11 Sep
|
Quess IT Staffing
|
Mumbai
11 Sep
Quess IT Staffing
Mumbai
The L2 PIM/PAM Engineer is responsible for day-to-day administration, onboarding, and incident troubleshooting across enterprise Privileged Access Management platforms (e.g., CyberArk, BeyondTrust, Microsoft Entra PIM). In addition to operational maintenance, this role actively validates, audits, and assesses technical controls to ensure privileged accounts adhere to strict zero-trust and least-privilege standards.
Key Responsibilities
Implementation & Support (L2 Operations)
- Handle Day-2 operations, ticket escalations, and incident resolution for PAM components (Secure management, account onboarding, CPM/PSM failures, and policy errors).
- Onboard target systems (Windows, Linux, databases, network devices, and cloud infrastructure) into PAM vaults with automated credential rotation.
- Manage Just-In-Time (JIT) access requests, time-bound approvals, and role-activation workflows in Microsoft Entra PIM and PAM solutions.
- Monitor health checks for core PAM services (Vaults, Proxies, Discovery agents, Session Recording servers) and coordinate with vendor support or L3 teams for complex outages.
- Configure, test, and maintain custom plugins, CPM platform management policies, and connection components.
Technical Controls Assessment & Validation
- Conduct routine technical assessments to verify that credential auto-rotation, check-in/check-out policies, and password complexity controls function across all onboarded targets.
- Validate that Privileged Session Monitoring (PSM) and keylogging controls capture and index administrative sessions without bypassing.
- Audit Entra PIM policies: verify mandatory MFA triggers, justification requirements, approval chains, and maximum activation duration limits.
- Perform discovery scans to identify unmanaged privileged accounts, service accounts, and shadow admins across Active Directory, cloud, and hybrid environments.
- Generate compliance evidence and remediate gaps aligned with audit standards (CIS Benchmarks, ISO 27001, SOC 2).
Required Skills & Qualifications
- Core Platforms: Hands-on experience with at least one enterprise PAM tool (CyberArk PAS/Privilege Cloud, BeyondTrust Password Safe, Delinea/Thycotic) and Cloud PIM (Microsoft Entra ID PIM).
- Operating Systems & Networking: Working knowledge of Windows Server (Active Directory, Kerberos, GPOs), Linux/Unix (SSH, PAM modules, sudoers), and networking fundamentals (firewall ports, DNS, RDP, SSH).
- Scripting: Basic PowerShell, Bash, or Python scripting skills to assist with automated onboarding, discovery parsing, and API calls.
- Security Principles: Solid understanding of Least Privilege, Zero Trust, MFA, Session Isolation, and Break-Glass procedures.
Preferred Certifications
- CyberArk Defender (PAM-DEF) or Sentry (PAM-SEN)
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- CompTIA Security+ or SSCP
📌 PIM/PAM Engineer @ Mumbai
🏢 Quess IT Staffing
📍 Mumbai