PAM and Secrets Management Engineer
Applied Materials
- Location
- Bangalore,IND
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 125 approvals (FY2023)
- Posted
- Aug 21, 2026
Skills
About this role
Who We Are
Applied Materials is the global leader in materials science and engineering solutions that are at the foundation of virtually every new semiconductor chip and advanced display in the world. The equipment that we create and service is essential to advancing AI and accelerating the commercialization of next-generation semiconductor chips. Join us and push the boundaries of materials science and engineering in a company at the foundation of the electronics industry. The work we do together advances the world’s technology.
What We Offer
Location: Bangalore,IND You’ll benefit from a supportive work culture that encourages you to learn, develop, and grow your career as you take on challenges and drive innovative solutions for our customers. We empower our team to push the boundaries of what is possible—while learning every day in a supportive leading global company. Visit our Careers website to learn more. At Applied Materials, we care about the health and wellbeing of our employees. We’re committed to providing programs and support that encourage personal and professional growth and care for you at work, at home, or wherever you may go. Learn more about our benefits .
About the Role
Join Applied Materials as a PAM & Secrets Management Engineer to lead privileged access management and secrets management initiatives across our global enterprise infrastructure. You'll architect and operate enterprise-scale PAM solutions (CyberArk) and HashiCorp Vault, working at the intersection of security, DevOps, and cloud platforms to protect critical systems and enable secure development.
Key Responsibilities
Privileged Access Management (PAM) Design, implement, and manage enterprise PAM solutions at scale (500+ concurrent sessions, 2K+ daily logins, 2.5K+ targets) Operate and maintain CyberArk self-hosted environment lead evaluation of alternatives (Delinea, BeyondTrust, CyberArk Privilege Cloud) Architect privileged session management (PSM) for RDP, SSH with native client support and passwordless credential injection Implement automated account discovery and onboarding workflows (Windows local, AD, Linux/Unix accounts) Configure session recording, monitoring, and alerting for compliance and security Troubleshoot and resolve PAM infrastructure stability issues (eliminating outages) Secrets Management Architect and operate HashiCorp Vault Enterprise at scale across multi-cloud environments Implement Vault secrets engines: KV v2, Dynamic Secrets (LDAP, Azure, databases), PKI, Transit Encryption Design and deploy Vault authentication methods: OIDC/JWT, Kubernetes, AppRole, AWS IAM, Azure AD Configure Vault policies and namespaces for multi-tenant secret isolation Integrate Vault with CI/CD pipelines (Jenkins, GitLab, GitHub Actions, Azure DevOps) for secure secret injection Implement Vault Agent and sidecar injectors for application secret delivery Configure Vault auto-unseal with cloud KMS (AWS KMS, Azure Key Vault, GCP Cloud KMS) Manage Vault high availability, disaster recovery, and performance tuning Implement secret rotation automation for databases, cloud credentials, and API keys Cross-Functional Collaboration Partner with CI/CD, Network, Cloud, and Platform teams to integrate PAM/SM controls Lead incident response for privileged access breaches and secrets exposure events Conduct security assessments and ensure compliance with SOX, PCI-DSS, ISO 27001 Automate PAM and Secret Management workflows using Python, Bash, PowerShell, Terraform, Ansible Required Qualifications Privileged Access Management (PAM) Expertise: 5+ years hands-on experience with enterprise PAM solutions at scale (10,000+ employees or global infrastructure) Deep experience with privileged session management: RDP, SSH session recording, monitoring, and credential injection Strong understanding of account lifecycle management: discovery, onboarding, rotation for Windows local, AD, Linux/Unix accounts Experience with PAM platforms: