Senior Privileged Access Management (PAM) Specialist

ECLARO

Canton (CT)

On-site

USD 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401(k) Retirement Savings Plan
Commuter Check pre-tax commuter benefits
Medical, Dental & Vision Insurance eligibility

Job summary

ECLARO is seeking a Senior Privileged Access Management Specialist in Canton, CT. This role is critical for overseeing privileged account policies and improving the PAM program. The ideal candidate should have advanced expertise in PAM technologies, specifically BeyondTrust and Microsoft Entra PIM, and proficiency in scripting languages like PowerShell and Python.

Key responsibilities include managing PAM solutions, ensuring secure account lifecycle management, and providing advanced troubleshooting for access failures. Candidates must have strong analytical skills and attention to detail.

Qualifications

  • Strong expertise with PAM platforms like BeyondTrust or Microsoft Entra PIM.
  • Advanced proficiency in PowerShell and Python for automation.
  • Strong knowledge of Active Directory and cloud platform permissions.

Responsibilities

  • Design and manage the enterprise PAM solution.
  • Maintain and upgrade PAM infrastructure across environments.
  • Lead governance of privileged access processes.

Skills

PowerShell scripting
Python scripting
Privileged Access Management
Active Directory
Analytical skills
Verbal communication
Attention to detail

Education

Bachelor's degree in Computer Science or related field

Tools

BeyondTrust
Microsoft Entra Privileged Identity Management

Job description

Senior Privileged Access Management (PAM) Specialist – Canton, CT. Job Number: 26-00832

Position Overview

The Senior PAM Specialist is a key member of the Identity & Access Management organization responsible for overseeing the policies, controls, and technologies governing privileged accounts and elevated access across the enterprise. The role is responsible for engineering, administering and improving the enterprise PAM program, and has accountability for the full lifecycle of privileged identities, implementing technical controls to safeguard high‑risk accounts, leading major PAM platform initiatives and partnering with technology and business teams to ensure secure, compliant access to critical systems. The position requires advanced technical expertise in PAM, IAM, analytical skills, and the ability to partner across security, infrastructure, audit, and application teams to maintain a secure and compliant privileged access ecosystem.

