Associate - IAM Engineering (PAM) - Global Information Security
Jefferies · Pune, India · 9h ago
Innovation Hub Overview
Jefferies is creating a Technology Innovation Hub in Pune, a greenfield opportunity to build the systems that power global markets. As our first India technology center, this hub brings together hands on builders who engineer the platforms behind Jefferies’ growth across capital markets, investment banking, and institutional securities. We’re scaling toward an elite team of 500 engineers while maintaining the agility, ownership, and meritocratic spirit that defines Jefferies. From cloud and data to AI, risk, and core business technologies, teams in Pune will lead high impact work with a global mandate.
IT Security Technology
Jefferies’ IT Security Technology / Global Information Security (GIS) team protects the firm’s critical systems, sensitive information, and global operations against evolving cyber threats. GIS partners with Technology, Operations, Corporate functions, and the Business to embed security into day-to-day operations while supporting productivity, regulatory compliance, and operational resilience. GIS balances strong controls with efficiency and operates globally across the US, EMEA, and APAC to provide round-the-clock coverage.
Role Overview
Jefferies India is seeking a skilled and motivated Privileged Access Management Engineer to join our cybersecurity team in Pune. The ideal candidate will have 3+ years of hands-on experience supporting and managing Privileged Access Management platforms, including CyberArk Password Vault, CyberArk EPM, BeyondTrust SRA/RA, and HashiCorp Vault.
This role will be responsible for supporting PAM infrastructure, ensuring platform stability, managing upgrades and integrations, and helping enhance privileged access and secrets management capabilities across the firm’s global technology environment.
Key Responsibilities
- Manage, support, and maintain PAM infrastructure across CyberArk Password Vault, CyberArk Endpoint Privilege Manager, BeyondTrust SRA/RA, and HashiCorp Vault.
- Perform platform maintenance, health checks, monitoring, backup and recovery activities, capacity planning, and operational stability checks.
- Plan and execute platform upgrades, patches, enhancements, migrations, and configuration changes.
- Support proof of concepts, tool evaluations, new integrations, and capability enhancements for PAM and secrets management platforms.
- Integrate PAM and Vault solutions with enterprise applications, EKS/Kubernetes, cloud platforms, and CI/CD pipelines.
- Automate account onboarding, password rotation, access workflows, reporting, and operational tasks using scripts and APIs.
- Support privileged account management, session monitoring, least privilege controls, break-glass access, and audit requirements.
- Partner with security, infrastructure, cloud, DevOps, and application teams to improve PAM maturity and operational effectiveness.
- Troubleshoot platform issues, coordinate with vendors when required, and ensure timely resolution of incidents and service requests.
- Maintain documentation, runbooks, standard operating procedures, and knowledge articles related to PAM operations.
- Ensure PAM processes align with internal security standards, regulatory expectations, and industry best practices.
Required Skills and Experience
- Minimum 3+ years of experience in cybersecurity, identity and access management, privileged access management, or related technology roles.
- Hands-on experience with CyberArk Password Vault and CyberArk Endpoint Privilege Manager.
- Experience with BeyondTrust SRA/RA.
- Experience with HashiCorp Vault for secrets management.
- Knowledge of PAM infrastructure management, including upgrades, patching, monitoring, troubleshooting, and operational support.
- Strong understanding of privileged access, secrets management, credential rotation, least privilege principles, and access governance.
- Experience with EKS, Kubernetes, containers, and CI/CD tools.
- Development or scripting experience using Python, PowerShell, Bash, Go, or similar languages.
- Experience working with APIs for automation and platform integration.
- Strong troubleshooting, analytical, and problem-solving skills.
- Ability to work collaboratively with global teams across security, infrastructure, cloud, DevOps, and application functions.
- Good communication skills with the ability to explain technical concepts clearly.
Preferred Qualifications
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Experience in a financial services or large enterprise technology environment.
- Familiarity with cloud platforms such as AWS, Azure, or GCP.
- Understanding of IAM concepts, access controls, RBAC, MFA, and Zero Trust principles.
- Experience with DevOps tools and practices such as Jenkins, GitLab, GitHub Actions, Terraform, Helm, or ArgoCD.
- Relevant certifications in CyberArk, BeyondTrust, HashiCorp Vault, cloud security, Kubernetes, or cybersecurity are desirable.
#LI-SK1