Privileged Access Management Engineer
Role Summary
The Privileged Access Management Engineer is responsible for the engineering, configuration, integration, and operational enhancement of Keyloop’s Privileged Access Management capability, with a strong focus on BeyondTrust Password Safe. This role will support the design and implementation of PAM controls across infrastructure, databases, cloud platforms, developer environments, privileged accounts, service accounts, secrets, and non-human identities. The engineer will work closely with Security Engineering, IAM, Infrastructure, Cloud Operations, IT, and platform owners to onboard privileged accounts, enforce least privilege, automate lifecycle controls, improve monitoring and audit evidence, and embed PAM as a sustainable business-as-usual security control.
Key Responsibilities
- Engineer, configure, maintain, and optimise BeyondTrust Password Safe and associated PAM components.
- Support the technical design and implementation of PAM controls across Windows, Linux, databases, cloud platforms, network devices, developer platforms, and privileged applications.
- Configure managed systems, managed accounts, access policies, credential rotation, password checkout restrictions, session recording, and approval workflows.
- Develop and maintain PAM platform standards, configuration baselines, runbooks, and operational procedures.
- Lead technical onboarding of privileged accounts into BeyondTrust, including domain administrators, local administrators, sudo accounts, database administrators, cloud administrators, application administrators, and service accounts.
- Support discovery of unmanaged, shared, orphaned, duplicate, stale, and over-privileged accounts across the estate.
- Work with platform owners to define account ownership, access requirements, rotation rules, session controls, and recertification processes.
- Implement lifecycle controls for privileged users, shared accounts, break-glass accounts, service accounts, secrets, keys, and non-human identities.
- Integrate PAM with Active Directory, Microsoft Entra ID, cloud IAM, infrastructure platforms, service management workflows, logging platforms, and monitoring tools.
- Develop automation to support account discovery, onboarding, rotation validation, reporting, access reviews, and control assurance.
- Use scripting and APIs to improve PAM operational efficiency, reduce manual effort, and strengthen repeatable engineering processes.
- Support secure integration patterns for DevOps pipelines, automation accounts, secrets management, and non-human identities.
- Support the removal of standing privileged access and implementation of just-in-time access models.
- Configure risk-based approval workflows, time-bound access, session monitoring, and stronger controls for production and critical systems.
- Work with IAM, Infrastructure, Cloud Operations, and application teams to ensure privileged access is brokered through PAM wherever technically feasible.
- Help define and implement controls that prevent direct privileged login outside approved PAM workflows.
- Produce PAM reporting on privileged account coverage, rotation status, session activity, onboarding progress, exceptions, break-glass use, and access review outcomes.
- Support audit, compliance, and customer assurance activities by providing accurate evidence of PAM controls and privileged activity.
- Review PAM alerts, session logs, access patterns, and control exceptions to identify issues requiring remediation.
- Track PAM risks, operational issues, and improvement actions through to closure.
- Partner with technical teams to embed PAM requirements into new platforms, applications, cloud services, and operational processes.
- Provide technical guidance to administrators and platform owners on PAM onboarding, privileged account handling, secrets management, and secure access patterns.
- Contribute to the maturity of Keyloop’s PAM operating model, including processes, governance, ownership, reporting, and support handover.
- Stay current with PAM, IAM, cloud security, privileged threat, and BeyondTrust platform developments.
PAM Engineering & BeyondTrust Platform Management
Privileged Account Discovery, Onboarding & Lifecycle Management
Integration, Automation & Engineering Improvement
Least Privilege, JIT Access & Control Enforcement
Monitoring, Reporting & Audit Evidence
Stakeholder Engagement & Continuous Improvement
Required Experience & Qualifications
- 4–7 years of experience in Privileged Access Management, Identity and Access Management, security engineering, infrastructure security, or a related technical security role.
- Hands-on engineering experience with BeyondTrust Password Safe, including configuration, onboarding, credential rotation, access policies, session recording, reporting, and operational support.
- Experience integrating PAM with Active Directory, Microsoft Entra ID, Windows, Linux, databases, cloud platforms, service accounts, and privileged applications.
- Strong understanding of privileged access risks, least privilege, just-in-time access, break-glass processes, secrets management, and privileged session monitoring.
- Experience with scripting, automation, APIs, or configuration tooling to support repeatable PAM operations and engineering improvements.
- Experience supporting audits, evidence collection, access reviews, control testing, and remediation tracking.
Skills & Competencies
- BeyondTrust Password Safe engineering, configuration, and administration
- PAM account discovery, onboarding, credential vaulting, and rotation
- Privileged session management, recording, monitoring, and audit reporting
- IAM, Active Directory, Microsoft Entra ID, Windows, Linux, database, cloud, and service account integration
- Secrets management, non-human identity controls, and DevOps integration patterns
- Scripting, API usage, automation, reporting, and operational runbook development
- Strong analytical and problem-solving abilities
- Ability to work across technical teams and translate security requirements into practical engineering outcomes
- Clear written and verbal communication with both technical and non-technical stakeholders
- Detail-oriented approach to documentation, configuration, evidence, and operational control
- Proactive, delivery-focused, and adaptable in a dynamic environment
Technical Skills
Soft Skills
Education & Certifications (Preferred)
- Bachelor’s degree in Information Security, Computer Science, IT, Engineering, or a related field.
- Relevant certifications such as BeyondTrust product certification, CyberArk Defender/Sentry, Microsoft security certifications, CISSP, CISM, CompTIA Security+, or equivalent practical experience.
- Cloud security or IAM certifications across Microsoft Azure, AWS, or Google Cloud are advantageous.
Values & Business Alignment
Demonstrates alignment with Keyloop’s values and ethical standards. Understands Keyloop’s business objectives, security priorities, and operational context. Ensures PAM engineering activities support reduced privileged access risk, improved auditability, stronger operational resilience, and secure delivery of services.