Overview
The Privileged Access Management (PAM) Engineer is responsible for the installation, operations, and maintenance of the Navy Federal PAM solution infrastructure. The PAM engineer will analyze, develop, and build processes and technology to ensure timely delivery of PAM services. The PAM engineer will be expected to contribute to overall design and long term strategy of the Privileged Access and Identity Management program. The PAM Engineer will work closely with internal teams such as information security, service desk, systems engineering, network security, audit, application developers, and other administrators in delivering PAM services. This will include managing the life cycle of users in the PAM system, creating and maintaining credentials and secrets, and implementing least privilege storage and delegation of access to secured objects. The PAM engineer will be expected to monitor and ensure the health of the systems providing PAM services.
Responsibilities
Operation of the Privileged Access Management (PAM) technologies, including accounts management, secrets management, and software and systems patchingLead projects to develop and deliver new security features and or software currencyWork with PAM team to implement and automate processes for administration and integration with external servicesContribute to PAM Security Strategy, including provisioning, password management and access policies, SSH key management, API key management, and reportingDesign, configure, and maintain PAM solutions for AIX, RHEL, Windows, and Mainframe systemsIntegrate the PAM solution with various technologies such as Service Now, VMWare, SailPoint or other top IDM solutionsProvide security consultation on internal projects focusing on business needs and how data is transmitted internally and externallyAuthoring and maintaining documentation procedures, inventories, and diagrams for PAM systems and processesMonitors and responds to capacity and performance needs of the PAM infrastructureProvides regular reports to leadership regarding security, capacity, usage, and licensingProvide rotational on-call support for production PAM infrastructure systems and processes
Qualifications
Bachelor's Degree in Information Technology, Computer Science or other related fields5-7+ years administering and maintaining Privileged Access Management (PAM) solutions, such as CyberArk, BeyondTrust, Thycotic or LiebermanConsiderable experience with Identity and Access Management vendors like Microsoft, CyberArk, ForgeRock, ServiceNow, RSA, etc.Demonstrates an understanding of how PAM integrates with common resources such as Windows, Linux/UNIX, VMWare, Azure, SQL/Oracle/DB2 database systems, Network appliances, and MainframeSignificant experience administering tier zero identity infrastructure that provides AAA services such as Active Directory, Azure Active Directory, and/or RSAExperience in developing automated solutions and processes using PowerShell for Windows and BASH for UNIX/LinuxExperience working in large security access system upgrades/projects using the Scaled Agile Framework (SAFe)Significant experience working in a large IT organization with responsibility for supporting the technology and processes in the Privileged Access Management domain and controls program, preferably in a financial services organizationSignificant experience in working with all levels of staff, management, stakeholders, vendorsAdvanced knowledge of Service Life Cycle or Agile FrameworksAdvanced verbal and written communication skillsAdvanced research, analytical, and problem-solving skillsEffective in producing desired results and achieving goals and objectivesPractical skill presenting findings, conclusions, alternatives, and information clearly and concisely
Desired Qualifications
Industry certifications in cyber or identity security attesting to broad knowledge of security best practices and design
Hours: Monday - Friday, 8:00AM - 4:30PM
Location: 820 Follin Lane, Vienna, VA 22180 | 5550 Heritage Oaks Dr. Pensacola, FL 32526 | 141 Security Dr. Winchester, VA 22602 | Remote
This position is eligible for the TalentQuest employee referral program. If an employee referred you for this job, please apply using the system-generated link that was sent to you.
Navy Federal is now hybrid! Our standard enterprise requirement for a hybrid schedule is to report on-site 4-16 days each month. The number of days reporting on-site will ultimately be determined by the employee's leadership and business unit needs. You will learn more throughout the hiring and on boarding process.
About Us
You have goals, dreams, hobbies, and things you're passionate about-what's important to you is important to us. We're looking for people who not only want to do meaningful, challenging work, keep their skills sharp and move ahead, but who also take time for the things that matter to them-friends, family, and passions. And we're looking for team members who are passionate about our mission-making a difference in military members' and their families' lives. Together, we can make it happen. Don't take our word for it:
• Military Times 2022 Best for Vets Employers
• WayUp Top 100 Internship Programs
• Forbes® 2022 The Best Employers for New Grads
• Fortune Best Workplaces for Women
• Fortune 100 Best Companies to Work For®
• Computerworld® Best Places to Work in IT
• Ripplematch Campus Forward Award - Excellence in Early Career Hiring
• Fortune Best Place to Work for Financial and Insurance Services
Equal Employment Opportunity: Navy Federal values, celebrates, and enacts diversity in the workplace. Navy Federal takes affirmative action to employ and advance in employment qualified individuals with disabilities, disabled veterans, Armed Forces service medal veterans, recently separated veterans, and other protected veterans. EOE/AA/M/F/Veteran/Disability EOE/AA/M/F/Veteran/Disability
Disclaimers: Navy Federal reserves the right to fill this role at a higher/lower grade level based on business need. An assessment may be required to compete for this position. Job postings are subject to close early or extend out longer than the anticipated closing date at the hiring team's discretion based on qualified applicant volume. Navy Federal Credit Union assesses market data to establish salary ranges that enable us to remain competitive. You are paid within the salary range, based on your experience, location and market position
Bank Secrecy Act: Remains cognizant of and adheres to Navy Federal policies and procedures, and regulations pertaining to the Bank Secrecy Act.