Senior Staff Cyber Security Engineer - PAM

Synopsys Inc

Morrisville (NC)

On-site

USD 140,000 - 180,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health benefits
Total rewards program

Job summary

Synopsys Inc. seeks an experienced Privileged Access Management (PAM) leader to secure critical identities and accounts across on-premises, cloud, and hybrid environments.

You will design enterprise PAM/IGA strategies, automate onboarding, credential rotation, and access reviews, and partner with security, DevOps, and IT teams to reduce risk. You will mentor a team, drive cross-functional governance, and help advance policy, standards, and runbooks while aligning with compliance requirements and

Qualifications

  • Bachelor's degree in information security, computer science, IT, or related field.
  • Minimum 5 years in Cybersecurity/IAM/PAM with leadership experience.
  • Hands-on experience with PAM, IGA, secrets management, and lifecycle processes.
  • Strong knowledge of Zero Trust, RBAC, SoD, and authentication frameworks.
  • Experience integrating identity security with apps, cloud, and directories.
  • Advanced scripting using PowerShell, Python, REST APIs; automation workflows.
  • Experience in hybrid and cloud environments; familiarity with SAML, OAuth, OIDC, LDAP, Kerberos, MFA.
  • Understanding of NIST, CIS Controls, ISO 27001 standards; relevant security certs a plus.

Responsibilities

  • Design and implement enterprise PAM strategies and roadmaps aligned with security and compliance.
  • Architect and manage PAM/IGA/secrets management across global environments.
  • Configure onboarding, vaulting, rotation, session monitoring, and privileged workflows.
  • Develop automated workflows for provisioning, deprovisioning, access reviews, and governance.
  • Integrate PAM with directories, cloud infra, DevOps tools, ITSM, and business apps.
  • Build secrets management for apps, service accounts, credentials, APIs, and automation platforms.
  • Create scripting/automation using PowerShell, Python, REST APIs, and orchestration tools.
  • Conduct privileged access assessments, identify gaps, and drive remediation.
  • Support Identity Governance initiatives, including RBAC, joiner/mover/leaver, and SoD.
  • Collaborate with security ops, cloud, audit, compliance, and application teams.
  • Lead PAM audits and provide evidence for SOX, ISO 27001, NIST, PCI-DSS, GDPR.

Skills

PAM leadership
PowerShell
Python
REST APIs
Automation scripting
RBAC
Zero Trust
SoD
MFA
Cloud integration

Education

Bachelor's degree in Information Security

Tools

PAM platforms
IGA platforms
Secrets management
Credential vaulting

Job description

We Are:

At Synopsys, we drive the innovations that shape the way we live and connect. Our technology is central to the Era of Pervasive Intelligence, from self-driving cars to learning machines. We lead in chip design, verification, and IP integration, empowering the creation of high-performance silicon chips and software content. Join us to transform the future through continuous technological innovation.

You Are:

You are a highly skilled and experienced Privileged Access Management (PAM) leader who is passionate about securing critical systems, identities, and privileged accounts in an increasingly complex threat landscape. You understand that identities are the new security perimeter and have extensive experience designing and operating enterprise-scale Privileged Access Management (PAM) and Identity Governance and Administration (IGA) programs.

You have deep expertise with industry-leading PAM, identity governance, secrets management, and privileged session management platforms, ensuring privileged accounts, service accounts, credentials, and secrets are effectively governed, monitored, and protected across on-premises, cloud, and hybrid environments.

You thrive in environments where automation, scalability, and security are equally important. You have hands-on experience developing scripts and automation solutions using PowerShell, Python, REST APIs, and orchestration frameworks to streamline onboarding, access reviews, privileged account lifecycle management, credential rotation, and compliance reporting.

