Aon logo
Aon
Posted 11 days agoVerified live 8h ago

Identity and Access Management Engineer - PAM

Brief overview

Remote
UndergradOr in progress
$92k–$130k/yrStated range
3+ yrsMinimum
Privileged Access ManagementCyberArk CloudCyberArkBeyondTrust EPMPowerShellPythonWindowsLinuxActive DirectoryIdentity and Access ManagementSIEMAPI-based Credential Access

Job description

Summary

Aon is a global organization focused on helping clients and colleagues make better decisions to protect and enrich lives. Aon is seeking a Privileged Access Management Engineer to engineer, implement, and support PAM solutions, particularly CyberArk Cloud, while onboarding applications, maintaining access policies, automating processes, and delivering secure, scalable identity and privileged-access capabilities.

Responsibilities

  • Engineer, implement and support security technologies focused on Privileged Access Management
  • Implement and integrate PAM solutions, with a strong focus on CyberArk Cloud, and support endpoint privilege capabilities using technologies such as BeyondTrust or CyberArk EPM
  • Onboard applications, accounts and credentials into PAM platforms while maintaining appropriate access controls and security policies
  • Maintain and enhance CyberArk policies and support endpoint privilege policies for workstation environments
  • Contribute to the architectural design of access controls, user entitlements, application credentials and user access policies
  • Partner with architecture and engineering teams to advance the Identity and Access Management strategy and related roadmap
  • Develop automation using scripting languages such as PowerShell or Python to improve privileged-access processes and capabilities
  • Configure and support API or programmatic access to managed credentials
  • Troubleshoot PAM, authentication and access issues, identify root causes and implement practical solutions
  • Use relevant security and SIEM data to support troubleshooting, monitoring and informed decision-making
  • Keep technical documentation current as platforms, configurations and environments evolve
  • Contribute to new PAM capabilities and product features while working within an Agile delivery environment
  • Communicate technical concepts clearly and collaborate effectively with engineering, architecture and business partners

Skills

  • 3+ years of relevant experience in privileged access, identity security or related security engineering
  • Hands-on experience implementing, developing or supporting CyberArk, with experience in CyberArk Cloud strongly preferred for this role
  • Experience with PAM operational activities such as credential onboarding, access administration, policy configuration and API-based credential access
  • Experience with endpoint privilege management technologies such as BeyondTrust EPM or CyberArk EPM
  • Hands-on experience supporting Windows and/or Linux infrastructure
  • Working knowledge of Active Directory, including users, computers, groups, Group Policy and trusts
  • Understanding of broader Identity and Access Management concepts such as authentication, access certification and public key infrastructure
  • Experience developing automation with scripting tools such as PowerShell, Python or comparable languages
  • Familiarity with SIEM technologies and querying security data
  • Understanding of web traffic and the ability to troubleshoot authentication flows
  • Experience contributing to technical projects in an Agile environment
  • Ability to create clear technical documentation and communicate effectively with technical and nontechnical stakeholders
  • Education: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field, or equivalent years of relevant industry experience
  • Experience with both CyberArk and BeyondTrust technologies
  • Exposure to emerging privileged-access use cases involving non-human identities (NHI) or AI-related security scenarios
  • Broader experience across Identity and Access Management platforms and security technologies

Qualifications

Must Haves

  • 3+ years of relevant experience in privileged access, identity security or related security engineering
  • Hands-on experience implementing, developing or supporting CyberArk, with experience in CyberArk Cloud strongly preferred for this role
  • Experience with PAM operational activities such as credential onboarding, access administration, policy configuration and API-based credential access
  • Experience with endpoint privilege management technologies such as BeyondTrust EPM or CyberArk EPM
  • Hands-on experience supporting Windows and/or Linux infrastructure
  • Working knowledge of Active Directory, including users, computers, groups, Group Policy and trusts
  • Understanding of broader Identity and Access Management concepts such as authentication, access certification and public key infrastructure
  • Experience developing automation with scripting tools such as PowerShell, Python or comparable languages
  • Familiarity with SIEM technologies and querying security data
  • Understanding of web traffic and the ability to troubleshoot authentication flows
  • Experience contributing to technical projects in an Agile environment
  • Ability to create clear technical documentation and communicate effectively with technical and nontechnical stakeholders
  • Education: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field, or equivalent years of relevant industry experience

Nice to Haves

  • Experience with both CyberArk and BeyondTrust technologies
  • Exposure to emerging privileged-access use cases involving non-human identities (NHI) or AI-related security scenarios
  • Broader experience across Identity and Access Management platforms and security technologies

Benefits

  • A 401(k) savings plan with employer contributions
  • An employee stock purchase plan
  • Consideration for long-term incentive awards at Aon's discretion
  • Medical, dental and vision insurance
  • Various types of leaves of absence
  • Paid time off, including 12 paid holidays throughout the calendar year
  • 15 days of paid vacation per year
  • Paid sick leave as provided under state and local paid sick leave laws
  • Short-term disability and optional long-term disability
  • Health savings account
  • Health care and dependent care reimbursement accounts
  • Employee and dependent life insurance and supplemental life and AD&D insurance
  • Optional personal insurance policies
  • Adoption assistance
  • Tuition assistance
  • Commuter benefits
  • An employee assistance program that includes free counseling sessions

More jobs like this