PAM Engineering Manager - Vice President
State Street · State of Telangāna, India
State Street · State of Telangāna, India
**Role Summary** We are seeking a highly skilled and motivated **Privileged Access Management (PAM) Engineering Manager – Vice President** to join the Global Cybersecurity organization. This is a hands-on technical leadership role for someone who thrives in complex, highly regulated environments and is passionate about privileged access security, CyberArk, HashiCorp Vault, PIM, AKV, AWS, automation, platform modernization, and operational resilience. The role will drive engineering ownership for strategic PAM capabilities across the enterprise, including CyberArk, HashiCorp Vault, privileged account onboarding, secrets management, automation, access modernization, platform reliability, and integration with enterprise IAM, security, and cloud ecosystems. - **Role Title:** PAM Engineering Manager – Vice President - **Capability:** Privileged Access Management / Infrastructure Access Management - **Function:** Global Cybersecurity - **Primary Focus:** CyberArk, HashiCorp Vault, PIM, AKV, AWS, PAM engineering, platform modernization, automation, and risk reduction - **Location:** Bangalore or Hyderabad **Key Responsibilities** **PAM Engineering Leadership** - Lead the engineering lifecycle for enterprise PAM platforms, including CyberArk, HashiCorp Vault, CA-PAM migration support, PIM, AKV, AWS, and related privileged access capabilities. - Drive platform architecture, design, implementation, integration, and continuous improvement for privileged access services. - Own engineering delivery for strategic PAM initiatives such as CyberArk platform uplift, HashiCorp adoption, secrets management expansion, CPM/PSM capability development, access modernization, and migration from legacy PAM platforms. - Partner with product, operations, governance, application, infrastructure, and cloud teams to ensure PAM engineering outcomes align with business priorities, risk requirements, and enterprise security standards. - Lead engineering design and implementation across CyberArk components including Vault, PVWA, CPM, PSM, PSMP, DR, connectors, integrations, monitoring, and platform automation. - Drive HashiCorp Vault engineering for secrets management use cases including cloud workload identities, Azure service principals, AWS workloads, static secrets, database secrets, certificate/PKI use cases, and application credential modernization. - Ensure PAM platforms are engineered for scalability, resilience, auditability, and secure operations. - Support design patterns for privileged account onboarding across Windows, Unix/Linux, databases, network devices, cloud platforms, service accounts, application accounts, and non-human identities. - Identify and deliver automation opportunities to reduce manual effort, ticket volume, operational risk, and configuration errors. - Drive API, scripting, CI/CD, Terraform, PowerShell, REST API, and workflow-based automation for PAM and secrets management use cases. - Establish reusable engineering patterns, onboarding templates, reference architectures, and technical accelerators. - Promote engineering practices such as test automation, code review, tech debt reduction, platform refactoring, and continuous improvement. - Ensure PAM engineering solutions support least privilege, zero trust, credential vaulting, session monitoring, access control, audit logging, and regulatory expectations. - Partner with governance and audit teams to close control gaps, support evidence generation, remediate findings, and improve control traceability. - Drive remediation of platform-related vulnerabilities, configuration gaps, audit issues, and resiliency risks. - Ensure PAM controls integrate with IAM, SIEM, ServiceNow, SailPoint, monitoring, change management, and incident response processes. - Collaborate with global technology, cybersecurity, infrastructure, application, cloud, risk, audit, and business stakeholders. - Translate business and regulatory requirements into scalable PAM engineering solutions. - Provide senior technical leadership during major incidents, platform escalations, design reviews, audit discussions, and program governance forums. - Work across time zones and global teams to support enterprise delivery. - Lead, mentor, and develop a high-performing PAM engineering team. - Provide technical guidance to engineers and support teams across L2/L3/L4 responsibilities. - Build engineering capability across CyberArk, HashiCorp Vault, cloud PAM, automation, secrets management, and non-human identity security. - Foster a culture of accountability, engineering discipline, innovation, documentation, and operational excellence. - Create and maintain architecture diagrams, engineering standards, SOPs, runbooks, implementation patterns, knowledge articles, and support handover documents. - Ensure documentation is audit-ready, operationally usable, and aligned to enterprise standards. - Establish clear ownership models, RACI alignment, support handoffs, escalation paths, and post-implementation validation practices. **Your Team** You will be part of the **Global Cybersecurity Privileged Access Management / Infrastructure Access Management team**, responsible for engineering and modernizing enterprise privileged access, secrets management and non-human identity/account capabilities. The team supports business-critical access platforms that enable secure infrastructure access, privileged credential management, session control, secrets management, and privileged access governance across the enterprise. This role will work closely with PAM Operations, PAM Governance, Cloud Security, Infrastructure, Application Technology, Risk, Audit, and Product teams to deliver secure, scalable, and resilient privileged access services. **Required Experience** - 16+ years of technology experience, with significant experience in cybersecurity, IAM, PAM, infrastructure security, or platform engineering. - Strong hands-on experience with one or more leading PAM platforms such as **Cybe