PAM Lead Engineer jobs in United States
cer-icon
Apply on Employer Site
company-logo

TIH · 3 months ago

PAM Lead Engineer

100 CRC Insurance Group is seeking a PAM Lead Engineer to oversee the organization’s privileged access management program. The role involves designing and implementing strategies to manage privileged access, collaborating with various teams to enhance security measures, and mentoring PAM engineers.

Insurance
check
Comp. & Benefits
check
H1B Sponsor Likelynote

Responsibilities

Develop and implement strategies, policies, and controls to reduce privileged access and streamline the management of privileged entitlements, including hardening PAM policies to ensure robust controls for critical applications supporting a least privilege model. Track reduction in privileged account incidents and regularly report on improvements in access review completion times to demonstrate measurable progress
Assess privileged access risks and recommend solutions in partnership with IT, security, and business teams, incorporating Zero Trust framework principles and enforcing least privilege access policies to minimize risk and ensure robust protection of critical assets. Measure compliance rates against audit requirements and report on mitigation effectiveness to ensure accountability
Lead roadmap development and continuous improvement of PAM frameworks. Design, implement, and manage PAM solutions to safeguard critical systems and data, with regular tracking and reporting on the adoption and effectiveness of new PAM features and controls
Lead integration of PAM tools with IAM platforms and relevant enterprise applications, measuring successful integration milestones and tracking reductions in access-related incidents post-implementation
In partnership with IT, define and implement Just-in-Time (JIT) and Role-Based Access Control (RBAC) models related to privileged access and entitlements leveraging IAM automation framework. Monitor and report on the reduction of unnecessary entitlements
Act as a Subject Matter Expert (SME) and technical lead for PAM initiatives. Provide expert guidance, training, and support for technical teams and end users regarding privileged access and evaluate the effectiveness of training programs through feedback and improvement in compliance metrics
Align PAM architecture and processes with regulatory frameworks (CFIUS, SOX, HIPAA, GDPR, PCI). Perform regular access reviews of privileged accounts, permissions, and entitlements across environments. Measure and report on access review completion rates and compliance with Cyber policies and audit requirements
Monitor, audit, and report on privileged account activities for compliance and anomaly detection. Define and implement proactive and/or automated controls when possible and regularly share metrics on detection rates and remediation times
Respond to and investigate privileged account security incidents, drive root cause analysis and remediation, and track incident response times and reductions in repeat incidents to demonstrate ongoing improvement
Develop/enhance, document, and enforce privileged account operational lifecycle policies, standards, and procedures, measuring adherence rates and reporting on policy update frequency to ensure continual alignment with organizational needs
Stay informed on emerging PAM trends, threats, and technologies; implement improvements accordingly and communicate the impact of these enhancements via quarterly progress reports
Mentor and lead PAM engineers in project and daily operations, monitoring skill development and project success rates to ensure effective team growth and operational excellence
Continue to maintain a comprehensive approach to privileged access management by regularly reviewing and updating responsibilities to reflect changes in technology, regulations, and organizational needs, and report annually on these updates and their impact on PAM program effectiveness

Qualification

Privileged Access ManagementIdentityAccess ManagementPAM tools expertiseRegulatory compliance experienceScripting/automation skillsAnalytical skillsCloud security knowledgeLeadership skillsCommunication skillsProblem-solving skills

Required

Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience is required
5+ years of experience in identity and access management, with a strong emphasis on privileged access and PAM solutions is required
Language Fluency: English (Required)
Expertise with PAM tools (e.g., CyberArk, Azure PIM (APIM)) and IAM platform integration
Solid foundation in authentication, authorization, and access control concepts
Demonstrated experience leading process re-engineering initiatives for PAM operations, implementing automation solutions, and driving data-driven risk remediation across enterprise environments
Advanced scripting/automation experience for PAM operations using PowerShell, Python, or similar tools such as Ansible or Bash
Ability to identify and assess privileged access and entitlement risks, and to define and implement effective mitigation strategies
Experience with regulatory standards (SOX, PCI-DSS, HIPAA) and compliance requirements
Strong analytical, problem-solving, and communication skills
Knowledge of securing privileged access in cloud and hybrid/multi-cloud environments
Demonstrated leadership in managing cross-functional teams and successful delivery of cloud security projects (e.g., overseeing cloud migration initiatives, coordinating with stakeholders across IT and business units, or implementing security automation in multi-cloud environments)
Ability to operate effectively in a dynamic, fast-paced environment
May require on-call availability and participation in incident response outside regular hours
Works closely with IT Security, Infrastructure, and Application teams to ensure privileged access security and compliance across the organization

Preferred

Relevant certifications (CISSP, CISM, vendor-specific PAM) preferred

Benefits

Medical, dental, vision, life, disability, and AD&D insurance
Tax-advantaged savings accounts
401(k) plan with company match
Generous paid time off programs, including company holidays, vacation and sick days, new parent leave
Restricted stock units and/or a deferred compensation plan

Company

TIH

twittertwitter
company-logo
TIH, the fifth largest insurance broker in the United States, offers highly consultative risk management services and nearly all types of coverage, including personal, small business, corporate, employee benefits, life and health, and title.

H1B Sponsorship

TIH has a track record of offering H1B sponsorships. Please note that this does not guarantee sponsorship for this specific role. Below presents additional info for your reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (2)
2024 (6)

Funding

Current Stage
Late Stage
Total Funding
$1.95B
2024-02-20Private Equity
2024-02-20Acquired
2023-02-16Secondary Market· $1.95B

Leadership Team

leader-logo
John Howard
Chairman & CEO
linkedin
leader-logo
Jeremy Davis
Chief Technology Officer
linkedin
Company data provided by crunchbase