Назад
Company hidden
4 дня назад

Systems Engineer II - PAM (Cybersecurity)

99 000 - 121 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Systems Engineer II - PAM (Cybersecurity) (PAM/IAM, AWS, PKI): Engineering and supporting privileged and non-human identity controls across enterprise and cloud platforms with an accent on secrets management, certificate lifecycle automation, and privileged session governance. Focus on designing access-control workflows, eliminating long-lived credentials, troubleshooting security platforms, and supporting compliance in a 24x7 operational environment.

Location: Chicago, Illinois; hybrid work model. Candidates must independently possess eligibility to work in the United States for any employer at the date of hire. Visa sponsorship is not available.

Base pay: $99,000–$121,000 USD per year for Phoenix, AZ and Chicago, IL, plus a discretionary incentive plan and benefits.

Company

hirify.global provides payment and transaction-protection solutions, including Zelle and Paze, for financial institutions, consumers, and small businesses.

What you will do

  • Engineer, implement, and support Privileged Access Management solutions, including vaulting, session control, and Just-In-Time privileged access.
  • Administer secrets-management platforms, credential onboarding, vault configuration, and automated password and secret rotation.
  • Manage service and workload identity lifecycles, including provisioning, ownership validation, governance, and deprovisioning.
  • Support enterprise certificate lifecycle management, including issuance, renewal, revocation, and automation.
  • Design, test, and implement automation workflows for privileged identity and certificate management.
  • Provide troubleshooting, incident response, reporting, documentation, compliance support, and participation in a 24x7 on-call rotation.

Requirements

  • Bachelor’s degree or equivalent experience and 3–5 years of experience in IAM, Security Engineering, or Infrastructure Security.
  • Hands-on experience with PAM platforms such as Delinea or CyberArk, secrets-management tools such as Vault or Secret Server, or AWS IAM.
  • Experience with enterprise PKI and certificate management, including Active Directory service accounts.
  • Knowledge of RBAC, least privilege, Just-In-Time access, service/workload identity security, REST APIs, and automation tooling.
  • Scripting experience with PowerShell, Python, or Bash, plus network troubleshooting knowledge covering TCP/IP, DNS, and firewall rules.
  • U.S. work eligibility is required; visa sponsorship is unavailable. Background and drug screening are required.

Nice to have

  • Experience with dynamic secrets, workload identity, credential rotation, and privileged session management.
  • Experience engineering AWS IAM environments, cross-account trust, federated authentication, and least-privilege policies.
  • Experience embedding secrets and certificate automation into CI/CD pipelines or supporting PCI, SOX, NIST, or ISO audits.
  • Relevant security certifications such as AWS Security Specialty, HashiCorp Vault Associate, or Delinea Engineer.

Culture & Benefits

  • Hybrid collaboration model for roles based in the listed offices.
  • Medical, dental, and vision coverage, with HSA or FSA options.
  • 401(k) plan with a 100% company Safe Harbor match on the first 6% deferred.
  • Flexible or generous paid time off, 11 company holidays, and a paid volunteer day.
  • 12 weeks of paid parental leave and family-planning support.

Hiring process

  • Benefits and further details are shared during the interview process.
  • Employment eligibility is verified through E-Verify.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →