Company:GuidePoint Security
Location:United States
Languages:English
Seniority level:Senior, 3-5+ years
Experience:3-5+ years
Skills:AWSPythonCloud ComputingCybersecurityGCPLDAPAzureLinuxDevOps
- Bachelor’s degree in Computer Science, Information Security, or related field — or equivalent work experience.
- 3-5+ years of experience in Privileged Access Management engineering or Consulting.
- Hands-on experience with Delinea Secret Server (on-prem or cloud) including password rotation, connectors, RBAC, and auditing.
- Experience in implementing CyberArk Privileged Cloud (or CyberArk CorePAS).
- Strong understanding of privileged account governance, password rotation, service account automation, and session management.
- Experience with Windows/Linux server administration and Active Directory.
- Familiarity with scripting (PowerShell, Python) and REST APIs.
- Knowledge of common security frameworks and access control principles.
- Deploy, configure, manage, and support Delinea Secret Server and CyberArk Privileged-Cloud environments.
- Manage vaulting, onboarding, and lifecycle governance for privileged, shared, and service accounts.
- Maintain password rotation policies, session management, access workflows, and security controls.
- Implement and oversee privileged session monitoring, session recording, and behavioral alerts.
- Ensure adherence to least-privilege and Zero-Trust principles.
- Support modern PAM capabilities such as Just-in-Time privilege elevation, ephemeral credentials, secrets management APIs, and cloud-native PAM.
- Assist in building automated credential workflows for CI/CD pipelines and DevOps systems.
- Integrate PAM platforms with AD/LDAP, Azure AD, SSO/IDP, SIEM, MFA, ticketing systems, and cloud services (AWS/Azure/GCP).
- Onboard new systems, servers, applications, databases, and network devices to Delinea and CyberArk.
- Configure connectors, distributed engines, secrets management API endpoints, and credential plugins.
- Develop automation for onboarding, rotation, and monitoring using PowerShell, Python, or REST APIs.