About Us Visa is a world leader in payments technology, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories, dedicated to uplifting everyone, everywhere by being the best way to pay and be paid. At Visa, you'll have the opportunity to create impact at scale - tackling meaningful challenges, growing your skills and seeing your contributions impact lives around the world. Join Visa and do work that matters - to you, to your community, and to the world. Progress starts with you. Job Description The Cybersecurity Engineer - Cloud is responsible for designing, implementing, and operating security controls that protect cloud native platforms and workloads across public cloud environments (AWS, Azure, GCP). The role partners closely with engineering, DevOps, and architecture teams to ensure cloud services are secure by design, compliant with regulatory requirements, and resilient at scale. This position combines hands on engineering, security architecture, and risk based decision making within complex, distributed, and regulated environments. In addition to cloud security responsibilities, this role provides security oversight and engineering support for AI enabled capabilities used across the Pismo platform. The engineer ensures that adoption of Artificial Intelligence and Large Language Models (LLMs) is aligned with Visa security controls, Pismo data protection principles, and global regulatory expectations. This is a remote position. A remote position does not require job duties be performed within proximity of a Visa office location. Remote positions may be required to be present at a Visa office with scheduled notice. Visa requires at least 3 days in office, expectations of these days will be confirmed by your Hiring Manager. Qualifications 6+ years in IAM/security engineering with strong hands-on delivery (not only governance). Strong knowledge of IAM fundamentals: identity lifecycle, authentication, authorization, MFA, RBAC/ABAC, access reviews. Demonstrated coding ability and automation mindset: Python/Go preferred; PowerShell/Bash acceptable; experience shipping tools used by others. Experience implementing enterprise IAM standards and operating in compliance-driven environments (access control evidence, audits, governance). Solid understanding of segregation of duties and production access constraints. Multi-cloud security/IAM experience across AWS/Azure/GCP. Experience with identity providers / governance platforms (e.g., federated SSO patterns, directory groups, access certification workflows). Experience engineering and/or integrating PAM capabilities and processes (vaulting/rotation, JIT/JEA). Experience applying GenAI to security operations responsibly (workflow automation, evidence generation, policy templating). Security certifications (nice-to-have): CISSP/CISM, cloud certs, IAM-related certs. U.S. Applicants Only The estimated salary range for this position is $145,300.00 to $ 232,700.00 USD per year, which may include potential sales incentive payments (if applicable). Salary may vary depending on job-related factors which may include knowledge, skills, experience, and location. In addition, this position may be eligible for bonus and equity.Visa has a comprehensive benefits package for which this position may be eligible that includes Medical, Dental, Vision, 401(k), FSA/HSA, Life Insurance, Paid Time Off, and Wellness Program. Work Hours Varies upon the needs of the department. Travel Requirements This position requires travel 5-10% of the time. Mental/Physical Requirements This position will be performed in an office setting. The position will require the incumbent to sit and stand at a desk, communicate in person and by telephone, frequently operate standard office equipment, such as telephones and computers. Visa is an EEO Employer Qualified applicants will receive consideration for employment without regard to race, color religion, sex, national origin, sexual orientation, gender identity, disability or protect veteran status. Visa will also consider for employment qualified applicants with criminal histories in a manner consistent with the EEOC guidelines and applicable local law.
08/05/2026
Full time
About Us Visa is a world leader in payments technology, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories, dedicated to uplifting everyone, everywhere by being the best way to pay and be paid. At Visa, you'll have the opportunity to create impact at scale - tackling meaningful challenges, growing your skills and seeing your contributions impact lives around the world. Join Visa and do work that matters - to you, to your community, and to the world. Progress starts with you. Job Description The Cybersecurity Engineer - Cloud is responsible for designing, implementing, and operating security controls that protect cloud native platforms and workloads across public cloud environments (AWS, Azure, GCP). The role partners closely with engineering, DevOps, and architecture teams to ensure cloud services are secure by design, compliant with regulatory requirements, and resilient at scale. This position combines hands on engineering, security architecture, and risk based decision making within complex, distributed, and regulated environments. In addition to cloud security responsibilities, this role provides security oversight and engineering support for AI enabled capabilities used across the Pismo platform. The engineer ensures that adoption of Artificial Intelligence and Large Language Models (LLMs) is aligned with Visa security controls, Pismo data protection principles, and global regulatory expectations. This is a remote position. A remote position does not require job duties be performed within proximity of a Visa office location. Remote positions may be required to be present at a Visa office with scheduled notice. Visa requires at least 3 days in office, expectations of these days will be confirmed by your Hiring Manager. Qualifications 6+ years in IAM/security engineering with strong hands-on delivery (not only governance). Strong knowledge of IAM fundamentals: identity lifecycle, authentication, authorization, MFA, RBAC/ABAC, access reviews. Demonstrated coding ability and automation mindset: Python/Go preferred; PowerShell/Bash acceptable; experience shipping tools used by others. Experience implementing enterprise IAM standards and operating in compliance-driven environments (access control evidence, audits, governance). Solid understanding of segregation of duties and production access constraints. Multi-cloud security/IAM experience across AWS/Azure/GCP. Experience with identity providers / governance platforms (e.g., federated SSO patterns, directory groups, access certification workflows). Experience engineering and/or integrating PAM capabilities and processes (vaulting/rotation, JIT/JEA). Experience applying GenAI to security operations responsibly (workflow automation, evidence generation, policy templating). Security certifications (nice-to-have): CISSP/CISM, cloud certs, IAM-related certs. U.S. Applicants Only The estimated salary range for this position is $145,300.00 to $ 232,700.00 USD per year, which may include potential sales incentive payments (if applicable). Salary may vary depending on job-related factors which may include knowledge, skills, experience, and location. In addition, this position may be eligible for bonus and equity.Visa has a comprehensive benefits package for which this position may be eligible that includes Medical, Dental, Vision, 401(k), FSA/HSA, Life Insurance, Paid Time Off, and Wellness Program. Work Hours Varies upon the needs of the department. Travel Requirements This position requires travel 5-10% of the time. Mental/Physical Requirements This position will be performed in an office setting. The position will require the incumbent to sit and stand at a desk, communicate in person and by telephone, frequently operate standard office equipment, such as telephones and computers. Visa is an EEO Employer Qualified applicants will receive consideration for employment without regard to race, color religion, sex, national origin, sexual orientation, gender identity, disability or protect veteran status. Visa will also consider for employment qualified applicants with criminal histories in a manner consistent with the EEOC guidelines and applicable local law.
Position - Security Engineer Location - Fort Worth, TX (Hybrid) Job ID - 178604 Position Overview We are seeking a Directory Services Engineer to support critical cybersecurity initiatives focused on identity infrastructure security, Tier 0 protection, and resiliency. This role is hands-on and execution-focused, working across Active Directory, Microsoft Entra ID (Azure AD), and hybrid identity environments. The engineer will play a key role in hardening identity systems, identifying attack paths, and implementing remediation actions to reduce enterprise risk. Key Responsibilities Identity Engineering & Operations • Administer and support Active Directory (AD) and Microsoft Entra ID (Azure AD) environments. • Implement and manage Azure AD Connect / Entra Connect for hybrid identity synchronization. • Support domain controllers, forests, trusts, and authentication services. • Execute identity-related changes, configurations, and deployments. Security Hardening & Tier 0 Protection • Implement security controls for Tier 0 assets (AD, Entra ID, domain controllers). • Perform system hardening in alignment with cybersecurity standards. • Support initiatives for privileged access restrictions and identity protection. • Remediate identified security gaps and misconfigurations. Attack Path Identification & Remediation • Analyze and identify identity-based attack paths across on-prem and cloud environments. • Support remediation efforts to eliminate: o Privilege escalation paths o Excessive permissions o Identity misconfigurations • Partner with cybersecurity teams to reduce identity attack surface. Resiliency & Recovery Support • Implement and validate Active Directory forest recovery procedures. • Support backup, restore, and testing activities for identity systems. • Assist in improving resiliency and recoverability of Tier 0 infrastructure. Integration Support • Assist in integration and configuration of identity with: o MFA / Conditional Access o PAM (e.g., CyberArk) o IGA (e.g., Saviynt) o Secrets and certificate platforms (e.g., HashiCorp, Keyfactor) • Support identity governance and access control initiatives. Automation & Execution • Use PowerShell and scripting to automate identity tasks and remediation. • Execute predefined engineering tasks, runbooks, and operational procedures. • Document configurations, changes, and implementation steps. Job Description: Operationalize automated data discovery, classification, and inventory; apply sensitivity labels and consistent taxonomy across data stores, pipelines, and collaboration systems. Engineer DSPM capabilities with tools (e.g., Securiti, BigID) to surface data posture risks (overexposure, shadow data, stale sensitive data) and drive remediation workflows. Implement and support encryption, tokenization, masking, anonymization/pseudonymization for data at rest and in transit; integrate with cloud key management systems and enforce approved cryptographic standards; define crypto baselines and policy-as-code guardrails. Configure and govern access controls with RBAC/ABAC and purpose-based authorization; perform least-privilege and fine-grained access reviews across data platforms. Deploy, tune, and operate DLP and DAM solutions (e.g., Microsoft Purview DLP, Imperva/Guardium); build detections for PII/PCI/PHI and reduce false positives with policy and context improvements. Integrate and tune UEBA and Insider Risk signals to detect anomalous data access and exfiltration, partner on response workflows and preventive control changes. Integrate data protection telemetry with SIEM/SOAR; build detections, correlation rules, and automated response playbooks for data-related threats and policy violations. Implement data minimization and retention/ROT enforcement patterns; automate monitoring of lifecycle actions (archive, delete, redact) aligned to policy and legal holds. Implement DSAR (data subject access request) orchestration and fulfillment with SLA monitoring; automate data collection, redaction, and secure delivery with audit trails. Contribute to cookie/tag governance and catalog assurance; validate consent signals, storage durations, and vendor script behavior against policy. Support privacy platform capabilities and integrate with identity, ticketing, data catalogs/lineage, and evidence repositories. Embed data protection and privacy-by-design controls into services and CI/CD (pre-commit/CI privacy code scanning, secret scanning, schema checks for sensitive fields, data egress policies). Produce compliance evidence and reports for GDPR/CCPA/CPRA, PCI DSS, HIPAA, and internal audits; maintain controls health dashboards, regulatory tracking, and program KPIs. Investigate data-related incidents and privacy events in partnership with IR/SOC/Privacy Office. Collect artifacts, support forensics, document findings, and drive preventive engineering fixes. Conduct platform hardening and vulnerability remediation for data control tooling (misconfigurations, exposed buckets, weak crypto, excessive permissions). Participate in red teaming/tabletop exercises for data scenarios (insider misuse, public link exposures, unintended AI training data); translate findings into control improvements. Partner with Cybersecurity, Privacy Office, Enterprise Data, Legal, and product/platform teams to align designs and deliver privacy- and data protection-by-design outcomes. Document engineering patterns, runbooks, and reference architectures; create training and technical guidance that strengthen secure data handling practices across teams. Communicate clearly and concisely with technical and non?technical audiences - summarize incidents, risks, and recommended actions with accurate, complete context. Required Skills & Experience 3-7 years of hands-on experience in: Active Directory administration/engineering Microsoft Entra ID (Azure AD) Azure AD Connect / hybrid identity environments Experience with: AD security hardening Identity-related attack techniques (privilege escalation, lateral movement) Attack path analysis or remediation activities Strong working knowledge of: Tier 0 concepts and identity as a control plane Authentication protocols (Kerberos, NTLM, SAML, OAuth) Preferred Experience Exposure to: CyberArk or other PAM tools Saviynt or similar IGA platforms Ping Identity or federation solutions HashiCorp Vault, Keyfactor, or PKI environments Experience supporting AD forest recovery exercises Familiarity with Zero Trust principles Key Traits for Success Strong execution and delivery focus Security and resiliency mindset Ability to quickly identify and remediate risks Works effectively in a cross-functional cybersecurity environment Comfortable working in fast-paced, project-driven (contract) engagements Pay Range: $65 - $70/Hr The specific compensation for this position will be determined by a number of factors, including the scope, complexity and location of the role as well as the cost of labor in the market; the skills, education, training, credentials and experience of the candidate; and other conditions of employment. Our full-time consultants have access to benefits including medical, dental, vision and 401K contributions as well as any other PTO, sick leave, and other benefits mandated by appliable state or localities where you reside or work.
08/05/2026
Full time
Position - Security Engineer Location - Fort Worth, TX (Hybrid) Job ID - 178604 Position Overview We are seeking a Directory Services Engineer to support critical cybersecurity initiatives focused on identity infrastructure security, Tier 0 protection, and resiliency. This role is hands-on and execution-focused, working across Active Directory, Microsoft Entra ID (Azure AD), and hybrid identity environments. The engineer will play a key role in hardening identity systems, identifying attack paths, and implementing remediation actions to reduce enterprise risk. Key Responsibilities Identity Engineering & Operations • Administer and support Active Directory (AD) and Microsoft Entra ID (Azure AD) environments. • Implement and manage Azure AD Connect / Entra Connect for hybrid identity synchronization. • Support domain controllers, forests, trusts, and authentication services. • Execute identity-related changes, configurations, and deployments. Security Hardening & Tier 0 Protection • Implement security controls for Tier 0 assets (AD, Entra ID, domain controllers). • Perform system hardening in alignment with cybersecurity standards. • Support initiatives for privileged access restrictions and identity protection. • Remediate identified security gaps and misconfigurations. Attack Path Identification & Remediation • Analyze and identify identity-based attack paths across on-prem and cloud environments. • Support remediation efforts to eliminate: o Privilege escalation paths o Excessive permissions o Identity misconfigurations • Partner with cybersecurity teams to reduce identity attack surface. Resiliency & Recovery Support • Implement and validate Active Directory forest recovery procedures. • Support backup, restore, and testing activities for identity systems. • Assist in improving resiliency and recoverability of Tier 0 infrastructure. Integration Support • Assist in integration and configuration of identity with: o MFA / Conditional Access o PAM (e.g., CyberArk) o IGA (e.g., Saviynt) o Secrets and certificate platforms (e.g., HashiCorp, Keyfactor) • Support identity governance and access control initiatives. Automation & Execution • Use PowerShell and scripting to automate identity tasks and remediation. • Execute predefined engineering tasks, runbooks, and operational procedures. • Document configurations, changes, and implementation steps. Job Description: Operationalize automated data discovery, classification, and inventory; apply sensitivity labels and consistent taxonomy across data stores, pipelines, and collaboration systems. Engineer DSPM capabilities with tools (e.g., Securiti, BigID) to surface data posture risks (overexposure, shadow data, stale sensitive data) and drive remediation workflows. Implement and support encryption, tokenization, masking, anonymization/pseudonymization for data at rest and in transit; integrate with cloud key management systems and enforce approved cryptographic standards; define crypto baselines and policy-as-code guardrails. Configure and govern access controls with RBAC/ABAC and purpose-based authorization; perform least-privilege and fine-grained access reviews across data platforms. Deploy, tune, and operate DLP and DAM solutions (e.g., Microsoft Purview DLP, Imperva/Guardium); build detections for PII/PCI/PHI and reduce false positives with policy and context improvements. Integrate and tune UEBA and Insider Risk signals to detect anomalous data access and exfiltration, partner on response workflows and preventive control changes. Integrate data protection telemetry with SIEM/SOAR; build detections, correlation rules, and automated response playbooks for data-related threats and policy violations. Implement data minimization and retention/ROT enforcement patterns; automate monitoring of lifecycle actions (archive, delete, redact) aligned to policy and legal holds. Implement DSAR (data subject access request) orchestration and fulfillment with SLA monitoring; automate data collection, redaction, and secure delivery with audit trails. Contribute to cookie/tag governance and catalog assurance; validate consent signals, storage durations, and vendor script behavior against policy. Support privacy platform capabilities and integrate with identity, ticketing, data catalogs/lineage, and evidence repositories. Embed data protection and privacy-by-design controls into services and CI/CD (pre-commit/CI privacy code scanning, secret scanning, schema checks for sensitive fields, data egress policies). Produce compliance evidence and reports for GDPR/CCPA/CPRA, PCI DSS, HIPAA, and internal audits; maintain controls health dashboards, regulatory tracking, and program KPIs. Investigate data-related incidents and privacy events in partnership with IR/SOC/Privacy Office. Collect artifacts, support forensics, document findings, and drive preventive engineering fixes. Conduct platform hardening and vulnerability remediation for data control tooling (misconfigurations, exposed buckets, weak crypto, excessive permissions). Participate in red teaming/tabletop exercises for data scenarios (insider misuse, public link exposures, unintended AI training data); translate findings into control improvements. Partner with Cybersecurity, Privacy Office, Enterprise Data, Legal, and product/platform teams to align designs and deliver privacy- and data protection-by-design outcomes. Document engineering patterns, runbooks, and reference architectures; create training and technical guidance that strengthen secure data handling practices across teams. Communicate clearly and concisely with technical and non?technical audiences - summarize incidents, risks, and recommended actions with accurate, complete context. Required Skills & Experience 3-7 years of hands-on experience in: Active Directory administration/engineering Microsoft Entra ID (Azure AD) Azure AD Connect / hybrid identity environments Experience with: AD security hardening Identity-related attack techniques (privilege escalation, lateral movement) Attack path analysis or remediation activities Strong working knowledge of: Tier 0 concepts and identity as a control plane Authentication protocols (Kerberos, NTLM, SAML, OAuth) Preferred Experience Exposure to: CyberArk or other PAM tools Saviynt or similar IGA platforms Ping Identity or federation solutions HashiCorp Vault, Keyfactor, or PKI environments Experience supporting AD forest recovery exercises Familiarity with Zero Trust principles Key Traits for Success Strong execution and delivery focus Security and resiliency mindset Ability to quickly identify and remediate risks Works effectively in a cross-functional cybersecurity environment Comfortable working in fast-paced, project-driven (contract) engagements Pay Range: $65 - $70/Hr The specific compensation for this position will be determined by a number of factors, including the scope, complexity and location of the role as well as the cost of labor in the market; the skills, education, training, credentials and experience of the candidate; and other conditions of employment. Our full-time consultants have access to benefits including medical, dental, vision and 401K contributions as well as any other PTO, sick leave, and other benefits mandated by appliable state or localities where you reside or work.
Dear, Greetings for the day My name is Amarjeet Singh working as a recruitment specialist at Valzo soft, please have a look at the job description below and let me know your interest about this opportunity. If possible, please share with me your latest resume. Job Title: CyberArk EPM Architect Location: Austin, TX or Irvine, CA Job Description: We are seeking an experienced CyberArk Endpoint Privilege Manager (EPM) Architect with deep technical expertise in designing, deploying, and migrating enterprise EPM environments. The ideal candidate will lead large-scale implementations, architect scalable privilege management solutions, and drive seamless migrations between CyberArk EPM tenants while minimizing business impact. Key Responsibilities Architect, deploy, and configure CyberArk EPM across enterprise Windows and macOS environments. Lead end-to-end migration of CyberArk EPM policies, configurations, application groups, and rule sets from one environment/tenant to another. Design and implement application control, privilege elevation, and least privilege strategies. Develop, optimize, and troubleshoot EPM policies, trusted applications, and elevation rules. Integrate CyberArk EPM with enterprise identity, security, and endpoint management platforms (Microsoft Intune, MECM/SCCM, SentinelOne, SIEM, etc.). Automate deployment, policy management, and migration activities using PowerShell and REST APIs. Perform architectural reviews, health assessments, and recommend best practices for performance, scalability, and security. Collaborate with security, infrastructure, desktop engineering, and application teams throughout implementation and migration projects. Create technical documentation, migration runbooks, and operational procedures. Provide Level 3/4 technical support and mentor engineering teams. Required Skills 8+ years of endpoint security experience with 4+ years of hands-on CyberArk EPM architecture and implementation. Proven experience deploying CyberArk EPM in large enterprise environments. Strong experience migrating CyberArk EPM from one tenant/environment to another, including policy and configuration migration. Deep understanding of application control, privilege management, allow/block rules, elevation policies, and sub-process elevation. Strong PowerShell scripting and API automation experience. Experience with Microsoft Intune, MECM/SCCM, Active Directory, Entra ID, Windows Security, and endpoint management. Strong troubleshooting, communication, documentation, and stakeholder management skills. Preferred Qualifications CyberArk certifications (EPM, Defender, Sentry, or Guardian). Experience with enterprise transformation, Zero Trust, and Privileged Access Management (PAM) initiatives. Experience integrating EPM with SIEM, EDR/XDR, and ITSM platforms. Regards, Amarjeet Singh Sr. Account Manager +1- Valzo Soft Solutions LLC
08/05/2026
Full time
Dear, Greetings for the day My name is Amarjeet Singh working as a recruitment specialist at Valzo soft, please have a look at the job description below and let me know your interest about this opportunity. If possible, please share with me your latest resume. Job Title: CyberArk EPM Architect Location: Austin, TX or Irvine, CA Job Description: We are seeking an experienced CyberArk Endpoint Privilege Manager (EPM) Architect with deep technical expertise in designing, deploying, and migrating enterprise EPM environments. The ideal candidate will lead large-scale implementations, architect scalable privilege management solutions, and drive seamless migrations between CyberArk EPM tenants while minimizing business impact. Key Responsibilities Architect, deploy, and configure CyberArk EPM across enterprise Windows and macOS environments. Lead end-to-end migration of CyberArk EPM policies, configurations, application groups, and rule sets from one environment/tenant to another. Design and implement application control, privilege elevation, and least privilege strategies. Develop, optimize, and troubleshoot EPM policies, trusted applications, and elevation rules. Integrate CyberArk EPM with enterprise identity, security, and endpoint management platforms (Microsoft Intune, MECM/SCCM, SentinelOne, SIEM, etc.). Automate deployment, policy management, and migration activities using PowerShell and REST APIs. Perform architectural reviews, health assessments, and recommend best practices for performance, scalability, and security. Collaborate with security, infrastructure, desktop engineering, and application teams throughout implementation and migration projects. Create technical documentation, migration runbooks, and operational procedures. Provide Level 3/4 technical support and mentor engineering teams. Required Skills 8+ years of endpoint security experience with 4+ years of hands-on CyberArk EPM architecture and implementation. Proven experience deploying CyberArk EPM in large enterprise environments. Strong experience migrating CyberArk EPM from one tenant/environment to another, including policy and configuration migration. Deep understanding of application control, privilege management, allow/block rules, elevation policies, and sub-process elevation. Strong PowerShell scripting and API automation experience. Experience with Microsoft Intune, MECM/SCCM, Active Directory, Entra ID, Windows Security, and endpoint management. Strong troubleshooting, communication, documentation, and stakeholder management skills. Preferred Qualifications CyberArk certifications (EPM, Defender, Sentry, or Guardian). Experience with enterprise transformation, Zero Trust, and Privileged Access Management (PAM) initiatives. Experience integrating EPM with SIEM, EDR/XDR, and ITSM platforms. Regards, Amarjeet Singh Sr. Account Manager +1- Valzo Soft Solutions LLC
Genesis10 is currently seeking a PAM Automation Engineer for a remote position with a Major Financial Institution. This is a 12-month contract-to-hire opportunity. Overview Our client is seeking a PAM Automation Engineer to join the Privileged Access Management Services team. This role focuses on building and supporting automation that enables secure access elevation services across Unix, Linux, and other non-Microsoft systems. Responsibilities Build and maintain automation supporting privileged access workflows Create, execute, and enhance Ansible playbooks for production systems Support tools that provide elevated access for IT professionals across the Federal Reserve Develop automation focused on resiliency, self-healing, alerting, and remediation Support authentication and authorization processes for Unix/Linux and non-Microsoft systems Assist with the remediation of Unix-related identity and access vulnerabilities Collaborate closely with engineering teammates during coding, troubleshooting, and solutioning sessions Qualifications Significant hands-on experience with Ansible Experience creating and executing Ansible playbooks in production environments Strong Unix/Linux administration or engineering experience Experience automating infrastructure or operational workflows Understanding of privileged access management (PAM), IAM, or access elevation concepts Ability to troubleshoot and support production automation systems Must be a United States citizen or lawful permanent resident with a minimum of three years of U.S. residency Technologies & Tools Experience with the following technologies is highly valued: Ansible YAML Perl PowerShell Tcl/Tk PHP SQL querying Unix/Linux Bash scripting SSH Delinea/Centrify-style Active Directory bridging solutions PAM or homegrown access elevation tools Ideal Backgrounds Strong candidates may come from backgrounds such as: Unix/Linux Systems Administration with automation and security experience AIX administration with infrastructure automation expertise Infrastructure automation engineering PAM/IAM automation engineering Production resiliency or self-healing automation engineering Preferred Skills Perl scripting PowerShell Tcl/Tk PHP development SQL querying Bash scripting Unix vulnerability remediation PAM or Identity Governance & Administration (IGA) experience Team Environment 4-person engineering team 100% remote team structure Highly collaborative and high-performing culture Frequent teamwork during coding, troubleshooting, and design sessions Strong knowledge sharing and peer support Training & Ramp-Up New team members will complete approximately 45 days of virtual onboarding and training, including: Homegrown access elevation tool overview PHP essentials SQL querying fundamentals Team shadowing and operational support exposure Before joining the on-call rotation, engineers will begin handling incidents and working closely alongside the team. Schedule & On-Call Monday-Friday schedule 8-hour shift between 7:00 AM and 6:00 PM On-call rotation approximately 1 week every 5 weeks Tertiary support responsibilities Call volume is relatively low, but incidents can be high-impact when they occur Typically, no on-call participation until approximately 4-5 months into the role Pay range: $56.00 - $66.00 per hour Only candidates available and ready to work directly as Genesis10 employees will be considered for this position. If you have the described qualifications and are interested in this exciting opportunity, please apply! Ranked a Top Staffing Firm in the U.S. by Staffing Industry Analysts for six consecutive years, Genesis10 puts thousands of consultants and employees to work across the United States every year in contract, contract-for-hire, and permanent placement roles. With more than 300 active clients, Genesis10 provides access to many of the Fortune 100 firms and a variety of mid-market organizations across the full spectrum of industry verticals. Benefits of Working with Genesis10: Access to hundreds of clients, most of whom have been working with Genesis10 for 5-20 years. The opportunity to have a career-home in Genesis10; many of our consultants have been working exclusively with Genesis10 for years. Access to an experienced, caring recruiting team (more than 7 years of experience, on average) Behavioral Health Platform Medical, Dental, Vision Health Savings Account Voluntary Hospital Indemnity (Critical Illness & Accident) Voluntary Term Life Insurance 401K Sick Pay (for applicable states/municipalities) Commuter Benefits (Dallas, NYC, SF, and Illinois) Genesis10 is an Equal Opportunity Employer. Candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
08/05/2026
Full time
Genesis10 is currently seeking a PAM Automation Engineer for a remote position with a Major Financial Institution. This is a 12-month contract-to-hire opportunity. Overview Our client is seeking a PAM Automation Engineer to join the Privileged Access Management Services team. This role focuses on building and supporting automation that enables secure access elevation services across Unix, Linux, and other non-Microsoft systems. Responsibilities Build and maintain automation supporting privileged access workflows Create, execute, and enhance Ansible playbooks for production systems Support tools that provide elevated access for IT professionals across the Federal Reserve Develop automation focused on resiliency, self-healing, alerting, and remediation Support authentication and authorization processes for Unix/Linux and non-Microsoft systems Assist with the remediation of Unix-related identity and access vulnerabilities Collaborate closely with engineering teammates during coding, troubleshooting, and solutioning sessions Qualifications Significant hands-on experience with Ansible Experience creating and executing Ansible playbooks in production environments Strong Unix/Linux administration or engineering experience Experience automating infrastructure or operational workflows Understanding of privileged access management (PAM), IAM, or access elevation concepts Ability to troubleshoot and support production automation systems Must be a United States citizen or lawful permanent resident with a minimum of three years of U.S. residency Technologies & Tools Experience with the following technologies is highly valued: Ansible YAML Perl PowerShell Tcl/Tk PHP SQL querying Unix/Linux Bash scripting SSH Delinea/Centrify-style Active Directory bridging solutions PAM or homegrown access elevation tools Ideal Backgrounds Strong candidates may come from backgrounds such as: Unix/Linux Systems Administration with automation and security experience AIX administration with infrastructure automation expertise Infrastructure automation engineering PAM/IAM automation engineering Production resiliency or self-healing automation engineering Preferred Skills Perl scripting PowerShell Tcl/Tk PHP development SQL querying Bash scripting Unix vulnerability remediation PAM or Identity Governance & Administration (IGA) experience Team Environment 4-person engineering team 100% remote team structure Highly collaborative and high-performing culture Frequent teamwork during coding, troubleshooting, and design sessions Strong knowledge sharing and peer support Training & Ramp-Up New team members will complete approximately 45 days of virtual onboarding and training, including: Homegrown access elevation tool overview PHP essentials SQL querying fundamentals Team shadowing and operational support exposure Before joining the on-call rotation, engineers will begin handling incidents and working closely alongside the team. Schedule & On-Call Monday-Friday schedule 8-hour shift between 7:00 AM and 6:00 PM On-call rotation approximately 1 week every 5 weeks Tertiary support responsibilities Call volume is relatively low, but incidents can be high-impact when they occur Typically, no on-call participation until approximately 4-5 months into the role Pay range: $56.00 - $66.00 per hour Only candidates available and ready to work directly as Genesis10 employees will be considered for this position. If you have the described qualifications and are interested in this exciting opportunity, please apply! Ranked a Top Staffing Firm in the U.S. by Staffing Industry Analysts for six consecutive years, Genesis10 puts thousands of consultants and employees to work across the United States every year in contract, contract-for-hire, and permanent placement roles. With more than 300 active clients, Genesis10 provides access to many of the Fortune 100 firms and a variety of mid-market organizations across the full spectrum of industry verticals. Benefits of Working with Genesis10: Access to hundreds of clients, most of whom have been working with Genesis10 for 5-20 years. The opportunity to have a career-home in Genesis10; many of our consultants have been working exclusively with Genesis10 for years. Access to an experienced, caring recruiting team (more than 7 years of experience, on average) Behavioral Health Platform Medical, Dental, Vision Health Savings Account Voluntary Hospital Indemnity (Critical Illness & Accident) Voluntary Term Life Insurance 401K Sick Pay (for applicable states/municipalities) Commuter Benefits (Dallas, NYC, SF, and Illinois) Genesis10 is an Equal Opportunity Employer. Candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
The KPMG Advisory practice is at the forefront of transformation, offering excellent opportunities for individuals to advance their careers and expertise with KPMG. Looking ahead, we anticipate continued evolution and success within the practice, fostering both personal and professional development, thereby creating new pathways for growth. In this ever-changing market environment, our professionals must be adaptable and thrive in a collaborative, team-driven culture. At KPMG, our people are our number one priority. With a wealth of learning and career development opportunities, a world-class training facility, and leading market tools, we help our people continue to grow both professionally and personally. If you're looking for a firm with a strong team connection where you can be your whole self, have an impact, advance your skills, deepen your experiences, and have the flexibility and access to constantly find new areas of inspiration and expand your capabilities, then consider a career in Advisory. KPMG is currently seeking a Senior Associate, Privileged Access Management Delivery Engineer to join our Advisory Services practice. Responsibilities: Support the delivery, configuration, and operationalization of Privileged Access Management (PAM) solutions as part of enterprise Identity & Access Management (IAM) programs Implement and maintain PAM capabilities including privileged credential management, session management, just-in-time access, and endpoint management (EPM)components; implement automated integration across adjacent security solutions (for example: Crowdstrike, SIEM solutions, ServiceNow); automate PAM tasks using scripting and APIs (such as PowerShell, Python, REST, and others) and integrate with enterprise platforms (that is, Active Directory, IdPs, ITSM platforms, SIEM platforms, and more) Integrate PAM solutions across cloud environments (for example: Azure, AWS, GCP) while following security leading practices Execute privileged access onboarding activities, access workflow configurations, and break glass process enablement Perform risk assessments, evaluate privileged access controls, and support remediation activities across client environments Collaborate with cross-functional engineering, security, and risk teams to enhance PAM processes and resolve technical issues; support migrations from legacy or alternative PAM tooling; contribute to standardization of PAM delivery patterns and templates Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment Qualifications: Minimum three years of recent professional experience in Identity & Access Management, Privileged Access Management, or cybersecurity Bachelor's degree from an accredited college or university is required; CyberArk Certified Delivery Engineer (CDE) or CyberArk Endpoint Privilege Manager (EPM) Certification preferred Hands on experience with Privileged Access Management delivery and engineering, with specific experience using CyberArk On-Prem and SaaS solutions; additional experience with secrets management platforms (that is, Conjur, HashiCorp) and other PAM platforms (such as Delinea, BeyondTrust) preferred Familiarity with infrastructure administration (such as Windows, Linux, Databases), networking basics, and IT architecture principles preferred. Experience supporting PAM integrations within cloud platforms such as Azure, AWS, or GCP; proficiency with scripting, automation integrations, infrastructure-as-code, and configuration management Strong understanding of IAM concepts, privileged access controls, and associated security risks; strong problem solving, communication, and documentation skills with the ability to work collaboratively across teams Ability to travel as required Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future; KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa) KPMG LLP and its subsidiaries ("KPMG") complies with all local/state regulations regarding displaying salary ranges. If required, the ranges displayed below or via the URL below are specifically for those potential hires who will work in the location(s) listed. Any offered salary is determined based on relevant factors such as applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications and market considerations. In addition, KPMG is proud to offer a comprehensive, competitive benefits package, with options designed to help you make the best decisions for yourself, your family, and your lifestyle. Available benefits are based on eligibility. Our Total Rewards package includes a variety of medical and dental plans, vision coverage, disability and life insurance, 401(k) plans, and a robust suite of personal well-being benefits to support your mental health. Depending on job classification, standard work hours, and years of service, KPMG provides Personal Time Off per fiscal year. Additionally, each year KPMG publishes a calendar of holidays to be observed during the year and provides eligible employees two breaks each year where employees will not be required to use Personal Time Off; one is at year end and the other is around the July 4th holiday. Additional details about our benefits can be found towards the bottom of our KPMG US Careers site at Benefits & How We Work . Follow this link to obtain salary ranges by city outside of CA: California Salary Range: $95855 - $208265 KPMG offers a comprehensive compensation and benefits package. KPMG is an equal opportunity employer. KPMG complies with all applicable federal, state and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other category protected by applicable federal, state or local laws. The attached link contains further information regarding KPMG's compliance with federal, state and local recruitment and hiring laws. No phone calls or agencies please. KPMG recruits on a rolling basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) for which they are qualified that is also of interest to them. Los Angeles County applicants: Material job duties for this position are listed above. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, and safeguard business operations and company reputation. Pursuant to the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers, Fair Chance Initiative for Hiring Ordinance, and San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
08/04/2026
Full time
The KPMG Advisory practice is at the forefront of transformation, offering excellent opportunities for individuals to advance their careers and expertise with KPMG. Looking ahead, we anticipate continued evolution and success within the practice, fostering both personal and professional development, thereby creating new pathways for growth. In this ever-changing market environment, our professionals must be adaptable and thrive in a collaborative, team-driven culture. At KPMG, our people are our number one priority. With a wealth of learning and career development opportunities, a world-class training facility, and leading market tools, we help our people continue to grow both professionally and personally. If you're looking for a firm with a strong team connection where you can be your whole self, have an impact, advance your skills, deepen your experiences, and have the flexibility and access to constantly find new areas of inspiration and expand your capabilities, then consider a career in Advisory. KPMG is currently seeking a Senior Associate, Privileged Access Management Delivery Engineer to join our Advisory Services practice. Responsibilities: Support the delivery, configuration, and operationalization of Privileged Access Management (PAM) solutions as part of enterprise Identity & Access Management (IAM) programs Implement and maintain PAM capabilities including privileged credential management, session management, just-in-time access, and endpoint management (EPM)components; implement automated integration across adjacent security solutions (for example: Crowdstrike, SIEM solutions, ServiceNow); automate PAM tasks using scripting and APIs (such as PowerShell, Python, REST, and others) and integrate with enterprise platforms (that is, Active Directory, IdPs, ITSM platforms, SIEM platforms, and more) Integrate PAM solutions across cloud environments (for example: Azure, AWS, GCP) while following security leading practices Execute privileged access onboarding activities, access workflow configurations, and break glass process enablement Perform risk assessments, evaluate privileged access controls, and support remediation activities across client environments Collaborate with cross-functional engineering, security, and risk teams to enhance PAM processes and resolve technical issues; support migrations from legacy or alternative PAM tooling; contribute to standardization of PAM delivery patterns and templates Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment Qualifications: Minimum three years of recent professional experience in Identity & Access Management, Privileged Access Management, or cybersecurity Bachelor's degree from an accredited college or university is required; CyberArk Certified Delivery Engineer (CDE) or CyberArk Endpoint Privilege Manager (EPM) Certification preferred Hands on experience with Privileged Access Management delivery and engineering, with specific experience using CyberArk On-Prem and SaaS solutions; additional experience with secrets management platforms (that is, Conjur, HashiCorp) and other PAM platforms (such as Delinea, BeyondTrust) preferred Familiarity with infrastructure administration (such as Windows, Linux, Databases), networking basics, and IT architecture principles preferred. Experience supporting PAM integrations within cloud platforms such as Azure, AWS, or GCP; proficiency with scripting, automation integrations, infrastructure-as-code, and configuration management Strong understanding of IAM concepts, privileged access controls, and associated security risks; strong problem solving, communication, and documentation skills with the ability to work collaboratively across teams Ability to travel as required Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future; KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa) KPMG LLP and its subsidiaries ("KPMG") complies with all local/state regulations regarding displaying salary ranges. If required, the ranges displayed below or via the URL below are specifically for those potential hires who will work in the location(s) listed. Any offered salary is determined based on relevant factors such as applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications and market considerations. In addition, KPMG is proud to offer a comprehensive, competitive benefits package, with options designed to help you make the best decisions for yourself, your family, and your lifestyle. Available benefits are based on eligibility. Our Total Rewards package includes a variety of medical and dental plans, vision coverage, disability and life insurance, 401(k) plans, and a robust suite of personal well-being benefits to support your mental health. Depending on job classification, standard work hours, and years of service, KPMG provides Personal Time Off per fiscal year. Additionally, each year KPMG publishes a calendar of holidays to be observed during the year and provides eligible employees two breaks each year where employees will not be required to use Personal Time Off; one is at year end and the other is around the July 4th holiday. Additional details about our benefits can be found towards the bottom of our KPMG US Careers site at Benefits & How We Work . Follow this link to obtain salary ranges by city outside of CA: California Salary Range: $95855 - $208265 KPMG offers a comprehensive compensation and benefits package. KPMG is an equal opportunity employer. KPMG complies with all applicable federal, state and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other category protected by applicable federal, state or local laws. The attached link contains further information regarding KPMG's compliance with federal, state and local recruitment and hiring laws. No phone calls or agencies please. KPMG recruits on a rolling basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) for which they are qualified that is also of interest to them. Los Angeles County applicants: Material job duties for this position are listed above. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, and safeguard business operations and company reputation. Pursuant to the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers, Fair Chance Initiative for Hiring Ordinance, and San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
The KPMG Advisory practice is at the forefront of transformation, offering excellent opportunities for individuals to advance their careers and expertise with KPMG. Looking ahead, we anticipate continued evolution and success within the practice, fostering both personal and professional development, thereby creating new pathways for growth. In this ever-changing market environment, our professionals must be adaptable and thrive in a collaborative, team-driven culture. At KPMG, our people are our number one priority. With a wealth of learning and career development opportunities, a world-class training facility, and leading market tools, we help our people continue to grow both professionally and personally. If you're looking for a firm with a strong team connection where you can be your whole self, have an impact, advance your skills, deepen your experiences, and have the flexibility and access to constantly find new areas of inspiration and expand your capabilities, then consider a career in Advisory. KPMG is currently seeking a Senior Associate, Privileged Access Management Delivery Engineer to join our Advisory Services practice. Responsibilities: Support the delivery, configuration, and operationalization of Privileged Access Management (PAM) solutions as part of enterprise Identity & Access Management (IAM) programs Implement and maintain PAM capabilities including privileged credential management, session management, just-in-time access, and endpoint management (EPM)components; implement automated integration across adjacent security solutions (for example: Crowdstrike, SIEM solutions, ServiceNow); automate PAM tasks using scripting and APIs (such as PowerShell, Python, REST, and others) and integrate with enterprise platforms (that is, Active Directory, IdPs, ITSM platforms, SIEM platforms, and more) Integrate PAM solutions across cloud environments (for example: Azure, AWS, GCP) while following security leading practices Execute privileged access onboarding activities, access workflow configurations, and break glass process enablement Perform risk assessments, evaluate privileged access controls, and support remediation activities across client environments Collaborate with cross-functional engineering, security, and risk teams to enhance PAM processes and resolve technical issues; support migrations from legacy or alternative PAM tooling; contribute to standardization of PAM delivery patterns and templates Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment Qualifications: Minimum three years of recent professional experience in Identity & Access Management, Privileged Access Management, or cybersecurity Bachelor's degree from an accredited college or university is required; CyberArk Certified Delivery Engineer (CDE) or CyberArk Endpoint Privilege Manager (EPM) Certification preferred Hands on experience with Privileged Access Management delivery and engineering, with specific experience using CyberArk On-Prem and SaaS solutions; additional experience with secrets management platforms (that is, Conjur, HashiCorp) and other PAM platforms (such as Delinea, BeyondTrust) preferred Familiarity with infrastructure administration (such as Windows, Linux, Databases), networking basics, and IT architecture principles preferred. Experience supporting PAM integrations within cloud platforms such as Azure, AWS, or GCP; proficiency with scripting, automation integrations, infrastructure-as-code, and configuration management Strong understanding of IAM concepts, privileged access controls, and associated security risks; strong problem solving, communication, and documentation skills with the ability to work collaboratively across teams Ability to travel as required Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future; KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa) KPMG LLP and its subsidiaries ("KPMG") complies with all local/state regulations regarding displaying salary ranges. If required, the ranges displayed below or via the URL below are specifically for those potential hires who will work in the location(s) listed. Any offered salary is determined based on relevant factors such as applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications and market considerations. In addition, KPMG is proud to offer a comprehensive, competitive benefits package, with options designed to help you make the best decisions for yourself, your family, and your lifestyle. Available benefits are based on eligibility. Our Total Rewards package includes a variety of medical and dental plans, vision coverage, disability and life insurance, 401(k) plans, and a robust suite of personal well-being benefits to support your mental health. Depending on job classification, standard work hours, and years of service, KPMG provides Personal Time Off per fiscal year. Additionally, each year KPMG publishes a calendar of holidays to be observed during the year and provides eligible employees two breaks each year where employees will not be required to use Personal Time Off; one is at year end and the other is around the July 4th holiday. Additional details about our benefits can be found towards the bottom of our KPMG US Careers site at Benefits & How We Work . Follow this link to obtain salary ranges by city outside of CA: California Salary Range: $95855 - $208265 KPMG offers a comprehensive compensation and benefits package. KPMG is an equal opportunity employer. KPMG complies with all applicable federal, state and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other category protected by applicable federal, state or local laws. The attached link contains further information regarding KPMG's compliance with federal, state and local recruitment and hiring laws. No phone calls or agencies please. KPMG recruits on a rolling basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) for which they are qualified that is also of interest to them. Los Angeles County applicants: Material job duties for this position are listed above. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, and safeguard business operations and company reputation. Pursuant to the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers, Fair Chance Initiative for Hiring Ordinance, and San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
08/04/2026
Full time
The KPMG Advisory practice is at the forefront of transformation, offering excellent opportunities for individuals to advance their careers and expertise with KPMG. Looking ahead, we anticipate continued evolution and success within the practice, fostering both personal and professional development, thereby creating new pathways for growth. In this ever-changing market environment, our professionals must be adaptable and thrive in a collaborative, team-driven culture. At KPMG, our people are our number one priority. With a wealth of learning and career development opportunities, a world-class training facility, and leading market tools, we help our people continue to grow both professionally and personally. If you're looking for a firm with a strong team connection where you can be your whole self, have an impact, advance your skills, deepen your experiences, and have the flexibility and access to constantly find new areas of inspiration and expand your capabilities, then consider a career in Advisory. KPMG is currently seeking a Senior Associate, Privileged Access Management Delivery Engineer to join our Advisory Services practice. Responsibilities: Support the delivery, configuration, and operationalization of Privileged Access Management (PAM) solutions as part of enterprise Identity & Access Management (IAM) programs Implement and maintain PAM capabilities including privileged credential management, session management, just-in-time access, and endpoint management (EPM)components; implement automated integration across adjacent security solutions (for example: Crowdstrike, SIEM solutions, ServiceNow); automate PAM tasks using scripting and APIs (such as PowerShell, Python, REST, and others) and integrate with enterprise platforms (that is, Active Directory, IdPs, ITSM platforms, SIEM platforms, and more) Integrate PAM solutions across cloud environments (for example: Azure, AWS, GCP) while following security leading practices Execute privileged access onboarding activities, access workflow configurations, and break glass process enablement Perform risk assessments, evaluate privileged access controls, and support remediation activities across client environments Collaborate with cross-functional engineering, security, and risk teams to enhance PAM processes and resolve technical issues; support migrations from legacy or alternative PAM tooling; contribute to standardization of PAM delivery patterns and templates Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment Qualifications: Minimum three years of recent professional experience in Identity & Access Management, Privileged Access Management, or cybersecurity Bachelor's degree from an accredited college or university is required; CyberArk Certified Delivery Engineer (CDE) or CyberArk Endpoint Privilege Manager (EPM) Certification preferred Hands on experience with Privileged Access Management delivery and engineering, with specific experience using CyberArk On-Prem and SaaS solutions; additional experience with secrets management platforms (that is, Conjur, HashiCorp) and other PAM platforms (such as Delinea, BeyondTrust) preferred Familiarity with infrastructure administration (such as Windows, Linux, Databases), networking basics, and IT architecture principles preferred. Experience supporting PAM integrations within cloud platforms such as Azure, AWS, or GCP; proficiency with scripting, automation integrations, infrastructure-as-code, and configuration management Strong understanding of IAM concepts, privileged access controls, and associated security risks; strong problem solving, communication, and documentation skills with the ability to work collaboratively across teams Ability to travel as required Applicants must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future; KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa) KPMG LLP and its subsidiaries ("KPMG") complies with all local/state regulations regarding displaying salary ranges. If required, the ranges displayed below or via the URL below are specifically for those potential hires who will work in the location(s) listed. Any offered salary is determined based on relevant factors such as applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications and market considerations. In addition, KPMG is proud to offer a comprehensive, competitive benefits package, with options designed to help you make the best decisions for yourself, your family, and your lifestyle. Available benefits are based on eligibility. Our Total Rewards package includes a variety of medical and dental plans, vision coverage, disability and life insurance, 401(k) plans, and a robust suite of personal well-being benefits to support your mental health. Depending on job classification, standard work hours, and years of service, KPMG provides Personal Time Off per fiscal year. Additionally, each year KPMG publishes a calendar of holidays to be observed during the year and provides eligible employees two breaks each year where employees will not be required to use Personal Time Off; one is at year end and the other is around the July 4th holiday. Additional details about our benefits can be found towards the bottom of our KPMG US Careers site at Benefits & How We Work . Follow this link to obtain salary ranges by city outside of CA: California Salary Range: $95855 - $208265 KPMG offers a comprehensive compensation and benefits package. KPMG is an equal opportunity employer. KPMG complies with all applicable federal, state and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other category protected by applicable federal, state or local laws. The attached link contains further information regarding KPMG's compliance with federal, state and local recruitment and hiring laws. No phone calls or agencies please. KPMG recruits on a rolling basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) for which they are qualified that is also of interest to them. Los Angeles County applicants: Material job duties for this position are listed above. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, and safeguard business operations and company reputation. Pursuant to the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers, Fair Chance Initiative for Hiring Ordinance, and San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.