JOB SUMMARYThis position is responsible for designing, implementing, and maintaining privileged access security controls across UTSW's on-premises and cloud environments. This role ensures the protection of high-risk accounts and credentials by deploying enterprise-grade Privileged Access Management (PAM) solutions, integrating with identity platforms, and enforcing least-privilege principles. The engineer will lead technical onboarding of privileged accounts, automate credential rotation, and implement session monitoring to reduce operational risk. Collaboration with Information Security, Infrastructure, and Application teams is essential to align PAM capabilities with UTSW's IAM roadmap, regulatory compliance (HIPAA, NIST), and audit requirements.
This is NOT a 100% remote position, but it is eligible for a hybrid work schedule. BENEFITSUT Southwestern is proud to offer a competitive and comprehensive benefits package to eligible employees. Our benefits are designed to support your overall wellbeing, and include:
- PPO medical plan, available day one at no cost for full-time employee-only coverage
- 100% coverage for preventive healthcare-no copay
- Paid Time Off, available day one
- Retirement Programs through the Teacher Retirement System of Texas (TRS)
- Paid Parental Leave Benefit
- Wellness programs
- Tuition Reimbursement
- Public Service Loan Forgiveness (PSLF) Qualified Employer
- Learn more about these and other UTSW employee benefits!
EXPERIENCE AND EDUCATIONRequired- Education
Bachelor's Degree with major coursework in computer science, math, information systems or other related field.
- Experience
5 years of experience in field directly related to operating systems and systems administration, including experience working with and maintaining IGA or PAM tools.
Experience with project management phases and methodologies, as it relates to assigned projects and tasks.
An equivalent combination of education and/or directly related experience may be substituted in lieu of the stated requirements.
Preferred- Licenses and Certifications
CISSP, Microsoft Certified: Identity & Access Administrator, CyberArk Guardian/Sentry, or equivalent.
JOB DUTIES- Deploy and maintain PAM platforms (CyberArk, BeyondTrust, Microsoft Entra ID PIM).
- Integrate PAM with Active Directory, MFA (Duo), and cloud services.
- Onboard privileged accounts, automate credential rotation, and manage sessions.
- Define PAM policies, standards, and operational runbooks.
- Monitor KPIs and provide audit evidence for HIPAA/NIST compliance.
- Support incident response for privileged account misuse or compromise.
- Responsible for developing documentation relative to assigned projects and tasks including documentation related to system testing, disaster recovery and routine system administration processes.
- Performs other duties as assigned.