Source description
About the role
PAM Engineering & BeyondTrust Platform Management
Engineer, configure, maintain, and optimise BeyondTrust Password Safe and associated PAM components.
Support the technical design and implementation of PAM controls across Windows, Linux, databases, cloud platforms, network devices, developer platforms, and privileged applications.
Configure managed systems, managed accounts, access policies, credential rotation, password checkout restrictions, session recording, and approval workflows.
Develop and maintain PAM platform standards, configuration baselines, runbooks, and operational procedures.
Privileged Account Discovery, Onboarding & Lifecycle Management
Lead technical onboarding of privileged accounts into BeyondTrust, including domain administrators, local administrators, sudo accounts, database administrators, cloud administrators, application administrators, and service accounts.
Support discovery of unmanaged, shared, orphaned, duplicate, stale, and over-privileged accounts across the estate.
Work with platform owners to define account ownership, access requirements, rotation rules, session controls, and recertification processes.
Implement lifecycle controls for privileged users, shared accounts, break-glass accounts, service accounts, secrets, keys, and non-human identities.
Integration, Automation & Engineering Improvement
Integrate PAM with Active Directory, Microsoft Entra ID, cloud IAM, infrastructure platforms, service management workflows, logging platforms, and monitoring tools.
Develop automation to support account discovery, onboarding, rotation validation, reporting, access reviews, and control assurance.
Use scripting and APIs to improve PAM operational efficiency, reduce manual effort, and strengthen repeatable engineering processes.
Support secure integration patterns for DevOps pipelines, automation accounts, secrets management, and non-human identities.
Least Privilege, JIT Access & Control Enforcement
Support the removal of standing privileged access and implementation of just-in-time access models.
Configure risk-based approval workflows, time-bound access, session monitoring, and stronger controls for production and critical systems.
Work with IAM, Infrastructure, Cloud Operations, and application teams to ensure privileged access is brokered through PAM wherever technically feasible.
Help define and implement controls that prevent direct privileged login outside approved PAM workflows.
Monitoring, Reporting & Audit Evidence
Produce PAM reporting on privileged account coverage, rotation status, session activity, onboarding progress, exceptions, break-glass use, and access review outcomes.
Support audit, compliance, and customer assurance activities by providing accurate evidence of PAM controls and privileged activity.
Review PAM alerts, session logs, access patterns, and control exceptions to identify issues requiring remediation.
Track PAM risks, operational issues, and improvement actions through to closure.
Stakeholder Engagement & Continuous Improvement
Partner with technical teams to embed PAM requirements into new platforms, applications, cloud services, and operational processes.
Provide technical guidance to administrators and platform owners on PAM onboarding, privileged account handling, secrets management, and secure access patterns.
Contribute to the maturity of Keyloop’s PAM operating model, including processes, governance, ownership, reporting, and support handover.
Stay current with PAM, IAM, cloud security, privileged threat, and BeyondTrust platform developments.
More at Keyloop
Related open roles
Solution Manager
Hyderabad
Principal Infrastructure Engineer (Linux Expert)
Hyderabad · Hybrid
Supply and Demand Support Analyst - Keyloop Leads
Hyderabad · Hybrid
Senior Boomi Developer
Hyderabad · Hybrid
Business Systems Analyst (Data & Integration)
Hyderabad · Hybrid
Privileged Access Management Analyst
Hyderabad · Hybrid
