... Privileged Access Management (PAM). The PAM Engineer plays a pivotal role in ensuring secure, compliant, and tightly governed privileged access across the enterprise. This role is responsible for ...
... Privileged Access Management (PAM). The PAM Engineer plays a pivotal role in ensuring secure, compliant, and tightly governed privileged access across the enterprise. This role is responsible for ...
Job Summary The Privileged Access Management (PAM) Lead Engineer is responsible for the end-to-end design, implementation, and governance of privileged access controls across enterprise environments.
Job Summary The Privileged Access Management (PAM) Lead Engineer is responsible for the end-to-end design, implementation, and governance of privileged access controls across enterprise environments.
... Privileged Access Management (PAM). The PAM Engineer plays a pivotal role in ensuring secure, compliant, and tightly governed privileged access across the enterprise. This role is responsible for ...
... Privileged Access Management (PAM). The PAM Engineer plays a pivotal role in ensuring secure, compliant, and tightly governed privileged access across the enterprise. This role is responsible for ...
Privileged Access Management (PAM) Engineer Plano, TX Who we are Collaborative. Respectful. A place to dream and do. These are just a few words that describe what life is like at Toyota. As one of ...
Privileged Access Management (PAM) Engineer Plano, TX Who we are Collaborative. Respectful. A place to dream and do. These are just a few words that describe what life is like at Toyota. As one of ...
Privileged Access Management (PAM) Engineer
Plano, TX · On-site +1
Privileged Access Management (PAM) Engineer Plano, TX Who we are Collaborative. Respectful. A place to dream and do. These are just a few words that describe what life is like at Toyota. As one of ...
Privileged Access Management (PAM) Engineer
Plano, TX · On-site +1
Privileged Access Management (PAM) Engineer Plano, TX Who we are Collaborative. Respectful. A place to dream and do. These are just a few words that describe what life is like at Toyota. As one of ...
Role: Privileged Access Management (PAM) Architect Location: Iselin NJ (Remote) - Open to travel on need basis Type: Full-Time Main Duties & Responsibilities of the Role: * Lead the architecture ...
Quick apply
Role: Privileged Access Management (PAM) Architect Location: Iselin NJ (Remote) - Open to travel on need basis Type: Full-Time Main Duties & Responsibilities of the Role: * Lead the architecture ...
Operations Engineer - Privileged Access Management
Nashville, TN · On-site
$67K - $90K/yr
Privileged Access Management (PAM) Operations Engineer Location: Nashville, Tennessee Job Type : Full Time Your role : • A Security Tools subject matter expert is required to work within the global ...
Quick apply
Operations Engineer - Privileged Access Management
Nashville, TN · On-site
$67K - $90K/yr
Privileged Access Management (PAM) Operations Engineer Location: Nashville, Tennessee Job Type : Full Time Your role : • A Security Tools subject matter expert is required to work within the global ...
Senior Engineer - Privileged Access Management
Charleston, WV · Remote
$117K - $160K/yr
AHEAD is searching for a Senior Privileged Access Management (PAM) Engineer to be a part of our Managed Services team. This individual will lead the design, implementation, and ongoing operations of ...
Quick apply
Senior Engineer - Privileged Access Management
Charleston, WV · Remote
$117K - $160K/yr
AHEAD is searching for a Senior Privileged Access Management (PAM) Engineer to be a part of our Managed Services team. This individual will lead the design, implementation, and ongoing operations of ...
Senior Engineer - Privileged Access Management
$117K - $160K/yr
AHEAD is searching for a Senior Privileged Access Management (PAM) Engineer to be a part of our Managed Services team. This individual will lead the design, implementation, and ongoing operations of ...
Senior Engineer - Privileged Access Management
$117K - $160K/yr
AHEAD is searching for a Senior Privileged Access Management (PAM) Engineer to be a part of our Managed Services team. This individual will lead the design, implementation, and ongoing operations of ...
R0237518 Privileged Access Management Engineer The Opportunity: Everyone knows security needs to be "baked in" to a system architecture, but you know how to bake it in. You can identify and implement ...
R0237518 Privileged Access Management Engineer The Opportunity: Everyone knows security needs to be "baked in" to a system architecture, but you know how to bake it in. You can identify and implement ...
Lead Privileged Access Management (PAM) Engineer
Washington, DC · Hybrid
$85 - $96/hr
Hybrid 2 Days Onsite/3 Days Remote in Washington, DC Our client seeks a Lead Privileged Access Management (PAM) Engineer to design, implement, and operate enterprise PAM solutions across a complex ...
