About The Position

At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all of our employees feel respected, valued and have an opportunity to contribute to the company’s success. As a Privileged Access Management (PAM) Engineer within PNC's Tempus Technologies organization, you may be based in a remote location. Tempus Technologies, Inc. is the expert leader of secure payments at the point of interaction. For more than 25 years, innovation and producing high quality custom-ready solutions is at the forefront of everything we do. We’re committed to developing exceptional point-of-sale payment integration technology and software solutions to meet the growing needs of our customers’ business requirements. Our knowledgeable and friendly employees are passionately dedicated to delivering world-class support to every client. We thrive in a transparent culture that understands the value of shared ideas, teamwork, and excellence in everything we do. The Privileged Access Management (PAM) Engineer is responsible for the hands‑on engineering, integration, and operation of privileged access and secrets management platforms, with a primary focus on CyberArk Privileged Access Management and HashiCorp Vault. This role serves as a technical subject matter expert for privileged access controls, ensuring administrative, service, and application credentials are securely managed, rotated, and audited. The PAM Engineer partners closely with Infrastructure, Cloud, Application Engineering, DevOps, Security Operations, and Compliance teams to enforce least privilege, reduce credential‑based risk, and support secure business operations. The ideal candidate brings strong technical depth in CyberArk and Vault, a deep understanding of privileged access risk, and the ability to integrate PAM capabilities across hybrid infrastructure, cloud platforms, and modern application environments.

Requirements

  • Hands‑on experience with HashiCorp Vault for secrets management.
  • Strong understanding of privileged access risks, least privilege, and credential management.
  • Experience integrating PAM solutions across servers, databases, applications, and cloud platforms.
  • Familiarity with Linux and Windows administration, scripting, and automation.
  • Experience operating in regulated or audited environments (PCI DSS, SOC 2, SOX, HIPAA, etc.).
  • Strong troubleshooting, analytical, and problem‑solving skills.
  • Ability to communicate effectively with both technical and non‑technical stakeholders.
  • University / college degree, with 5+ years of industry-relevant experience. Specific certifications are often required. In lieu of a degree, a comparable combination of education, job specific certification(s), and experience (including military service) may be considered.
  • Analytical Thinking
  • Effective Communications
  • Information Security Management
  • Information Security Technologies
  • IT Environment
  • IT Standards, Procedures & Policies
  • IT Systems Management
  • Network and Internet Security
  • Problem Solving
  • Technical Troubleshooting

Nice To Haves

  • This position may be eligible for remote work in select geographic locations, subject to approval by PNC. If approved, work must be conducted from a quiet, secure, and confidential home-based workspace. Occasional in-office participation may be required based on business needs.

Responsibilities

  • Operate and support day to day Privileged Access Management services, ensuring secure and reliable privileged access.
  • Manage onboarding, modification, and decommissioning of privileged accounts.
  • Troubleshoot and resolve PAM related incidents, access issues, and platform errors.
  • Ensure PAM services meet availability, performance, and operational support expectations.
  • Serve as the primary technical engineer and platform owner for CyberArk PAM.
  • Onboard privileged accounts, systems, and platforms into CyberArk.
  • Configure credential vaulting, rotation policies, access workflows, and session recording.
  • Implement approval workflows and controls for administrative and emergency access.
  • Partner with infrastructure and application teams to integrate servers, databases, and platforms into PAM.
  • Monitor and maintain CyberArk components, connectors, and job health.
  • Engineer and operate enterprise secrets management using HashiCorp Vault.
  • Implement secure storage, access control, and rotation of application and infrastructure secrets.
  • Integrate Vault with CI/CD pipelines, cloud services, and runtime environments.
  • Support dynamic secrets, short lived credentials, and non-human identity use cases.
  • Partner with development teams to adopt secure secrets management patterns.
  • Integrate PAM solutions with on prem, hybrid, and cloud environments.
  • Support API based integrations and automation for privileged access and secrets usage.
  • Collaborate with DevOps and platform teams to reduce hard coded credentials and manual processes.
  • Improve onboarding speed and consistency through automation and standardization.
  • Monitor PAM health, usage, and access activity.
  • Analyze trends and issues to improve reliability and reduce operational risk.
  • Maintain PAM technical documentation, standards, and operational runbooks.
  • Identify and implement improvements to strengthen privileged access controls and scalability.
  • Support audit and compliance activities related to privileged access and secrets management.
  • Produce reports and evidence for access usage, approvals, and session activity.
  • Assist with remediation of policy violations or audit findings.
  • Ensure privileged access controls align with least privilege and regulatory requirements.
  • Provides subject matter expertise when applying security concepts.
  • Leverages technical knowledge and industry experience to design, build, and maintain technology solutions.
  • Responsible for deliverables related to project timelines.
  • Responsible for working with architecture to take high level architectural designs and determine the specifics around implementation details (ex: sizing) integration details, onboarding and operationalization.
  • Evaluates patches, updates, and ongoing maintenance.
  • Determines impacts to existing solutions when new standards are implemented.
  • Utilizes change control and other governance processes to ensure alignment of solutions .
  • Develops detailed implementation, configuration, design, and engineering documentation.
  • Build and implement solutions.
  • Works with operational partners to enable transition and day-to-day supportability.
  • Provides engineering support to existing technology in a production environment and collaborating with other groups as required.
  • Seeks opportunities to grow a broad knowledge base to complement specific subject matter expertise.

Benefits

  • medical/prescription drug coverage (with a Health Savings Account feature)
  • dental and vision options
  • employee and spouse/child life insurance
  • short and long-term disability protection
  • 401(k) with PNC match
  • pension and stock purchase plans
  • dependent care reimbursement account
  • back-up child/elder care
  • adoption, surrogacy, and doula reimbursement
  • educational assistance, including select programs fully paid
  • a robust wellness program with financial incentives
  • maternity and/or parental leave
  • up to 11 paid holidays each year
  • 9 occasional absence days each year, unless otherwise required by law
  • between 15 to 25 vacation days each year, depending on career level; and years of service.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service