Job Title: Privileged Access Management (PAM) Engineer - Beyond Trust
Location: 1600 7th Ave Seattle, WA 98101(hybrid)
Shift: 1st (Mon to Thurs - Onsite/ Friday - Remote)
Duration: 6-month contract with potential full-time conversion
Salary: $90/hr. on W2 without benefits
Role & Responsibilities:
- Serve as the primary technical expert for Beyond Trust PAM solutions, including architecture, deployment, configuration, and optimization of password vaults and endpoint privilege management systems.
- Design and execute large-scale PAM deployments across Windows, macOS, and Linux environments, ensuring seamless integration with existing IT infrastructure.
- Develop and maintain privilege elevation policies, credential rotation schedules, access request workflows, and governance rules aligned with security and compliance standards.
- Integrate PAM solutions with ITSM platforms, SIEM tools, vulnerability scanners, directory services, and other security infrastructure to create automated privileged access workflows.
- Provide expert-level troubleshooting and technical support for PAM platform issues, performance optimization, privileged account onboarding, and user access requests.
- Ensure PAM implementations meet compliance standards such as PCI DSS, and enforce audit trails, session recording, and privileged account governance.
Required Skills & Experience:
- 4-6+ years of hands-on experience implementing and managing enterprise PAM platforms, specifically BeyondTrust Password Safe / Endpoint Privilege Management (EPM).
- Strong experience with privileged account discovery, credential management, password rotation, session management, and access request workflows using enterprise PAM solutions.
- Solid understanding of Windows Server administration, Active Directory, Group Policy, and PowerShell scripting.
- Experience with Linux/Unix system administration and shell scripting for cross-platform PAM deployments.
Preferred Qualifications & Certifications:
- Vendor certifications: Beyond Trust Certified Implementation Engineer, CyberArk Certified Delivery Engineer, Delinea Certified Professional, or equivalent.
- Security certifications: CISSP, CISM, or other relevant security credentials.
- Experience with multiple PAM vendors, platform migrations, or integrations.
- Knowledge of DevOps practices, CI/CD pipelines, Infrastructure as Code (Terraform, Ansible).
- Experience integrating PAM with ITSM platforms (ServiceNow, Jira) and SIEM tools (Splunk, QRadar).
- Understanding of Zero Trust architecture, least privilege access principles, and secrets management platforms (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault).
|