Privileged Access Management (PAM) Engineer

Posted One Month Ago
Be an Early Applicant
San Jose, CA, USA
In-Office
150K-175K Annually
Senior level
Cloud • Information Technology • Logistics • Software
The Role
Design, administer, secure, and improve enterprise CyberArk PAM environments. Manage privileged, service, and application accounts across Windows, Linux, databases, networks, cloud, and applications. Integrate PAM with identity, authentication, MFA, SIEM, ticketing, and security platforms. Develop PowerShell and Python automation, support audits and incident response, troubleshoot complex infrastructure issues, and implement least-privilege and Zero Trust controls.
Summary Generated by Built In

Samsung SDS America is a leading provider of enterprise technology and digital transformation services, helping organizations modernize infrastructure, strengthen cybersecurity, and adopt cloud, AI, and data-driven technologies. As part of Samsung SDS, a global technology and logistics organization with operations across 40 countries, Samsung SDS America combines enterprise-scale technology expertise with deep experience supporting complex business enviroments.

Our teams operate at the intersection of technology, security, and business transformation—helping customers design, implement, and operate secure enterprise environments at scale. This role provides an opportunity to contribute directly to that mission by protecting some of an organization's most sensitive assets: privileged identities, credentials, administrative access, and the infrastructure they control.

Position Overview

Samsung SDS America is seeking an experienced Privileged Access Management (PAM) Engineer to design, implement, administer, secure, and continuously improve enterprise privileged-access capabilities.

This position has a strong emphasis on CyberArk or Delinea, Windows and Linux infrastructure, authentication services, privileged-account security, and enterprise identity management. The engineer will be responsible for both the technical operation of the PAM environment and the development of security controls, automation, integrations, and governance processes that reduce the risk associated with privileged access.

The ideal candidate brings7+ years of hands-on IT infrastructure and cybersecurity experience, including significant experience supporting large-scale Microsoft Active Directory and Linux environments, privileged and service accounts, authentication infrastructure, and enterprise security controls. The successful candidate will be comfortable operating at both the engineering and operational levels—designing solutions, troubleshooting complex issues, automating repetitive processes, and partnering with infrastructure, security, application, and business teams.

This position is full time onsite at our offices in San Jose, CA.

Responsibilities

  • Design, implement, administer, and continuously improve enterprise Privileged Access Management (PAM) and identity security solutions.
  • Manage privileged accounts, service accounts, application credentials, and administrative access across Windows, Linux/Unix, databases, network devices, cloud platforms, and enterprise applications.
  • Configure and maintain PAM policies, access controls, credential management, password rotation, session monitoring, and auditing capabilities.
  • Support and administer enterprise PAM platforms, with CyberArk or Delinea as the primary technology environment; experience with other leading PAM platforms is also applicable.
  • Integrate PAM solutions with Active Directory, LDAP, MFA, SSO, SIEM, ticketing systems, cloud platforms, and other enterprise security technologies.
  • Identify and remediate excessive, dormant, orphaned, shared, unmanaged, or otherwise high-risk privileged access.
  • Implement security controls aligned with Zero Trust, least privilege, and privileged-access security best practices.
  • Develop automation for account discovery, onboarding, credential management, access reviews, compliance reporting, and other PAM processes using PowerShell, Python, APIs, or other scripting technologies.
  • Troubleshoot complex identity, authentication, privileged-access, and infrastructure security issues.
  • Support PAM platform upgrades, migrations, integrations, high availability, disaster recovery, and ongoing platform optimization.
  • Partner with cybersecurity, infrastructure, network, cloud, application, and business teams to strengthen enterprise identity and privileged-access security.
  • Support security audits, compliance requirements, vulnerability remediation, and incident-response activities involving privileged accounts and credentials.

Automation & Security Operations

  • Develop automation using PowerShell, Python, Microsoft Graph/API, and other scripting technologies.
  • Automate privileged-account discovery and onboarding, password management, access reviews, service-account inventory, and compliance reporting.
  • Integrate PAM events with SIEM and security-monitoring platforms and support investigation of privileged-access events.
  • Support security audits, compliance requirements, incident response, vulnerability remediation, and privileged-credential compromise investigations.

Infrastructure & Support

  • Support secure Windows and Linux infrastructure and apply enterprise security-hardening standards.
  • Troubleshoot identity, authentication, infrastructure, and connectivity issues across complex enterprise environments.
  • Apply fundamental networking knowledge, including TCP/IP, DNS, DHCP, routing, and firewall concepts.
  • Collaborate with cybersecurity, infrastructure, network, cloud, application, and business teams to resolve complex technical issues and continuously strengthen privileged-access security.

Requirements
  • 7+ years of professional experience in IT infrastructure, cybersecurity, identity management, systems engineering, or a related field.
  • Significant hands-on experience implementing, administering, and supporting an enterprise Privileged Access Management (PAM) solution.
  • Advanced experienced managing privilege, service, applications, and administrative accounts across Active Directory, LDAP, Windows, UNIX/Linux, databases, network devices, cloud enviroments.
  • Strong enterprise-level Microsoft Active Directory and LDAP administration experiences, including forests, domains, domain controllers, sites, OUs, Group Policies, authentication, and privilege access security.
  • Strong experience with CyberArk, Delinea (including Secret Server), or comparable enterprise PAM technologies
  • Experience implementing or supporting privileged-access security models, including Tier 0/Tier 1/Tier 2 administration, administrative account controls, and security hardening.
  • Strong understanding of IAM, PAM, authentication, authorization, MFA, SSO, Zero Trust, and least-privilege principles.
  • Experience integrating PAM or IAM technologies with Active Directory, Entra ID/Azure AD, LDAP, SAML, RADIUS, TACACS+, MFA, SIEM, and other enterprise platforms.
  • Strong scripting and automation experience using PowerShell, Python, REST APIs, Microsoft Graph, or similar technologies.
  • Strong understanding of enterprise networking fundamentals, including TCP/IP, DNS, DHCP, routing, and firewall concepts.
  • Experience supporting security audits, compliance programs, vulnerability remediation, and security investigations.
  • Strong troubleshooting, analytical, communication, and problem-solving skills.

Preferred Qualifications

  • CyberArk certification or demonstrated equivalent hands-on expertise.
  • Hands-on experience with Delinea Secret Server or other Delinea PAM products.
  • Experience migrating between PAM platforms or implementing a new enterprise PAM solution.
  • Experience with CyberArk or Delinea APIs and automated account onboarding.
  • Experience managing large-scale service-account and application-credential environments.
  • Experience implementing Zero Trust and least-privilege security architectures.
  • Experience integrating PAM solutions with cloud and hybrid identity environments.
  • Experience developing automated security controls, compliance reporting, and privileged-access reviews.
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related discipline is preferred.

Benefits

Samsung SDSA offers a comprehensive suite of programs to support our employees:

  • Top-notch medical, dental, vision and prescription coverage
  • Wellness program
  • Parental leave
  • 401K match and savings plan
  • Flexible spending accounts
  • Life insurance
  • Paid Holidays
  • Paid Time off
  • Additional benefits

Samsung SDS America, Inc. is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity or expression, national origin, disability, status as a protected veteran, marital status, genetic information, medical condition, or any other characteristic protected by law.

We are committed to providing reasonable accommodations to participate in the job application or interview process for candidates with disabilities. Please let your recruiter know if you need an accommodation at any point during the interview process.

The base pay range for this role depends on appropriate skills, experience, and technical level. The base salary range is USD $150,000-175,000.

Individual base pay depends on various factors, in addition to primary work location, such as complexity and responsibility of role, job duties/requirements, and relevant experience and skills.

Certain roles are eligible for additional rewards, including annual bonus. U.S.-based employees have access to medical, dental, and vision insurance, a 401(k) plan and company match, short-term and long-term disability coverage, basic life insurance, and wellbeing benefits, among others. U.S.-based employees also receive, per calendar year, up to 10 scheduled paid holidays, and Paid Time Off.

Skills Required

  • 7+ years of professional experience in IT infrastructure, cybersecurity, identity management, systems engineering, or a related discipline
  • Extensive enterprise experience implementing, administering, and supporting CyberArk PAM
  • Experience with CyberArk Digital Vault, CPM, PVWA, PSM, PSM for SSH, CCP, AAM, and EPV
  • Experience onboarding and managing privileged accounts across Windows/Active Directory, Linux/Unix, databases, network devices, applications, and service accounts
  • Deep Microsoft Active Directory experience, including forests, domains, Domain Controllers, Sites, OUs, GPOs, and privileged-access security
  • Strong understanding of IAM, PAM, authentication, authorization, MFA, SSO, and least-privilege security concepts
  • Hands-on Windows and Linux server administration and security hardening experience
  • Strong scripting and automation capabilities using PowerShell and/or Python
  • Experience with REST APIs and automation frameworks
  • Working knowledge of Microsoft Entra ID/Azure AD, AWS IAM, LDAP, SAML, RADIUS, and/or TACACS+
  • Experience integrating PAM or identity platforms with SIEM, MFA, ticketing, and security-monitoring solutions
  • Strong understanding of enterprise networking fundamentals, including TCP/IP, DNS, and DHCP
  • Experience supporting security audits, compliance programs, vulnerability remediation, and incident-response activities
  • Strong troubleshooting, analytical, documentation, and problem-solving skills
  • Ability to collaborate effectively with infrastructure engineering, cybersecurity, application, cloud, and business teams
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related discipline
  • CyberArk certification or equivalent expertise
  • Experience with CyberArk architecture, upgrades, migrations, disaster recovery, and high-availability implementations
  • Experience with CyberArk REST APIs and automated account onboarding
  • Experience managing large-scale service-account and application-credential environments
  • Experience implementing Zero Trust security architectures
  • Familiarity with privileged-access workstation concepts and Microsoft security-tiering methodologies
  • Experience integrating PAM with cloud and hybrid identity environments
  • Experience developing automated security controls, compliance reporting, and access-review processes
  • Experience working in large, global, or highly regulated enterprise environments

Samsung SDS America, Inc. Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Samsung SDS America, Inc. and has not been reviewed or approved by Samsung SDS America, Inc..

  • Healthcare Strength — Company materials and job postings list comprehensive medical, dental, vision, and prescription coverage, often paired with wellness programs and FSAs. Built In also notes disability and life insurance, reinforcing a robust health-related package.
  • Leave & Time Off Breadth — Built In and company sources highlight generous PTO, paid holidays, and paid sick days. Multiple postings reaffirm paid time off and holidays as standard parts of the package.
  • Retirement Support — Careers pages and postings consistently include a 401(k) with employer match and savings plan. This retirement support is positioned as a core part of the total rewards offering.

Samsung SDS America, Inc. Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Hanyang
Year Founded: 1997

What We Do

Samsung SDS America is a global provider of IT services, cloud computing, digital logistics, and enterprise digital transformation solutions. They operate in IT Service and Logistics segments, offering consulting, system design, integration, and global logistics services.

Similar Jobs

Comcast Logo Comcast

Enterprise Account Executive

Digital Media • Information Technology • News + Entertainment
Remote or Hybrid
California, USA
115000 Employees
65K-116K Annually

Comcast Logo Comcast

Account Executive

Digital Media • Information Technology • News + Entertainment
Remote or Hybrid
California, USA
115000 Employees
72K-96K Annually

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Temporary Associate

eCommerce • Fashion • Retail • Sales • Wearables • Design
Hybrid
Vacaville, CA, USA
16000 Employees
15-20 Hourly

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Temporary Associate

eCommerce • Fashion • Retail • Sales • Wearables • Design
Hybrid
Barstow, CA, USA
16000 Employees
15-20 Hourly

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account