What You’ll Be Doing:
  • Designing and implementing enterprise-wide Privileged Access Management strategies and roadmaps aligned with security and compliance requirements.
  • Architecting, deploying, and managing Privileged Access Management (PAM), Identity Governance and Administration (IGA), secrets management, and privileged session management platforms across global environments.
  • Configuring and optimizing privileged account onboarding, credential vaulting, password rotation, session monitoring, session recording, and privileged access workflows.
  • Developing automated workflows for account provisioning, deprovisioning, access certification, entitlement reviews, and privileged access governance.
  • Integrating PAM and identity security platforms with enterprise directories, cloud environments, infrastructure platforms, DevOps tools, ITSM solutions, and business applications.
  • Designing and managing enterprise secrets management capabilities for applications, service accounts, privileged credentials, APIs, and automation platforms.
  • Building scripting and automation capabilities using PowerShell, Python, REST APIs, JSON, and orchestration tools to improve operational efficiency and reduce manual effort.
  • Conducting privileged access assessments, identifying security gaps, and implementing remediation strategies.
  • Supporting Identity Governance initiatives, including role-based access controls, access reviews, joiner-mover-leaver processes, and segregation of duties controls.
  • Partnering with security operations, cloud, infrastructure, audit, compliance, and application teams to ensure effective privileged access controls.
  • Leading PAM-related audits and providing evidence for SOX, ISO 27001, NIST, PCI-DSS, GDPR, and other regulatory requirements.
  • Developing PAM standards, policies, procedures, technical documentation, and operational runbooks.
  • Monitoring platform health, performance, and security while driving continuous improvement and modernization initiatives.
The Impact You Will Have:
  • Safeguard Synopsys’ most sensitive data and intellectual property against advanced cyber threats and nation-state actors.
  • Ensure compliance with a rapidly evolving landscape of regulations and standards, maintaining Synopsys’ status as a trusted partner.
  • Mitigate systemic risks across global supply chains and minimize the potential for cascading breaches in interconnected environments.
  • Leverage AI and automation to stay ahead of sophisticated attacks, driving innovation in defensive capabilities.
  • Provide strategic leadership and mentorship to build a proactive, resilient cybersecurity team.
  • Enable business agility by integrating security seamlessly into operations, supporting Synopsys’ continued growth and technological leadership.
What You’ll Need:
  • Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field.
  • Minimum of 5 years of experience in Cybersecurity, Identity and Access Management (IAM), Identity Governance, or Privileged Access Management (PAM), including at least 2 years in a senior or lead engineering role.
  • Hands-on experience implementing and supporting Privileged Access Management (PAM) platforms, Identity Governance and Administration (IGA) platforms, Secrets Management solutions, and Identity Lifecycle Management processes.
  • Strong understanding of Zero Trust Architecture, Role-Based Access Control (RBAC), Least Privilege Principles, Segregation of Duties (SoD), and Authentication and Authorization Frameworks.
  • Experience integrating identity security platforms with enterprise applications, cloud providers, security tooling, and directory services.
  • Advanced scripting and automation experience using PowerSehll, Python, REST APIs and Workflow Automation Platforms.
  • Experience supporting hybrid and cloud environments, including public cloud and SaaS platforms.
  • Familiarity with authentication protocols and identity standards such as SAML, OAuth, OIDC, LDAP, Kerberos, and Multi-Factor Authentication (MFA).
  • Strong understanding of NIST, CIS Controls, ISO 27001, Zero Trust, and identity security best practices.
  • Security certifications such as CISSP, CISM, CCSP, GIAC, Microsoft Security Certifications, or vendor-specific certifications are a plus (or willingness to obtain).
Who You Are:
  • Strategic, analytical thinker with a proactive approach to problem-solving.
  • Excellent communicator, able to articulate complex security concepts to both technical and non-technical audiences.
  • Collaborative, inclusive leader with a passion for mentorship and team development.
  • Adaptable, detail-oriented, and committed to continuous learning in a rapidly evolving threat landscape.
  • Highly ethical, trustworthy, and dedicated to protecting sensitive information and organizational integrity.
The Team You’ll Be A Part Of:

You will join Synopsys' Data & Identity Security Engineering team, a highly skilled group of security professionals focused on protecting the company's intellectual property, sensitive information, and critical business systems. The team is responsible for advancing enterprise data protection strategies, implementing industry-leading security technologies, and enabling secure collaboration across a global workforce.

Collaboration, innovation, and a shared commitment to excellence define the team's culture. Your expertise will directly contribute to strengthening Synopsys' data security posture and supporting the company's leadership in secure technology solutions.

Rewards and Benefits:

We offer a comprehensive range of health, wellness, and financial benefits to cater to your needs. Our total rewards include both monetary and non-monetary offerings.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Staff Cyber Security Engineer - Data Security
Senior Staff Cyber Security Engineer - Data Security

Synopsys Inc • Morrisville (NC)

On-site
USD 120,000 - 180,000
Cyber Security Manager
Cyber Security Manager

Synopsys, Inc. • Exton (PA)

On-site
USD 160,000 - 210,000
Hybrid work
Competitive benefits
Cyber Security Manager
Cyber Security Manager

Ansys, Inc. • Exton (PA)

On-site
USD 191,000 - 286,000
PAM Security Architect
PAM Security Architect

Compunnel, Inc. • Westlake (OH)

On-site
USD 120,000 - 150,000
Senior Offensive Security Engineer
Senior Offensive Security Engineer

Synopsys Inc • Morrisville (NC)

Hybrid
USD 140,000 - 190,000
Senior PAM Architect & IAM Leader
Senior PAM Architect & IAM Leader

Synopsys Inc • Morrisville (NC)

On-site
USD 140,000 - 180,000
Health benefits
Total rewards program
Information Technology Security Engineer
Information Technology Security Engineer

IZAR Associates, Inc. • United States

Hybrid
USD 100,000 - 130,000
Senior Technology Security Engineer (IAM)
Senior Technology Security Engineer (IAM)

Pointwest-North America • Des Moines (IA)

On-site
USD 100,000 - 130,000
Applications Engineering( Security IP), Staff Engineer-18148
Applications Engineering( Security IP), Staff Engineer-18148

Synopsys Inc • United States

On-site
USD 140,000 - 190,000
PAM Specialist
PAM Specialist

Shain Associates • New York (NY)

On-site
USD 150,000 - 230,000