Quick apply
Lead Privileged Access Management (PAM) Engineer
Washington, DC · Hybrid
$85 - $96/hr
Hybrid 2 Days Onsite/3 Days Remote in Washington, DC Our client seeks a Lead Privileged Access Management (PAM) Engineer to design, implement, and operate enterprise PAM solutions across a complex ...
Senior Engineer - Privileged Access Management
Chicago, IL · On-site
$118K - $161K/yr
AHEAD is searching for a Senior Privileged Access Management (PAM) Engineer to be a part of our Managed Services team. This individual will lead the design, implementation, and ongoing operations of ...
Senior Engineer - Privileged Access Management
Chicago, IL · On-site
$118K - $161K/yr
AHEAD is searching for a Senior Privileged Access Management (PAM) Engineer to be a part of our Managed Services team. This individual will lead the design, implementation, and ongoing operations of ...
Job Summary We're looking for an experienced PAM Engineer to strengthen our cybersecurity posture ... Cloud Identity & Access * Manage privileged roles and accounts in Entra ID (Azure AD) , AWS IAM ...
Quick apply
Job Summary We're looking for an experienced PAM Engineer to strengthen our cybersecurity posture ... Cloud Identity & Access * Manage privileged roles and accounts in Entra ID (Azure AD) , AWS IAM ...
Senior Associate, Privileged Access Management Delivery Engineer
Atlanta, GA · On-site
$110K - $151K/yr
KPMG is currently seeking a Senior Associate, Privileged Access Management Delivery Engineer to join our Advisory Services practice. Responsibilities: * Support the delivery, configuration, and ...
Senior Associate, Privileged Access Management Delivery Engineer
Atlanta, GA · On-site
$110K - $151K/yr
KPMG is currently seeking a Senior Associate, Privileged Access Management Delivery Engineer to join our Advisory Services practice. Responsibilities: * Support the delivery, configuration, and ...
Saviynt IAM Staff Augmentation - Senior Identity & Access Management Engineer
Prosper, TX · Hybrid
$95K - $131K/yr
... Privileged Access & Directory Services Support and integration with Privileged Access Management (PAM) platforms Active Directory engineering in hybrid environments (on-prem + cloud) Enforcement of ...
Quick apply
Saviynt IAM Staff Augmentation - Senior Identity & Access Management Engineer
Prosper, TX · Hybrid
$95K - $131K/yr
... Privileged Access & Directory Services Support and integration with Privileged Access Management (PAM) platforms Active Directory engineering in hybrid environments (on-prem + cloud) Enforcement of ...
Privileged Access Management - Platform Engineering Lead
North Chicago, IL · On-site +1
$109K/yr
In the role of Privileged Access Management - Platform Lead, you'll tackle complex, high-stakes challenges at the intersection of security engineering and enterprise strategy-owning and evolving a ...
Privileged Access Management - Platform Engineering Lead
North Chicago, IL · On-site +1
$109K/yr
In the role of Privileged Access Management - Platform Lead, you'll tackle complex, high-stakes challenges at the intersection of security engineering and enterprise strategy-owning and evolving a ...
Lead Privileged Access Management (PAM) Engineer
Washington, DC · Hybrid
$85 - $96/hr
Hybrid 2 Days Onsite/3 Days Remote in Washington, DC Our client seeks a Lead Privileged Access Management (PAM) Engineer to design, implement, and operate enterprise PAM solutions across a complex ...
Lead Privileged Access Management (PAM) Engineer
Washington, DC · Hybrid
$85 - $96/hr
Hybrid 2 Days Onsite/3 Days Remote in Washington, DC Our client seeks a Lead Privileged Access Management (PAM) Engineer to design, implement, and operate enterprise PAM solutions across a complex ...
Athenix Special Missions is seeking a Privileged Access Management (PAM) Engineer Journeyman in MacDill Air Force Base (Tampa), Florida! Athenix Special Missions is a world leader in designing ...
Athenix Special Missions is seeking a Privileged Access Management (PAM) Engineer Journeyman in MacDill Air Force Base (Tampa), Florida! Athenix Special Missions is a world leader in designing ...
Identity & Access Management Engineer
Chicago, IL · On-site
$118K - $161K/yr
Senior Identity & Access Management Engineer Location: Chicago, IL (Hybrid) Employment Type ... CyberArk or other privileged access management solutions Integration & Automation * Experience ...
Quick apply
Identity & Access Management Engineer
Chicago, IL · On-site
$118K - $161K/yr
Senior Identity & Access Management Engineer Location: Chicago, IL (Hybrid) Employment Type ... CyberArk or other privileged access management solutions Integration & Automation * Experience ...
Athenix Special Missions is seeking a Privileged Access Management (PAM) Engineer Journeyman in MacDill Air Force Base (Tampa), Florida! Athenix Special Missions is a world leader in designing ...
Quick apply
Athenix Special Missions is seeking a Privileged Access Management (PAM) Engineer Journeyman in MacDill Air Force Base (Tampa), Florida! Athenix Special Missions is a world leader in designing ...
Privileged Access Management Engineer information
See salary details
$61.5K - $74.6K
0% of jobs
$74.6K - $87.7K
2% of jobs
$87.7K - $100.8K
3% of jobs
$100.8K - $113.9K
6% of jobs
$113.9K - $127K
5% of jobs
$127K - $140K
4% of jobs
$141.4K is the 25th percentile. Wages below this are outliers.
$140K - $153.1K
39% of jobs
$161.2K is the 75th percentile. Wages above this are outliers.
$153.1K - $166.2K
24% of jobs
$166.2K - $179.3K
2% of jobs
$179.3K - $192.4K
0% of jobs
$192.4K - $205.5K
14% of jobs
$61.5K
$152.8K
$205.5K
How much do privileged access management engineer jobs pay per year?
What are the key skills and qualifications needed to thrive in the Privileged Access Management Engineer position, and why are they important?
A Privileged Access Management (PAM) Engineer needs a strong background in information security, identity and access management principles, and experience with enterprise PAM solutions. Familiarity with tools such as CyberArk, BeyondTrust, or Thycotic, and relevant certifications like CISSP or CompTIA Security+ are highly valued. Exceptional problem-solving skills, attention to detail, and effective communication enable success in a collaborative environment. These skills are critical for safeguarding sensitive assets, ensuring regulatory compliance, and supporting secure business operations.
What are some typical daily responsibilities of a Privileged Access Management Engineer?
As a Privileged Access Management Engineer, your daily tasks often involve managing user access permissions, maintaining and upgrading PAM solutions, and monitoring for unauthorized access attempts. You may work closely with IT security and operations teams to enforce security policies and address access-related incidents. Routine responsibilities also include auditing privileged accounts, updating documentation, and participating in compliance and risk assessments. This role requires you to be proactive and responsive, ensuring that only authorized personnel can access critical systems and sensitive data.
What is a Privileged Access Management Engineer job?
A Privileged Access Management (PAM) Engineer is responsible for designing, implementing, and maintaining security controls to manage and protect privileged accounts within an organization. They work with PAM solutions to enforce least privilege access, monitor privileged session activity, and prevent unauthorized access to critical systems. PAM Engineers collaborate with security teams to ensure compliance with industry standards and regulatory requirements while continuously improving identity and access management processes.

Full-time
Posted 6 days ago
IDEXX Laboratories rating
7.4
Based on 54 frontline employees who took The Breakroom Quiz
60th of 103 rated laboratories
Job description
IT accelerates the success of IDEXX employees and customers by providing scalable, secure, and innovative technology solutions. As a global organization supporting critical systems across cloud and onprem environments, we are committed to maturing our identity and security posture-particularly in the area of Privileged Access Management (PAM).
The PAM Engineer plays a pivotal role in ensuring secure, compliant, and tightly governed privileged access across the enterprise. This role is responsible for planning, implementing, and operating our PAM platform (e.g., CyberArk Privilege Cloud), supporting our strategy to reduce risk, strengthen identity governance, and meet audit and regulatory requirements.
This position partners closely with Security, Infrastructure, Cloud Engineering, Application teams, and IAM functions to enforce best practices, monitor privileged activity, and support the operational lifecycle of privileged accounts across servers, endpoints, cloud platforms, network devices, and SaaS environments.
If you are passionate about reducing privileged-access risk and enabling secure operations through automation, governance, and modern PAM tooling, we encourage you to apply.
In this role, you willbe responsible for:
Privileged Access Platform Administration
- Deploy, configure, andmaintainthe enterprise PAM platform (e.g., CyberArk) including credential vaulting, session management, password rotation, andjustIntime(JIT) access.
- Manage platform components such as vault servers, connectors, session recording infrastructure, credential providers, and privileged session gateways.
- Ensure high availability, performance optimization, and adherence to operational SLAs.
Privileged Account & Credential Lifecycle Management
- Onboard andmaintainprivileged accounts across Windows, Linux, network devices, databases, cloud platforms (Azure, AWS, GCP), and SaaS admin consoles.
