access with employer matching
+1
PAM Lead
PAM Lead

Veriipro • Irvine (CA)

On-site
USD 130,000 - 160,000
Senior Manager, Privileged Access Management – PAM
Senior Manager, Privileged Access Management – PAM

Jobtailor • Town of Florida (NY)

On-site
USD 140,000 - 185,000
PAM & IAM Engineer: Privileged Access Specialist
PAM & IAM Engineer: Privileged Access Specialist

The Fountain Group • Mesquite (TX)

Hybrid
Health insurance
Vision insurance
Dental insurance
+2
Identity & PAM Security Engineer
Identity & PAM Security Engineer

ApplyMint • United States

On-site
USD 120,000 - 160,000
Lead PAM Engineer – Senior
Lead PAM Engineer – Senior

Dormont Manufacturing Co • United States

On-site
USD 120,000 - 150,000
Information Technology Security Engineer
Information Technology Security Engineer

IZAR Associates, Inc. • United States

Hybrid
USD 100,000 - 130,000