Privileged Access Management Engineer

Bausch & Lomb
Bridgewater, New Jersey, US
Full-time

Bausch Health is a global company that develops, manufactures, and markets a differentiated product portfolio across multiple high-growth therapeutic areas including Gastroenterology, Generics, Neurology, Ortho Dermatologics, Medical Aesthetics and Dentistry.

We are delivering on our commitments as we build an innovative company dedicated to advancing global health. Each day, Bausch Health products are used by over 150 million people around the world.

Our approximately 7,000 employees are united around our mission of improving people’s lives with our health care products.

The primary function of the Privileged Access Management Engineer is to implement and support infrastructure, processes, procedures, and associated technologies relating to Privileged Access Management (PAM).

Key to this is the ongoing management and support of critical systems pertaining to credential management, remote desktop (RDP), and secure shell (SSH).

This role focuses on a multitude of PAM functions and integrations to enable access for IT systems and serves as L3 / L4 escalation support to operations teams.

  • Supports the introduction and promotion of PAM within the organization and assists with implementing new technologies to meet security goals
  • Serves as the engineering technical point of contact for the corporate PAM tool
  • Responsible for identifying and remediating misaligned permissions related to vaulted credentials, including coordinating access reviews and certifications
  • Implements and maintains integrations between the corporate PAM tool and external systems to enable remote access (RDP, SSH, etc.

and credential rotation

  • Maintains awareness of Common Vulnerabilities and Exposures (CVEs) and updates applicable to the corporate PAM tool and performs patches and upgrades as needed
  • Provides technical oversight and support to the wider IT Security team with regards to security investigations, incident response and blue team exercises
  • Collaborates with operational support teams to address recurring issues. Reviews policies, procedures, knowledge articles and other documentation as needed to ensure the effectiveness of the overall PAM program
  • Interfaces with the global audit and compliance team to align PAM security and data retention functions with corporate and third-party audit requirements
  • Responsible for delivering reports, health checks, and operational plans to deliver the incremental improvements required to maintain a strong security posture
  • Utilizes technical and environmental knowledge to support secure, risk-based practices, exercising judgment within broadly defined security practices and policies

Experience Requirements

  • Bachelor's degree in Information Systems, Computer Science or equivalent work experience required
  • At least 3 years of experience in the Information Security field
  • Experience implementing and supporting PAM technologies such as CyberArk, Delinea, or BeyondTrust in a complex global environment
  • Proficient knowledge of Windows and Linux server management and troubleshooting
  • Proficient knowledge of Remote Desktop (RDP) and Secure Shell (SSH)
  • Working knowledge of PowerShell, JSON, REST APIs and API authentication
  • Working knowledge of Active Directory and Entra ID with specific emphasis on password management and domain replication
  • Knowledge of Active Directory Organizational Units (OU), groups and user attributes
  • Basic understanding of authentication protocols such as SAML, OAuth and LDAP
  • Excellent research, analytical, and critical thinking skills. Ability to analyze information / data, identify trends, draw conclusions, and make recommendations
  • Strong verbal and written communications skills with the ability to facilitate crucial conversations and influence stakeholders
  • Effective interpersonal and group communication skills, including negotiation, ability to influence, strong presentation, motivational, change management and teaching skills
  • Familiarity with Identity and Access Management lifecycle, concepts, and technologies

Benefits package includes a Comprehensive Medical (includes Prescription Drug), Dental, Vision, Health Savings Account with company contribution, Flexible Spending Accounts, 401(k) matching, discretionary time off, paid sick time, tuition reimbursement, parental leave, short-term disability, long-term disability, life insurance, accidental death & dismemberment insurance, paid holidays, Employee Assistance Plan, commuter benefit, recognition awards, voluntary benefits (including Identity Theft, Student Loan and Breast Milk Shipping), employee referral bonuses and employee discounts.

LI-hybrid

This position may be available in the following location(s) : US - Bridgewater, NJ

Bausch Health Companies Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment regardless of race, color, religion, gender, national origin, age, sexual orientation, gender identity or expression, marital or veteran status, disability, or any other legally protected status.

We are committed to building diverse teams, representative of the patients and communities we serve, and we strive to create an inclusive workplace that cultivates collaboration.

If a candidate needs a reasonable accommodation / adjustment due to physical or mental health impairment for any part of the application process, they are encouraged to send their request to or call 908-927-1400 and let us know the nature of the request and their contact information.

Please be sure to include the job requisition number.

Job Applicants should be aware of job offer scams perpetrated through the use of the Internet and social media platforms.

To learn more please read .

30+ days ago
Related jobs
Bausch & Lomb
Bridgewater Township, New Jersey

The primary function of the Privileged Access Management Engineer is to implement and support infrastructure, processes, procedures, and associated technologies relating to Privileged Access Management (PAM). Key to this is the ongoing management and support of critical systems pertaining to credent...

Highmark Health
NJ, Working at Home, New Jersey

The Identity & Access Management Senior Security Engineer is responsible for acting as resource, leader, and peer coach with other engineers in the development, testing, implementation, and integration of Identity and Access Management systems and solutions. Identity Access Management Platforms: Sys...

CVS Health
Work from home, NJ, US
Remote

The Staff Security Engineer of IAM will be a product owner and lead engineer within Identity Access Management (IAM) space for CVS Health. Operating within DevOps and Agile frameworks as part of our Product Management Model, an ideal candidate will have strong soft skills and engineering skills. Ide...

Fox Rothschild
Morristown, New Jersey

As a member of the Information Services Department, the Identity & Access Management (IAM) Engineer will be responsible for managing Security Projects and Initiatives, implementing and maintaining Authentication and Authorization Frameworks, design and implementation of Lifecycle and Access Strategi...

Fiserv
Berkeley Heights, New Jersey

What does a successful CyberArk Engineer do at Fiserv?. This position reports to the Director of Privileged Access Engineering. Development of PAM (CyberArk) connection components and plugins as needed utilizing various scripting tools (PowerShell, python) and restAPI’s. CyberArk and all its compone...

Promoted
Uber
Millburn, New Jersey

Driving with Uber is an alternative to a part-time or full-time job and can get you earning cash on the road quickly.Driving with Uber allows you to earn quick cash while maintaining the flexibility your schedule requires (gig, part-time, full-time, seasonal, hourly, or temporary).With Uber, you can...

Promoted
Raritan Valley Community College
Branchburg, New Jersey

The PACE Student Place Navigator is a grant-funded position that develops outreach and recruitment programming to serve high school students and adult learners currently in the PACE (Pre-Apprenticeship in Career Education) Grant.Upon students' completion of the PACE program, the goal is to have the ...

Promoted
Uber
Bridgewater, New Jersey

Driving with Uber is an alternative to a part-time or full-time job and can get you earning cash on the road quickly.Driving with Uber allows you to earn quick cash while maintaining the flexibility your schedule requires (gig, part-time, full-time, seasonal, hourly, or temporary).With Uber, you can...

Promoted
Cisco Systems, Inc.
Woodbridge Township, New Jersey

The application window is extended to close on 11/06/24.The preferred location for this requisiton is New Jersey/New York Metro Area OR RTP.The Customer Success Specialist (CSS) role is a critical, strategic advisor and technical expert that engages with customers to accelerate their adoption of Cis...

Promoted
Uber
Rocky Hill, New Jersey

Driving with Uber is an alternative to a part-time or full-time job and can get you earning cash on the road quickly.Driving with Uber allows you to earn quick cash while maintaining the flexibility your schedule requires (gig, part-time, full-time, seasonal, hourly, or temporary).With Uber, you can...