Privileged Access Management (Pam) Engineer

Samsung SDS America
  • San Jose, CA
    10 days ago

    Job Description

    Samsung SDS America is a leading provider of enterprise technology and digital transformation services, helping organizations modernize infrastructure, strengthen cybersecurity, and adopt cloud, AI, and data-driven technologies. As part of Samsung SDS, a global technology and logistics organization with operations across 40 countries, Samsung SDS America combines enterprise-scale technology expertise with deep experience supporting complex business enviroments.

    Our teams operate at the intersection of technology, security, and business transformation-helping customers design, implement, and operate secure enterprise environments at scale. This role provides an opportunity to contribute directly to that mission by protecting some of an organization's most sensitive assets: privileged identities, credentials, administrative access, and the infrastructure they control.

    Position Overview

    Samsung SDS America is seeking an experienced Privileged Access Management (PAM) Engineer to design, implement, administer, secure, and continuously improve enterprise privileged-access capabilities.

    This position has a strong emphasis on CyberArk, Windows and Linux infrastructure, authentication services, privileged-account security, and enterprise identity management. The engineer will be responsible for both the technical operation of the PAM environment and the development of security controls, automation, integrations, and governance processes that reduce the risk associated with privileged access.

    The ideal candidate brings7+ years of hands-on IT infrastructure and cybersecurity experience, including significant experience supporting large-scale Microsoft Active Directory and Linux environments, privileged and service accounts, authentication infrastructure, and enterprise security controls. The successful candidate will be comfortable operating at both the engineering and operational levels-designing solutions, troubleshooting complex issues, automating repetitive processes, and partnering with infrastructure, security, application, and business teams.

    This position is full time onsite at our offices in San Jose, CA.

    Responsibilities

    Priveleged Access Management/CyberArk

    • Design, implement, administer, and continuously improve the enterprise CyberArk PAM environment, including Digital Vault, CPM, PVWA, PSM, PSM for SSH, CCP, AAM, and EPV.
    • Onboard, manage, and secure privileged, service, and application accounts across Active Directory, Linux/Unix, databases, network devices, cloud platforms, applications, and infrastructure appliances.
    • Configure CyberArk safes, platforms, policies, access controls, password rotation, reconciliation, and privileged-session monitoring/recording.
    • Troubleshoot CyberArk authentication, connectivity, account onboarding, password rotation, reconciliation, and session-management issues.
    • Integrate CyberArk with Active Directory, LDAP, SIEM, MFA, ticketing, IAM, and other enterprise security platforms.
    • Support CyberArk upgrades, migrations, high availability, disaster recovery, and platform lifecycle activities.
    • Design and maintain IAM/PAM processes aligned with Zero Trust and least-privilege principles.
    • Identify and remediate excessive, dormant, orphaned, shared, unmanaged, and otherwise high-risk privileged accounts.
    • Manage privileged identities including Domain/Enterprise Admins, local administrators, service accounts, application accounts, database accounts, and network administrator accounts.
    • Integrate PAM and identity services with Microsoft Entra ID/Azure AD, AWS IAM, LDAP, SAML, RADIUS, TACACS+, MFA, and SSO.

    Automation & Security Operations

    • Develop automation using PowerShell, Python, CyberArk REST APIs, Microsoft Graph/API, and other scripting technologies.
    • Automate privileged-account discovery and onboarding, password management, access reviews, service-account inventory, and compliance reporting.
    • Integrate PAM events with SIEM and security-monitoring platforms and support investigation of privileged-access events.
    • Support security audits, compliance requirements, incident response, vulnerability remediation, and privileged-credential compromise investigations.

    Infrastructure & Support

    • Support secure Windows and Linux infrastructure and apply enterprise security-hardening standards.
    • Troubleshoot identity, authentication, infrastructure, and connectivity issues across complex enterprise environments.
    • Apply fundamental networking knowledge, including TCP/IP, DNS, DHCP, routing, and firewall concepts.
    • Collaborate with cybersecurity, infrastructure, network, cloud, application, and business teams to resolve complex technical issues and continuously strengthen privileged-access security.

    Numbers & Facts

    LocationSan Jose, CA

    Skills

    • Amazon Web Services (AWS)unmatched
    • Application Programming Interface (API)unmatched
    • Applications Securityunmatched
    • Artificial Intelligence (AI)unmatched
    • Authenticationunmatched
    • Automationunmatched
    • Business Supportunmatched
    • Business Transformationunmatched
    • Cloud Applicationsunmatched
    • Cloud Computingunmatched
    • Continuous Improvementunmatched
    • Customer Support/Serviceunmatched
    • Disaster Recoveryunmatched
    • Enterprise Protectionunmatched
    • High Availabilityunmatched
    • Identify Issuesunmatched
    • Identity Data Managementunmatched
    • Incident Responseunmatched
    • Information Technology & Information Systemsunmatched
    • Internet Securityunmatched
    • Inventory Reportsunmatched
    • LDAP (Lightweight Directory Access Protocol)unmatched
    • Linux Operating Systemunmatched
    • Logisticsunmatched
    • Microsoft Active Directoryunmatched
    • Microsoft Product Familyunmatched
    • Microsoft Windows Azureunmatched
    • Microsoft Windows Operating Systemunmatched
    • Network Administration/Managementunmatched
    • Onboardingunmatched
    • Problem Solving Skillsunmatched
    • Python Programming/Scripting Languageunmatched
    • RADIUS (Remote Authentication Dial-In User Service)unmatched
    • REST (Representational State Transfer)unmatched
    • Reconciliationunmatched
    • Regulatory Complianceunmatched
    • Riskunmatched
    • Risk Managementunmatched
    • SSH (Secure Shell)unmatched
    • Scripting (Scripting Languages)unmatched
    • Security Assertion Markup Language (SAML)unmatched
    • Security Auditingunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Security Infrastructureunmatched
    • Security Monitoringunmatched
    • Single Sign-On (SSO)unmatched
    • TACACS+ (Terminal Access Controller Access Control System Plus)unmatched
    • Technical Operationsunmatched
    • Unix Operating Systemsunmatched
    • Windows PowerShellunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder