PAM and Secrets Management Engineer (Bengaluru)

PAM and Secrets Management Engineer (Bengaluru)

11 Aug
|
Nameless
|
Bengaluru

11 Aug

Nameless

Bengaluru

About the RolennJoin Applied Materials as a PAM u0026 Secrets Management Engineer to lead privileged access management and secrets management initiatives across our global enterprise infrastructure. Youu0027ll architect and operate enterprise-scale PAM solutions (CyberArk) and HashiCorp Vault, working at the intersection of security, DevOps, and cloud platforms to protect critical systems and enable secure development.nnKey ResponsibilitiesnnPrivileged Access Management (PAM)nn * Design, implement, and manage enterprise PAM solutions at scale (500+ concurrent sessions, 2K+ daily logins, 2.5K+ targets)n * Operate and maintain CyberArk self-hosted environment lead evaluation of alternatives (Delinea, BeyondTrust, CyberArk Privilege Cloud)n * Architect privileged session management (PSM) for RDP, SSH with native client support and passwordless credential injectionn * Implement automated account discovery and onboarding workflows (Windows local, AD, Linux/Unix accounts)n * Configure session recording, monitoring, and alerting for compliance and securityn * Troubleshoot and resolve PAM infrastructure stability issues (eliminating outages)nnnnSecrets Managementnn * Architect and operate HashiCorp Vault Enterprise at scale across multi-cloud environmentsn * Implement Vault secrets engines: KV v2, Dynamic Secrets (LDAP, Azure, databases), PKI, Transit Encryptionn * Design and deploy Vault authentication methods: OIDC/JWT, Kubernetes, AppRole, AWS IAM, Azure ADn * Configure Vault policies and namespaces for multi-tenant secret isolationn * Integrate Vault with CI/CD pipelines (Jenkins, GitLab, GitHub Actions, Azure DevOps) for secure secret injectionn * Implement Vault Agent and sidecar injectors for application secret deliveryn * Configure Vault auto-unseal with cloud KMS (AWS KMS, Azure Key Vault, GCP Cloud KMS)n * Manage Vault high availability, disaster recovery, and performance tuningn * Implement secret rotation automation for databases, cloud credentials, and API keysnnnnCross-Functional Collaborationnn * Partner with CI/CD, Network, Cloud, and Platform teams to integrate PAM/SM controlsn * Lead incident response for privileged access breaches and secrets exposure eventsn * Conduct security assessments and ensure compliance with SOX, PCI-DSS, ISO 27001n * Automate PAM and Secret Management workflows using Python, Bash, PowerShell, Terraform, AnsiblennnnRequired QualificationsnnPrivileged Access Management (PAM)



Expertise:nn * 5+ years hands-on experience with enterprise PAM solutions at scale (10,000+ employees or global infrastructure)n * Deep experience with privileged session management: RDP, SSH session recording, monitoring, and credential injectionn * Strong understanding of account lifecycle management: discovery, onboarding, rotation for Windows local, AD, Linux/Unix accountsn * Experience with PAM platforms: CyberArk (PAS, PVWA, CPM, PSM) or equivalent (BeyondTrust, Delinea, Arcon)n * Knowledge of least privilege principles and privilege elevation workflowsn * Experience integrating PAM with approval workflows (ServiceNow, ITSM tools)n * Understanding of session isolation, credential vaulting, and password/SSH key rotationn * Familiarity with PAM architecture: high availability, disaster recovery, horizontal scalingnnnnSecrets Management Expertise:nn * 3+ years hands-on experience with HashiCorp Vault in production environmentsn * Deep knowledge of Vault secrets engines: KV (v1/v2), Agile Secrets (databases, AWS, Azure), PKI, Transit, SSH, TOTPn * Experience with Vault authentication methods: Kubernetes, AppRole, OIDC/JWT, AWS IAM, Azure AD, LDAP, TLS Certificatesn * Strong understanding of Vault policies, namespaces, and entity/identity managementn * Experience with Vault Agent, sidecar injectors, and application integration patternsn * Knowledge of Vault operations: auto-unseal (HSM), replication (DR/Performance), backup/restore, upgradesn * Experience integrating Vault with CI/CD pipelines for dynamic secret injectionn * Understanding of secret zero problem and secure secret bootstrap mechanismsnnnnTechnical u0026 Cloud Skills:nn * Multi-cloud secrets management: AWS Secrets Manager/IAM, Azure Key Vault/Managed Identity, GCP Secret Managern * Experience with Kubernetes: Vault sidecar injection, CSI secret driver, external secrets operatorn * Proficiency in scripting and automation: Python, Bash, PowerShell, Go (preferred)n * Experience with Infrastructure-as-Code: Terraform, Ansible (Vault configuration automation)n * Understanding of PKI fundamentals: certificate lifecycle, CA hierarchies, mTLS, certificate-based authenticationn * Experience with Directory services: Active Directory, LDAP (for PAM/Vault integration)nnnnCollaboration u0026 Communication Skills:nn * Proven track record working with DevOps, Platform Engineering, Cloud,



and Network teamsn * Strong communication skills with technical and non-technical stakeholdersn * Ability to lead cross-functional PAM/SM initiatives and provide technical mentorshipn * Experience in incident response for privileged access and secret exposure eventsnnnnPreferred Qualifications (Advantages)nn * CyberArk Certified: CyberArk Defender, Sentry, or Trustee certificationsn * Hands-on experience in Delinea Secret Server, BeyondTrust, Arcon, CyberArk Privilege Cloudn * Experience with account discovery automation and policy-based onboarding at scalen * HashiCorp Certified: Vault Associate or Vault Professional certificationn * Deep knowledge of Vault database secrets engine: PostgreSQL, MySQL, MongoDB, MSSQL, Oracle dynamic credentialsn * Hands-on with Vault Transit engine: encryption-as-a-service, key derivation, convergent encryptionn * Experience with Vault SSH secrets engine: signed SSH certificates, OTP SSH, CA-based SSH accessn * Experience with Vault KMIP secrets engine for legacy application encryption key managementn * Experience with Vault monitoring: metrics (Prometheus), logging, audit logs, performance tuningnnnnCertifications u0026 Education:nn * Bacheloru0027s degree in Computer Science, Information Security, or related fieldn * Professional certifications: CyberArk CDE/Sentry, HashiCorp Vault Associate/Professional, CISSP, CISM, CISA, CEHn * Cloud certifications: AWS Security Specialty, Azure Security Engineer, GCP Security EngineernnnnCompliance u0026 Architecture:nn * Deep knowledge of compliance frameworks: SOX, PCI-DSS, NIST CSF, ISO 27001, GDPR, HIPAAn * Experience with zero-trust architecture and secrets management in zero-trust modelsn * Understanding of threat modeling for privileged access and secret exposure risksnnnn## Qualificationsnn### Education:nnBacheloru0027s Degreenn### Skillsnn### Certifications:nn### Languages:nn### Years of Experience:nn4 - 7 Yearsnn### Work Experience:nn## Additional Informationnn### nn### Shift:nnSwing (India)nn### nn### Travel:nnYes, 10% of the Timenn### nn### Relocation Eligible:nnYesnn### Referral Payment Plan:nnEmployee Referral (Standard)nnApplied Materials is an Equal Opportunity Employer committed to diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race, color, national origin, citizenship, ancestry, religion, creed, sex, sexual orientation, gender identity, age, disability, veteran or military status, or any other basis prohibited by law. n

📌 PAM and Secrets Management Engineer (Bengaluru)
🏢 Nameless
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: pam and secrets management engineer (bengaluru) / bengaluru