Position OverviewAs a Privileged Access Management (PAM) Engineer within PNC's Tempus Technologies organization, you may be based in a remote location.
The Privileged Access Management (PAM) Engineer is responsible for the hands‑on engineering, integration, and operation of privileged access and secrets management platforms, with a primary focus on CyberArk Privileged Access Management and HashiCorp Vault.
This role serves as a technical subject matter expert for privileged access controls, ensuring administrative, service, and application credentials are securely managed, rotated, and audited. The PAM Engineer partners closely with Infrastructure, Cloud, Application Engineering, DevOps, Security Operations, and Compliance teams to enforce least privilege, reduce credential‑based risk, and support secure business operations.
The ideal candidate brings strong technical depth in CyberArk and Vault, a deep understanding of privileged access risk, and the ability to integrate PAM capabilities across hybrid infrastructure, cloud platforms, and modern application environments.
Responsibilities:
Core PAM Operations
· Operate and support day to day Privileged Access Management services, ensuring secure and reliable privileged access.
· Manage onboarding, modification, and decommissioning of privileged accounts.
· Troubleshoot and resolve PAM related incidents, access issues, and platform errors.
· Ensure PAM services meet availability, performance, and operational support expectations.
Privileged Access Management
· Serve as the primary technical engineer and platform owner for CyberArk PAM.
· Onboard privileged accounts, systems, and platforms into CyberArk.
· Configure credential vaulting, rotation policies, access workflows, and session recording.
· Implement approval workflows and controls for administrative and emergency access.
· Partner with infrastructure and application teams to integrate servers, databases, and platforms into PAM.
· Monitor and maintain CyberArk components, connectors, and job health.
Secrets Management (HashiCorp Vault)
· Engineer and operate enterprise secrets management using HashiCorp Vault.
· Implement secure storage, access control, and rotation of application and infrastructure secrets.
· Integrate Vault with CI/CD pipelines, cloud services, and runtime environments.
· Support dynamic secrets, short lived credentials, and non-human identity use cases.
· Partner with development teams to adopt secure secrets management patterns.
Integration & Automation
· Integrate PAM solutions with on prem, hybrid, and cloud environments.
· Support API based integrations and automation for privileged access and secrets usage.
· Collaborate with DevOps and platform teams to reduce hard coded credentials and manual processes.
· Improve onboarding speed and consistency through automation and standardization.
PAM Platform Operations & Continuous Improvement
· Monitor PAM health, usage, and access activity.
· Analyze trends and issues to improve reliability and reduce operational risk.
· Maintain PAM technical documentation, standards, and operational runbooks.
· Identify and implement improvements to strengthen privileged access controls and scalability.
Compliance & Audit Support
· Support audit and compliance activities related to privileged access and secrets management.
· Produce reports and evidence for access usage, approvals, and session activity.
· Assist with remediation of policy violations or audit findings.
· Ensure privileged access controls align with least privilege and regulatory requirements.
Key Relationships:
· Identity and Access Management Lead
· Security Operations & Application Security Teams
· IT Infrastructure, Cloud & DevOps Teams
· Software Development Teams
· Compliance, Audit & Risk Management
· External Vendors & Implementation Partners
Qualifications:
· Hands‑on experience with HashiCorp Vault for secrets management.
· Strong understanding of privileged access risks, least privilege, and credential management.
· Experience integrating PAM solutions across servers, databases, applications, and cloud platforms.
· Familiarity with Linux and Windows administration, scripting, and automation.
· Experience operating in regulated or audited environments (PCI DSS, SOC 2, SOX, HIPAA, etc.).
· Strong troubleshooting, analytical, and problem‑solving skills.
· Ability to communicate effectively with both technical and non‑technical stakeholders.
This position may be eligible for remote work in select geographic locations, subject to approval by PNC. If approved, work must be conducted from a quiet, secure, and confidential home-based workspace. Occasional in-office participation may be required based on business needs.
Job Description- Provides subject matter expertise when applying security concepts. Leverages technical knowledge and industry experience to design, build, and maintain technology solutions. Responsible for deliverables related to project timelines.
- Responsible for working with architecture to take high level architectural designs and determine the specifics around implementation details (ex: sizing) integration details, onboarding and operationalization.
- Evaluates patches, updates, and ongoing maintenance. Determines impacts to existing solutions when new standards are implemented. Utilizes change control and other governance processes to ensure alignment of solutions .
- Develops detailed implementation, configuration, design, and engineering documentation. Build and implement solutions.
- Works with operational partners to enable transition and day-to-day supportability.
- Provides engineering support to existing technology in a production environment and collaborating with other groups as required. Seeks opportunities to grow a broad knowledge base to complement specific subject matter expertise.
Qualifications
Successful candidates must demonstrate appropriate knowledge, skills, and abilities for a role. Listed below are skills, competencies, work experience, education, and required certifications/licensures needed to be successful in this position.
CompetenciesAnalytical Thinking, Effective Communications, Information Security Management, Information Security Technologies, IT Environment, IT Standards, Procedures & Policies, IT Systems Management, Network and Internet Security, Problem Solving, Technical Troubleshooting
Work ExperienceRoles at this level typically require a university / college degree, with 5+ years of industry-relevant experience. Specific certifications are often required. In lieu of a degree, a comparable combination of education, job specific certification(s), and experience (including military service) may be considered.
EducationBachelors (Required)
CertificationsNo Required Certification(s)
LicensesCandidates being considered for the position will be subject to additional background checks as established by the specific government client contract.
Language Assessments
No Required or Preferred Language Assessments
Pay TransparencyBase Salary: $91,000.00 – $202,800.00
Salaries may vary based on geographic location, market data and on individual skills, experience, and education. This role is incentive eligible with the payment based upon company, business and/or individual performance.
Application WindowGenerally, this opening is expected to be posted for two business days from 08/31/2026, although it may be longer with business discretion.
BenefitsPNC offers a comprehensive range of benefits to help meet your needs now and in the future. Depending on your eligibility, options for full-time employees include: medical/prescription drug coverage (with a Health Savings Account feature), dental and vision options; employee and spouse/child life insurance; short and long-term disability protection; 401(k) with PNC match, pension and stock purchase plans; dependent care reimbursement account; back-up child/elder care; adoption, surrogacy, and doula reimbursement; educational assistance, including select programs fully paid; a robust wellness program with financial incentives.
In addition, PNC generally provides the following paid time off, depending on your eligibility: maternity and/or parental leave; up to 11 paid holidays each year; 9 occasional absence days each year, unless otherwise