- Implement automated password rotation, check-in/checkout workflows, and lifecycle governance for service accounts, application credentials, and secrets.
- Maintain leastprivilege standards, including enforcement of cloudonly admin accounts and removal of unnecessary or stale privileged principals.
JIT Access, PIM/PAM Integration & Access Elevation
- Administerjustintimeelevation policies for cloud roles (e.g., Entra PIM) and integrate them with the enterprise PAM strategy.
- Configureapprovalworkflows, MFA enforcement, activation duration settings, and monitoring for high-risk role activation.
- Ensure alignment between PIM (role elevation) and PAM (credential vaulting/session control) platforms.
Security, Compliance & Audit Support
- Maintaincontrolsrequiredfor SOX, SOC2, ISO, and internal/external audit reviews of privileged access activity.
- Support regular access reviews for privileged accounts and roles, collaborating with managers and system owners.
- Provide evidence for audits related to privileged access, session logs, credential governance, and administrative workflows.
Automation, Scripting & Operational Efficiency
- Develop andmaintainautomation (e.g., PowerShell, Python, APIs) for onboarding, credential rotation, vault management, and reporting.
- Build integrations between PAM and enterprise systems such as ServiceNow, SIEM, CMDB, IGA platforms, and cloud identity services.
- Streamline manual processes and reduce ticket volume through automation and mature workflow design.
Monitoring&Incident Response
- Monitor for suspicious privileged behavior, anomalous sign-ins, risky activations, or vault activity using SIEM and platform analytics.
- Maintain and periodically validatebreakglass/emergency access controls across critical systems.
- Serve as an escalation point for privileged access issues or failuresimpactingoperations.
CrossFunctional Collaboration & Governance
- Partner with infrastructure, application, cloud, and security teams to enforce standards for privileged access governance.
- Assistsystem owners inidentifyingwhat constitutes privileged access and mapping roles, entitlements, and required controls.
- Contribute to PAM roadmap planning, tool evaluations, and ongoing PAM maturity initiatives.
Location: Driving distance to our Westbrook, Maine HQ. Flexible hybrid on-site of 8 days per month/2 days per week on average, is required.
What You Will Need to Succeed:
- 2 to 5 years of hands-on experience administering enterprise PAM solutions such as CyberArk.
- Strong understanding of privileged access concepts including:
- Credential vaulting
- Session monitoring and recording
- JIT elevation & PIM
- Password rotation
- Tiering/Zero Trust/least privilege
- Expertisewith Windows/MacOS/Linuxadministration, Active Directory/Entra ID, cloud IAM roles (Azure, AWS, GCP), and integration of privileged accounts across these systems.
- Scripting & Automation: Proficiencyin PowerShell, APIs, JSON, and automation frameworks.Experience automating password rotation, onboarding workflows, and data collection.
- Soft Skills: Strong analytical abilities and troubleshooting skills for complex privileged access scenarios. Excellent communication skills and ability to translate technical concepts to nontechnical partners. Demonstratedcross-functionalcollaboration with security, engineering, and operations teams.
- Compliance & Security Knowledge: Familiarity with audits, risk controls, and compliance frameworks (SOX, SOC2, ISO 27001).Experience supporting audit evidence gathering and implementing controls to reduce privileged access risk.
Why IDEXX?
We're proud of the work we do, because our work matters. An innovation leader in every industry we serve, we follow our Purpose and Guiding Principles to help pet owners worldwide keep their companion animals healthy and happy, to ensure safe drinking water for billions, and to help farmers protect livestock and poultry from diseases. We have customers in over 175 countries and a global workforce of over 10,000 talented people.
So, what does that mean for you? We enrich the livelihoods of our employees with a positive and respectful work culture that embraces challenges and encourages learning and discovery. At IDEXX, you will be supported by competitive compensation, incentives, and benefits while enjoying purposeful work that drives improvement.
Let's pursue what matters together.
IDEXX values a diverse workforce and workplace and strongly encourages women, people of color, LGBTQ+ individuals, people with disabilities, members of ethnic minorities, foreign-born residents, and veterans to apply.
IDEXX is an equal opportunity employer. Applicants will not be discriminated against because of race, color, creed, sex, sexual orientation, gender identity or expression, age, religion, national origin, citizenship status, disability, ancestry, marital status, veteran status, medical condition, or any protected category prohibited by local, state, or federal laws.
#LI-EV1
What IDEXX Laboratories employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About IDEXX Laboratories
Sourced by ZipRecruiter
Industry
Manufacturing
Company size
10,000+ Employees
Headquarters location
Westbrook, ME, US
Year founded
1983