Privileged Access Management (PAM) Engineer (GOV) - Tempus
PNC Financial
- Location
- ZZ - Remote Location
- Work model
- Remote
- Level
- Mid
- Posted
- Sep 1, 2026
Skills
About this role
Position
Overview At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all of our employees feel respected, valued and have an opportunity to contribute to the company’s success. As a Privileged Access Management (PAM) Engineer within PNC's Tempus Technologies organization, you may be based in a remote location. Tempus Technologies, Inc. is the expert leader of secure payments at the point of interaction. For more than 25 years, innovation and producing high quality custom-ready solutions is at the forefront of everything we do. We’re committed to developing exceptional point-of-sale payment integration technology and software solutions to meet the growing needs of our customers’ business requirements. Our knowledgeable and friendly employees are passionately dedicated to delivering world-class support to every client. We thrive in a transparent culture that understands the value of shared ideas, teamwork, and excellence in everything we do. The Privileged Access Management (PAM) Engineer is responsible for the hands‑on engineering, integration, and operation of privileged access and secrets management platforms, with a primary focus on CyberArk Privileged Access Management and HashiCorp Vault. This role serves as a technical subject matter expert for privileged access controls, ensuring administrative, service, and application credentials are securely managed, rotated, and audited. The PAM Engineer partners closely with Infrastructure, Cloud, Application Engineering, DevOps, Security Operations, and Compliance teams to enforce least privilege, reduce credential‑based risk, and support secure business operations. The ideal candidate brings strong technical depth in CyberArk and Vault, a deep understanding of privileged access risk, and the ability to integrate PAM capabilities across hybrid infrastructure, cloud platforms, and modern application environments.
Responsibilities
Core PAM Operations · Operate and support day to day Privileged Access Management services, ensuring secure and reliable privileged access. · Manage onboarding, modification, and decommissioning of privileged accounts. · Troubleshoot and resolve PAM related incidents, access issues, and platform errors. · Ensure PAM services meet availability, performance, and operational support expectations. Privileged Access Management · Serve as the primary technical engineer and platform owner for CyberArk PAM. · Onboard privileged accounts, systems, and platforms into CyberArk. · Configure credential vaulting, rotation policies, access workflows, and session recording. · Implement approval workflows and controls for administrative and emergency access. · Partner with infrastructure and application teams to integrate servers, databases, and platforms into PAM. · Monitor and maintain CyberArk components, connectors, and job health. Secrets Management (HashiCorp Vault) · Engineer and operate enterprise secrets management using HashiCorp Vault. · Implement secure storage, access control, and rotation of application and infrastructure secrets. · Integrate Vault with CI/CD pipelines, cloud services, and runtime environments. · Support dynamic secrets, short lived credentials, and non-human identity use cases. · Partner with development teams to adopt secure secrets management patterns. Integration & Automation · Integrate PAM solutions with on prem, hybrid, and cloud environments. · Support API based integrations and automation for privileged access and secrets usage. · Collaborate with DevOps and platform teams to reduce hard coded credentials and manual processes. · Improve onboarding speed and consistency through automation and standardization. PAM Platform Operations & Continuous Improvement · Monitor PAM health, usage, and access activity. ·