Senior Technical Engineer (PAM Engineering )
Location: Hybrid – Buffalo, New york – 4 days onsite, one day remote
Senior Technical Engineer (PAM Engineering )
Ideal Skills and Technologies for Candidate
1. Privileged Access & Secrets Management Engineering
Demonstrated expert level experience designing, implementing, and operating Privileged Access Management (PAM) and Secrets Management solutions in large, regulated enterprise environments. Strong hands on expertise with CyberArk platforms, including credential vaulting, privileged session management, access policy enforcement, audit logging, and credential lifecycle automation. Experience leveraging Azure Key Vault for secure storage and management of application secrets, keys, and certificates. Proven ability to enforce least privilege, credential rotation, session monitoring, and compliance with internal risk, audit, and regulatory standards.
______________________________
__________
2. DevOps & Automation for Security Platforms
Proven experience integrating PAM and secrets management capabilities into DevOps and application delivery pipelines. Strong automation skills using scripting and APIs (e.g., PowerShell, REST) to support scalable onboarding, credential rotation, access workflows, and platform integrations. Able to partner effectively with application, cloud, and platform teams to embed security controls into modern CI/CD and cloud native architectures while minimizing friction for development teams.
______________________________
__________
3. Enterprise Infrastructure & Cloud Security Engineering
Strong background in hybrid enterprise infrastructure and cloud environments, including Windows and Linux systems, Active Directory and Entra ID, and Azure services. Experience designing resilient, highly available, and secure PAM integrations across on premises and cloud platforms. Deep understanding of authentication, authorization, logging, monitoring, and enterprise security architecture within financial services or other highly regulated environments.
Agile shop – 3 week sprint – looking for CyberArk experience, Cloud version
CDE cert is a preference
______________________________
__________
Required / Preferred Technologies
• CyberArk Privileged Access Management (Required)
• CyberArk CDE (Cloud or DevOps Extensions) – Preferred
• Azure Key Vault
• GitLab/ Ansible
• PowerShell and REST API automation
• CI/CD and DevOps tooling integration
• Active Directory / Entra ID
• Windows and Linux platforms