
Lead Privileged Access Management Engineer
Depository Trust & Clearing Corporation (DTCC)5 months ago
Dallas, TX, USAStaff+
Responsibilities
- Design and evolve scalable, resilient, and secure PAM platform architecture, including high availability and disaster recovery.
- Implement JIT access, session recording, credential vaulting, API integrations, and standardized onboarding for new systems.
- Build monitoring, logging, alerting, and end-to-end observability for PAM platforms using tools such as Splunk, Prometheus, and Grafana.
- Establish privileged account lifecycle policies, enforce password complexity and rotation, and maintain readiness for SOX, PCI, and internal audits.
- Develop scripts and connectors to automate provisioning, session management, and PAM integration with CI/CD workflows.
- Monitor PAM performance, lead incident response for privileged access breaches, and perform root-cause analysis and remediation.
- Communicate platform health, roadmap, and risk posture to senior leadership while managing vendors and licensing.
- Mentor engineers and review designs, code, and operational practices.
- Participate in disaster recovery exercises and ensure PAM resilience during loss-of-region scenarios.
Requirements
- At least 6 years of related experience, including 6+ years in security engineering, platform engineering, or IAM.
- Bachelor's degree preferred and/or equivalent experience.
- Strong understanding of privileged account lifecycle, credential vaulting, and session management.
- Expertise in automation using Jenkins, Python, Groovy, or equivalent technologies, and integration with CI/CD workflows.
- Familiarity with Windows, Unix/Linux, Active Directory, and hybrid cloud environments.
- Understanding of regulatory compliance and audit processes in financial or other highly regulated industries.
- Preferred experience with Bravura PAM or similar enterprise PAM solutions such as CyberArk.
- Knowledge of Zero Trust architectures, API-based integrations, JIT access, and ephemeral credentials.
- Familiarity with cloud, Kubernetes, OpenShift, and PAM integration patterns.
- Knowledge of risk frameworks and evidence automation for audits.
Benefits
- Competitive compensation including base pay and annual incentive.
- Comprehensive health and life insurance and well-being benefits, based on location.
- Pension and retirement benefits.
- Paid time off, personal/family care, and other leaves of absence.
- Flexible hybrid work model with 3 days onsite and 2 days remote, including onsite Tuesdays, Wednesdays, and a third team- or employee-specific day.