AHEAD Logo

AHEAD

Senior Engineer - Privileged Access Management

Posted 6 Days Ago
Remote
Hiring Remotely in United States
150K-170K Annually
Senior level
Remote
Hiring Remotely in United States
150K-170K Annually
Senior level
Lead architecture, implementation, and operations of multi-tenant Privileged Access Management (PAM) services (primarily BeyondTrust) for MSP customers. Design secure privileged workflows, integrate PAM with identity/ITSM/SIEM, automate onboarding and lifecycle tasks, maintain high-availability PAM infrastructure, conduct risk assessments and audits, mentor team members, and act as PAM subject matter expert for managed services engagements.
The summary above was generated by AI
AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digital transformation.
 
At AHEAD, we prioritize creating a culture of belonging, where all perspectives and voices are represented, valued, respected, and heard. We create spaces to empower everyone to speak up, make change, and drive the culture at AHEAD. 
 
We are an equal opportunity employer, and do not discriminate based on an individual's race, national origin, color, gender, gender identity, gender expression, sexual orientation, religion, age, disability, marital status, or any other protected characteristic under applicable law, whether actual or perceived. 
 
We embrace all candidates that will contribute to the diversification and enrichment of ideas and perspectives at AHEAD. 

AHEAD is searching for a Senior Privileged Access Management (PAM) Engineer to be a part of our Managed Services team. This individual will lead the design, implementation, and ongoing operations of multi-tenant PAM solutions for our MSP customers, with a primary focus on the BeyondTrust platform.

The Senior PAM Engineer will architect secure privileged access workflows, implement enterprise-grade BeyondTrust capabilities (such as password vaulting, session management, and least-privilege endpoint controls), integrate PAM with customer identity and ITSM platforms, and serve as the subject matter expert for privileged access across our managed services portfolio.

This role requires deep technical expertise in PAM concepts and BeyondTrust technologies, strong security and infrastructure fundamentals, and the ability to lead cross-functional initiatives with customers and internal teams. The ideal candidate will have extensive experience designing and operating PAM solutions in multi-customer environments, strong scripting and automation skills, and a consulting mindset suited to Managed Services delivery.

Duties & Responsibilities:

  • Lead architecture and design of multi-tenant BeyondTrust PAM services for MSP customers, including onboarding of new tenants and standardization of service offerings.
  • Architect secure privileged access workflows for infrastructure, applications, databases, cloud platforms, and network devices, aligned to least-privilege principles and regulatory requirements.
  • Implement and maintain BeyondTrust Password Safe and related components, including:
    • Discovery and onboarding of privileged accounts and systems
    • Password rotation policies and check-in/check-out workflows
    • Session brokering, recording, and real-time monitoring
    • Approval workflows and just-in-time (JIT) access
    • Implement and maintain BeyondTrust Privilege Management for endpoints and servers (Windows and Linux/Unix), including policy design, deployment, and tuning to minimize user/admin friction while enforcing least privilege.
    • Design and maintain highly available and secure BeyondTrust infrastructure, including clustering, scaling, upgrades, patching, and disaster recovery strategies across customer environments.
    • Integrate PAM with identity and security platforms, including:
      • Active Directory / Entra ID / LDAP and other directories for authentication and group-based access
      • MFA/SSO platforms using SAML/OIDC/OAuth2
      • SIEM and logging platforms for monitoring and alerting on privileged activity
      • ServiceNow and other ITSM tools for request, approval, and ticket correlation workflows
      • Develop and maintain automation and tooling (e.g., PowerShell, Python, REST APIs) to:
        • Accelerate onboarding and lifecycle management of privileged accounts and systems
        • Enforce configuration standards and policies at scale
        • Generate reports and dashboards for compliance and operational KPIs
        • Lead end-to-end customer onboarding to the PAM service, including:
          • Requirements gathering, use case definition, and risk assessment
          • Designing onboarding playbooks and standard reference architectures
          • Coordinating with internal and customer teams to implement and validate PAM controls
          • Define and maintain standardized PAM policies and baselines across customer environments, including credential management, access approval patterns, session monitoring, and privileged elevation rules.
          • Conduct security and risk assessments of existing privileged access practices, recommend remediation plans, and track execution to closure.
          • Serve as subject matter expert and escalation point for PAM-related incidents and service requests, including troubleshooting BeyondTrust platform issues and complex access problems.
          • Collaborate with security, infrastructure, network, and application teams (internal and customer) to ensure PAM controls are aligned with broader security architecture and operational requirements.
          • Develop and maintain comprehensive documentation, including:
            • Platform architectures and configuration standards
            • Customer-specific runbooks and operational procedures
            • Onboarding and migration playbooks
            • Knowledge base articles and FAQs for internal and customer use
            • Provide mentoring and guidance to team members on PAM concepts, BeyondTrust best practices, and secure operations in a managed services context.
            • Communicate with customers and internal stakeholders with transparency, providing regular status updates, risk/issue visibility, and technical recommendations.
            • Complete training and certification as assigned to further skills and knowledge, including PAM and BeyondTrust-specific certifications where applicable.
            • *Other job duties as assigned


Education & Experience:

  • Minimum Required – A college degree or equivalent in Information Systems, Computer Science, Cybersecurity, or a related field. Unique education, specialized experience, skills, knowledge, training, or certification may be substituted for formal education.
  • Minimum of 7 years of related experience in IT operations, infrastructure engineering, or cybersecurity, with significant hands-on responsibility for privileged access controls in enterprise environments.
  • 3+ years of direct experience designing, implementing, and operating PAM solutions (BeyondTrust strongly preferred; experience with platforms such as CyberArk or Delinea is a plus).
  • Experience delivering services in a managed services or consulting capacity, including direct customer engagement and multi-tenant or multi-customer environments.
  • Demonstrated experience leading technical initiatives, driving cross-functional projects, and mentoring junior team members.
  • Experience working with regulated or compliance-driven environments (e.g., SOX, PCI DSS, HIPAA, ISO 27001) and supporting audit and evidence collection for privileged access controls.

Knowledge, Skills & Abilities:

  • Excellent written and verbal communication skills and ability to build and maintain collaborative, positive working relationships at all levels (technical and business stakeholders).
  • Strong understanding of information security principles, including least privilege, separation of duties, identity and access management, and secure system design.
  • Deep knowledge of PAM concepts and practices, including privileged account discovery, credential vaulting, session management, just-in-time access, and privileged elevation.
  • Hands-on experience with BeyondTrust products in production environments, ideally including:
    • BeyondTrust Password Safe (or BeyondInsight platform)
    • BeyondTrust Privilege Management for Windows and Unix
    • BeyondTrust Remote Support or similar tools
    • Strong understanding of authentication and authorization protocols (e.g., Kerberos, NTLM, LDAP, RADIUS, SAML, OAuth2/OIDC, API key management) and their application in PAM architectures.
    • Experience integrating PAM platforms with:
      • Active Directory / Entra ID / LDAP and group-based access models
      • MFA/SSO solutions
      • SIEM and logging tools for monitoring privileged activity
      • ServiceNow or similar ITSM systems for request and approval workflows
      • Strong scripting and automation skills (e.g., PowerShell, Python, Bash) and experience using REST APIs to integrate and automate PAM workflows.
      • Experience with Windows and Linux operating systems, including server and workstation platforms, and common administrative tools used by privileged users.
      • Knowledge of enterprise IT systems including Active Directory, networking, firewalls, storage, compute, virtualization, and cloud services, and how privileged access is managed across these domains.
      • Familiarity with monitoring and observability platforms (e.g., Elastic, LogicMonitor or similar) to track PAM infrastructure health and performance.
      • Experience working in Scrum/Agile environments and contributing to structured delivery processes, including backlog grooming, sprint planning, and tracking work against clear acceptance criteria.
      • Strong analytical and problem-solving skills, with the ability to troubleshoot complex issues across application, infrastructure, and security layers.
      • Demonstrated ability to prioritize and manage multiple concurrent efforts in a fast-paced managed services environment.

The compensation range indicated in this posting reflects the On-Target Earnings (“OTE”) for this role, which includes a base salary and any applicable target bonus amount. This OTE range may vary based on the candidate’s relevant experience, qualifications, and geographic location.  
 
Why AHEAD:
 
Through our daily work and internal groups like Moving Women AHEAD and RISE AHEAD, we value and benefit from diversity of people, ideas, experience, and everything in between.
 
We fuel growth by stacking our office with top-notch technologies in a multi-million-dollar lab, by encouraging cross department training and development, sponsoring certifications and credentials for continued learning.
 
USA Employment Benefits include: 
- Medical, Dental, and Vision Insurance 
- 401(k) 
- Paid company holidays 
- Paid time off 
- Paid parental and caregiver leave 
- Plus more! See benefits https://www.aheadbenefits.com/ for additional details. 
 
Use of AI:
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, assessing responses, or to capture recordings and create transcriptions or summaries during interviews. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans.
 
If you would like more information about how your data is processed, please refer to the Candidate Privacy Notice or contact us at [email protected]
 
You may opt-out of the review or analysis of your application and resume by AI tools by using the General Application. Please include the role you wish to apply for in the Additional Information field. You may also choose to opt-out of recording and transcription at any time, including after joining an interview.  Candidates will not be penalized for choosing to opt-out.

Similar Jobs

An Hour Ago
Easy Apply
Remote or Hybrid
USA
Easy Apply
170K-221K Annually
Senior level
170K-221K Annually
Senior level
Food • Software
Senior Backend Engineer responsible for building, deploying, and monitoring backend applications. Collaborate with product and cross-functional teams to design/version APIs, build event-driven/asynchronous systems, improve performance and reliability, and drive CI/CD and observability best practices. Ship high-quality, well-tested features and support platform scalability and maintainability.
Top Skills: Apis (Public/Partner-Facing)AWSBackground Job ProcessingCi/CdCloud InfrastructureContainerized DeploymentsDocker (Containerization)GCPMessage QueuesObservabilityPython
An Hour Ago
Remote or Hybrid
United States
85K-115K Annually
Senior level
85K-115K Annually
Senior level
Food • Retail • Sales • Manufacturing
Lead sales and merchandising for regional and national wholesale accounts, develop business plans, manage distributor relationships (UNFI, Amazon, DoorDash), forecast and analyze promotions, coordinate cross-functional activities, manage MDF and trade shows, provide data-driven insights and mentorship, and oversee a Business Development Manager. Frequent travel required.
Top Skills: ETLExcelIriMicrosoft 365NielsenPower BITableau
3 Hours Ago
Remote or Hybrid
Pennsylvania, USA
65K-153K Annually
Senior level
65K-153K Annually
Senior level
Digital Media • Information Technology • News + Entertainment
Lead and develop a team of media planners to create strategic, data-driven media plans that maximize revenue and yield. Partner with Sales, Yield, and cross-functional teams to improve planning workflows, tools, and outputs, drive operational excellence, and support product rollouts and pricing analysis.

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account