PAM Engineer.
Experience : 7 years.
Location : Remote.
Notice Period : Immediate to 15 days max.
The IAM/PAM Engineer is the central technical resource responsible for the hands-on implementation, configuration, scripting, and maintenance of the Delinea PAM suite.
This role translates architectural designs and business requirements into a fully functional, automated, and secure privileged access management environment.
This is a hands-on, engineering-heavy role critical to the program's success.
Key Responsibilities :
Platform Management :
- Install, configure, and maintain new modules in the Delinea platform (Secret Server, Privilege Manager, Session Manager, Secure Remote Access).
Integration & Automation :
- Develop and maintain integrations between Delinea and other enterprise systems (e.g., SailPoint for IGA, ServiceNow for ticketing, Splunk for SIEM) using APIs and PowerShell/Python scripts.
Secrets Vaulting :
- Execute the onboarding of privileged accounts, service accounts, API keys, and other secrets into Delinea Secret Server, including configuring and testing automated password rotation.
Access Control Configuration :
- Implement and manage access control policies, roles, and folders within Delinea to enforce least privilege.
Session Management :
- Configure session brokering, monitoring, and recording for RDP, SSH, and web-based connections.
Operational Support :
- Serve as the Tier 3 support escalation point for PAM-related issues, perform routine maintenance, and ensure platform health and performance.
Required Skills &
Qualifications :
- 3 years of hands-on experience implementing and administering Delinea.
- Strong scripting skills (PowerShell, Python) for automation and integration.
- In-depth knowledge of PAM and IAM concepts (provisioning, SSO, RBAC) and integration with IGA tools.
- Solid understanding of Windows and Linux security and administration.
- Experience with network protocols and security concepts (Firewalls, DNS, AD, LDAP).
Delinea Core Concepts :
- Deep understanding of PAM principles : vaulting, session management, and privilege delegation.
- Knowledge of Delinea's architecture : Secret Server or PAM Essentials components, including the Distributed Engine.
- Understanding of Secret Templates, Folders, and Access Control mechanisms within Delinea.
Authentication & Authorization :
- OAuth 2.0 / OpenID Connect (OIDC) : Skill in configuring OAuth clients in both systems for secure server-to-server communication.
- Token Management : Handling access tokens, refresh tokens, and API keys securely.
Desirable Skills &
Qualifications :
- Knowledge in SailPoint ISC Workflows and the Delinea API/PowerShell SDK.
- Ability to interpret the output of Delinea AI/PAM-I.
- Skills in platforms like Azure Logic Apps, AWS Step Functions, or Microsoft Power Automate can be useful as an integration broker.