S

PAM Engineering Manager - Vice President

State Street
NewPosted today

LOCATION

Hyderabad · Onsite

EXPERIENCE

16+ Years

TYPE

FullTime

SALARY

Negotiable

SKILLS REQUIRED

Secrets ManagementPrivileged Access ManagementPlatform EngineeringIdentity and Access Management

Job description

Overview

Lead engineering ownership for enterprise Privileged Access Management (PAM) capabilities within the Global Cybersecurity organization. This hands-on technical leadership role focuses on CyberArk, HashiCorp Vault, PIM, AKV, AWS, automation, platform modernization, and operational resilience in complex, highly regulated environments.

What you'll do

  • Lead the engineering lifecycle for enterprise PAM platforms, including CyberArk, HashiCorp Vault, CA-PAM migration support, PIM, AKV, AWS, and related privileged access capabilities.
  • Drive platform architecture, design, implementation, integration, and continuous improvement for privileged access services.
  • Own engineering delivery for CyberArk platform uplift, HashiCorp adoption, secrets management expansion, CPM/PSM capability development, access modernization, and migration from legacy PAM platforms.
  • Lead engineering design and implementation across CyberArk Vault, PVWA, CPM, PSM, PSMP, DR, connectors, integrations, monitoring, and platform automation.
  • Drive HashiCorp Vault engineering for cloud workload identities, Azure service principals, AWS workloads, static secrets, database secrets, certificate/PKI use cases, and application credential modernization.
  • Ensure PAM platforms are engineered for scalability, resilience, auditability, secure operations, least privilege, zero trust, credential vaulting, session monitoring, access control, and audit logging.
  • Support privileged account onboarding across Windows, Unix/Linux, databases, network devices, cloud platforms, service accounts, application accounts, and non-human identities.
  • Identify and deliver automation opportunities using APIs, scripting, CI/CD, Terraform, PowerShell, REST API, and workflow-based automation.
  • Establish reusable engineering patterns, onboarding templates, reference architectures, and technical accelerators.
  • Promote test automation, code review, technical debt reduction, platform refactoring, and continuous improvement.
  • Partner with governance and audit teams to close control gaps, generate evidence, remediate findings, and improve control traceability.
  • Drive remediation of platform vulnerabilities, configuration gaps, audit issues, and resiliency risks.
  • Integrate PAM controls with IAM, SIEM, ServiceNow, SailPoint, monitoring, change management, and incident response processes.
  • Translate business and regulatory requirements into scalable PAM engineering solutions.
  • Provide senior technical leadership during major incidents, platform escalations, design reviews, audit discussions, and program governance forums.
  • Lead, mentor, and develop a PAM engineering team and provide technical guidance across L2/L3/L4 responsibilities.
  • Build engineering capability across CyberArk, HashiCorp Vault, cloud PAM, automation, secrets management, and non-human identity security.
  • Create and maintain architecture diagrams, engineering standards, SOPs, runbooks, implementation patterns, knowledge articles, and support handover documents.
  • Establish ownership models, RACI alignment, support handoffs, escalation paths, and post-implementation validation practices.

What you'll need

  • 16+ years of technology experience, with significant experience in cybersecurity, IAM, PAM, infrastructure security, or platform engineering.
  • Strong hands-on experience with one or more leading PAM platforms such as CyberArk, HashiCorp Vault, BeyondTrust, Delinea, or CA-PAM.
  • Deep understanding of privileged account management, credential vaulting, session monitoring, password rotation, privileged access workflows, and least privilege principles.
  • Experience leading large-scale PAM engineering or modernization initiatives in complex enterprise environments.
  • Strong knowledge of CyberArk architecture and components including Vault, PVWA, CPM, PSM, PSMP, DR, connectors, policies, safes, platforms, and onboarding patterns.
  • Experience with HashiCorp Vault architecture, secrets engines, authentication methods, policies, namespaces, replication, audit logging, and application integration patterns.
  • Experience integrating PAM solutions with IAM, SIEM, ServiceNow, SailPoint, Active Directory, cloud platforms, and enterprise monitoring tools.
  • Strong understanding of Windows, Linux/Unix, databases, network devices, cloud platforms, service accounts, and application credential management.
  • Experience with platform upgrades, patching, DR validation, certificate management, vulnerability remediation, and operational readiness.
  • Experience with Agile delivery, Jira, change management, incident management, problem management, and production support governance.
  • Technical skills in CyberArk Vault, PVWA, CPM, PSM, PSMP, PTA, EPM, AIM/Conjur or Secrets Manager capabilities.
  • Technical skills in HashiCorp Vault KV, database secrets, AppRole, LDAP/OIDC, Kubernetes auth, PKI, transit, dynamic secrets, replication, and audit logging.
  • Technical skills in PowerShell, Python, Shell scripting, REST APIs, Terraform, Ansible, and CI/CD pipelines.
  • Experience with Azure, AWS, and hybrid cloud identity and access patterns.
  • Experience with ServiceNow, SailPoint, Active Directory, LDAP, SIEM, monitoring platforms, and application onboarding workflows.
  • Experience with audit evidence, access reviews, control validation, policy compliance, and risk remediation.
  • Proven ability to lead technical initiatives and drive results across teams without relying solely on direct authority.
  • Strong people leadership, mentoring, stakeholder management, and executive communication skills.
  • Ability to simplify complex technical topics for senior stakeholders, risk partners, and engineering teams.
  • Strong ownership mindset focused on stability, security, resilience, and measurable delivery outcomes.
  • Ability to operate effectively across global teams and time zones.

Nice to have

  • CyberArk Defender, Sentry, or CDE certification.
  • HashiCorp Vault Associate or Professional certification.
  • Cloud certifications in Azure or AWS.
  • Experience with non-human identity governance, secrets discovery, credential rotation automation, and elimination of hardcoded credentials.
  • Experience with PAM modernization programs, CA-PAM to CyberArk/HashiCorp migration, cloud-native PAM, and ephemeral access models.
  • Familiarity with regulatory, audit, and risk expectations in financial services.
  • Experience leading transformation from operational support models into engineering-led platform ownership.

Details

  • Location: Bangalore or Hyderabad.
  • Work across time zones and global teams to support enterprise delivery.

Read the full description and apply on the company’s own careers page.

Stay safe

Hiring on Abekus is free for applicants

We never charge a fee, and employers are prohibited from doing so. If a recruiter asks for payment, please report them right away.

PAM Engineering Manager - Vice President