Responsibilities
  • Design, implement, and manage the enterprise PAM solution (e.g., password vaulting, session monitoring, credential rotation, credential relationships, and privileged access integrations with applications).
  • Maintain, upgrade, and optimize PAM infrastructure and integrations across on‑prem, cloud, and SaaS environments.
  • Ensure secure onboarding and lifecycle management of privileged accounts, service accounts, and application credentials.
  • Lead governance of privileged access processes, including periodic access certifications, entitlement reviews, break‑glass monitoring, and elevated‑access lifecycle controls.
  • Develop and manage PAM dashboards, KPIs, and reporting to measure control effectiveness, highlight risk trends, and ensure compliance with internal policies and regulatory requirements (SOX, NYDFS, etc.).
  • Identify, document, and track PAM‑related issues; drive remediation efforts to closure in partnership with technology and application teams.
  • Design and implement automated solutions for privileged access reporting, session monitoring, vaulting operations, and exception management using PowerShell, Python, SQL, or workflow tools.
  • Serve as SME for PAM platforms such as BeyondTrust, Microsoft Entra Privileged Identity Management (PIM), or equivalent technologies.
  • Oversee integration of PAM controls with enterprise systems, directories, cloud platforms, and critical applications; support onboarding of new privileged accounts and systems.
  • Conduct trend analysis on PAM data to identify anomalies or unusual access patterns and escale for investigation.
  • Provide advanced Tier II‑III troubleshooting for privileged access failures, vaulting issues, session monitoring, credential rotation, and privileged access integrations.
  • Prioritize urgent PAM‑related requests, high‑risk access elevations, and break‑glass events.
  • Maintain and enhance PAM operational documentation, workflows, and knowledge‑base content.
  • Partner with Internal Audit, Cybersecurity, Infrastructure, and Application Owners to ensure privileged access processes meet regulatory and internal control expectations.
  • Advise stakeholders on RBAC, least privilege design, SoD risk identification, and privileged access architecture.
  • Participate in and contribute to security assessments, incident reviews, and access‑related investigations.
  • Collaborate on IAM and PAM strategy, policies, and continuous‑improvement initiatives.
  • Contribute to group projects, process redesign efforts, and enterprise PAM roadmap planning.
  • Cross‑train team members to maintain operational continuity and uplift team capability.
  • Provide informal mentoring to junior IAM/PAM team members.
  • Provide technical direction, support and mentoring to junior team members, application development and architecture work in a collaborative manner.
  • Participate in architecture reviews and contribute to long‑term identity security strategy.
  • Operate with a high level of independence and technical judgment.
  • Make recommendations on PAM design, control frameworks, and automation opportunities.
  • Escalate systemic risks, policy gaps, and material access control findings.
Required Qualifications
  • Strong expertise with one or more PAM platforms (BeyondTrust, Microsoft Entra PIM).
  • Advanced proficiency in scripting (PowerShell, Python) for automation, reporting, and process streamlining.
  • Deep understanding of privileged access concepts: credential vaulting, session monitoring, least privilege, SoD, break‑glass, and privilege escalation risks.
  • Strong knowledge of Active Directory, Entra ID, Windows/Linux privilege models, and cloud platform permissions (Azure, AWS).
  • Strong analytical, diagnostic, and problem‑solving skills under pressure.
  • Strong organizational skills, attention to detail, and ability to manage multiple requests.
  • Excellent written and verbal communication skills.
  • Demonstrated engagement across functional teams to drive initiatives.
  • Ability to work strategically and collaboratively across departments.
Preferred Qualifications
  • Bachelor's degree in Computer Science, Information Systems or related field.
  • 5-7 years of experience in Privileged Access Management, Identity & Access Management, or Information Security.
  • Experience supporting PAM in regulated industries (SOX, NYDFS, GLBA).
  • Strong understanding of IAM, least privilege, Zero Trust architecture, and credential security.
  • Experience with scripting languages (PowerShell, Python, Bash) and API integrations.
  • Familiarity with Windows, Linux, networking fundamentals, and cloud platforms (Azure, AWS, GCP).
  • Experience supporting audits, compliance assessments, and privileged access risk remediation.
  • Familiarity with SailPoint, Identity Governance platforms, and audit/compliance tooling.
  • Experience with workflow automation, RPA, or orchestration tools a plus.
  • Certifications a plus (e.g., CISSP, CISM, etc.).
Benefits
  • 401(k) Retirement Savings Plan administered by Merrill Lynch.
  • Commuter Check pre‑tax commuter benefits.
  • Eligibility to purchase Medical, Dental & Vision Insurance through ECLARO.

Equal Opportunity Employer: ECLARO values diversity and does not discriminate based on Race, Color, Religion, Sex, Sexual Orientation, National Origin, Age, Genetic Information, Disability, Protected Veteran Status, or any other legally protected group status, in compliance with all applicable laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Privileged Access Management Specialist -IT (Hybrid)
Senior Privileged Access Management Specialist -IT (Hybrid)

Intact Insurance Group • Farmington (CT)

Hybrid
USD 111,000 - 148,000
Comprehensive medical, dental and vision insurance
401(k) savings with annual contributions
Mental health support and paid parental leave
Privileged Access Management
Privileged Access Management

Zigabyte Corporation • Arlington (VA)

On-site
USD 120,000 - 150,000
Senior Privileged Access Architect
Senior Privileged Access Architect

ECLARO • Canton (CT)

On-site
USD 90,000 - 130,000
401(k) Retirement Savings Plan
Commuter Check pre-tax commuter benefits
Medical, Dental & Vision Insurance eligibility
PAM Engineer
PAM Engineer

RedMatter Solutions • Washington, Northern (KY)

Hybrid
USD 140,000 - 200,000
Hearing about federal compliance
PAM Specialist
PAM Specialist

Shain Associates • New York (NY)

On-site
USD 150,000 - 230,000
Information Technology Security Engineer
Information Technology Security Engineer

IZAR Associates, Inc. • United States

Hybrid
USD 100,000 - 130,000
Beyond Trust Engineer - PAM
Beyond Trust Engineer - PAM

TekWissen ® • Seattle (WA)

Hybrid
Senior Privileged Access Management Engineer
Senior Privileged Access Management Engineer

Alliant Credit Union • Illinois

Hybrid
USD 106,000 - 183,000
Annual performance bonus
Work from home up to 3 days a week
Paid parental leave
+4
Sr. PAM Lead
Sr. PAM Lead

Datum Technologies Group • City of Hudson (NY)

Hybrid
USD 150,000 - 230,000
Information Technology Security Engineer
Information Technology Security Engineer

IZAR Associates, Inc. • United States

On-site
USD 100,000 - 130,000