Privileged Access Management Engineer

Keyloop

Hyderabad, INonsitePosted Jul 27, 2026
Posting intelligenceActively listed

Skills

sentryazureaws

About the role

Keyloop bridges the gap between dealers, manufacturers, technology suppliers and car buyers.

We empower car dealers and manufacturers to fully embrace digital transformation. How? By creating innovative technology that makes selling cars better for our customers, and buying and owning cars better for theirs.

We use cutting-edge technology to link our clients’ systems, departments and sites. We provide an open technology platform that’s shaping the industry for the future. We use data to help clients become more efficient, increase profitability and give more customers an amazing experience. Want to be part of it?

Role Summary

The Privileged Access Management Engineer is responsible for the engineering, configuration, integration, and operational enhancement of Keyloop’s Privileged Access Management capability, with a strong focus on BeyondTrust Password Safe. This role will support the design and implementation of PAM controls across infrastructure, databases, cloud platforms, developer environments, privileged accounts, service accounts, secrets, and non-human identities. The engineer will work closely with Security Engineering, IAM, Infrastructure, Cloud Operations, IT, and platform owners to onboard privileged accounts, enforce least privilege, automate lifecycle controls, improve monitoring and audit evidence, and embed PAM as a sustainable business-as-usual security control.

Key Responsibilities

PAM Engineering & BeyondTrust Platform Management

Engineer, configure, maintain, and optimise BeyondTrust Password Safe and associated PAM components.

Support the technical design and implementation of PAM controls across Windows, Linux, databases, cloud platforms, network devices, developer platforms, and privileged applications.

Configure managed systems, managed accounts, access policies, credential rotation, password checkout restrictions, session recording, and approval workflows.

Develop and maintain PAM platform standards, configuration baselines, runbooks, and operational procedures.

Privileged Account Discovery, Onboarding & Lifecycle Management

Lead technical onboarding of privileged accounts into BeyondTrust, including domain administrators, local administrators, sudo accounts, database administrators, cloud administrators, application administrators, and service accounts.

Support discovery of unmanaged, shared, orphaned, duplicate, stale, and over-privileged accounts across the estate.

Work with platform owners to define account ownership, access requirements, rotation rules, session controls, and recertification processes.

Implement lifecycle controls for privileged users, shared accounts, break-glass accounts, service accounts, secrets, keys, and non-human identities.

Integration, Automation & Engineering Improvement

Integrate PAM with Active Directory, Microsoft Entra ID, cloud IAM, infrastructure platforms, service management workflows, logging platforms, and monitoring tools.

Develop automation to support account discovery, onboarding, rotation validation, reporting, access reviews, and control assurance.

Use scripting and APIs to improve PAM operational efficiency, reduce manual effort, and strengthen repeatable engineering processes.

Support secure integration patterns for DevOps pipelines, automation accounts, secrets management, and non-human identities.

Least Privilege, JIT Access & Control Enforcement

Support the removal of standing privileged access and implementation of just-in-time access models.

Configure risk-based approval workflows, time-bound access, session monitoring, and stronger controls for production and critical systems.

Work with IAM, Infrastructure, Cloud Operations, and application teams to ensure privileged access is brokered through PAM wherever technically feasible.

Help define and implement controls that prevent direct privileged login outside approved PAM workflows.

Monitoring, Reporting & Audit Evidence

Produce PAM reporting on privileged account coverage, rotation status, session activity, onboarding progress, exceptions, break-glass use, and access review outcomes.

Support audit, compliance, and customer assurance activities by providing accurate evidence of PAM controls and privileged activity.

Review PAM alerts, session logs, access patterns, and control exceptions to identify issues requiring remediation.

Track PAM risks, operational issues, and improvement actions through to closure.

Stakeholder Engagement & Continuous Improvement

Partner with technical teams to embed PAM requirements into new platforms, applications, cloud services, and operational processes.

Provide technical guidance to administrators and platform owners on PAM onboarding, privileged account handling, secrets management, and secure access patterns.

Contribute to the maturity of Keyloop’s PAM operating model, including processes, governance, ownership, reporting, and support handover.

Stay current with PAM, IAM, cloud security, privileged threat, and BeyondTrust platform developments.

Required Experience & Qualifications

4–7 years of experience in Privileged Access Management, Identity and Access Management, security engineering, infrastructure security, or a related technical security role.

Hands-on engineering experience with BeyondTrust Password Safe, including configuration, onboarding, credential rotation, access policies, session recording, reporting, and operational support.

Experience integrating PAM with Active Directory, Microsoft Entra ID, Windows, Linux, databases, cloud platforms, service accounts, and privileged applications.

Strong understanding of privileged access risks, least privilege, just-in-time access, break-glass processes, secrets management, and privileged session monitoring.

Experience with scripting, automation, APIs, or configuration tooling to support repeatable PAM operations and engineering improvements.

Experience supporting audits, evidence collection, access reviews, control testing, and remediation tracking.

Skills & Competencies

Technical Skills

BeyondTrust Password Safe engineering, configuration, and administration

PAM account discovery, onboarding, credential vaulting, and rotation

Privileged session management, recording, monitoring, and audit reporting

IAM, Active Directory, Microsoft Entra ID, Windows, Linux, database, cloud, and service account integration

Secrets management, non-human identity controls, and DevOps integration patterns

Scripting, API usage, automation, reporting, and operational runbook development

Soft Skills

Strong analytical and problem-solving abilities

Ability to work across technical teams and translate security requirements into practical engineering outcomes

Clear written and verbal communication with both technical and non-technical stakeholders

Detail-oriented approach to documentation, configuration, evidence, and operational control

Proactive, delivery-focused, and adaptable in a dynamic environment

Education & Certifications (Preferred)

Bachelor’s degree in Information Security, Computer Science, IT, Engineering, or a related field.

Relevant certifications such as BeyondTrust product certification, CyberArk Defender/Sentry, Microsoft security certifications, CISSP, CISM, CompTIA Security+, or equivalent practical experience.

Cloud security or IAM certifications across Microsoft Azure, AWS, or Google Cloud are advantageous.

Values & Business Alignment

Demonstrates alignment with Keyloop’s values and ethical standards. Understands Keyloop’s business objectives, security priorities, and operational context. Ensures PAM engineering activities support reduced privileged access risk, improved auditability, stronger operational resilience, and secure delivery of services.

Why join us?

We’re on a journey to become market leaders in our space – and with that comes some incredible opportunities. Collaborate and learn from industry experts from all over the globe. Work with game-changing products and services. Get the training and support you need to try new things, adapt to quick changes and explore different paths. Join Keyloop and progress your career, your way.

An inclusive environment to thrive

We’re committed to fostering an inclusive work environment. One that respects all dimensions of diversity. We promote an inclusive culture within our business, and we celebrate different employees and lifestyles – not just on key days, but every day.

Be rewarded for your efforts

We believe people should be paid based on their performance so our pay and benefits reflect this and are designed to attract the very best talent. We encourage everyone in our organisation to explore opportunities which enable them to grow their career through investment in their development but equally by working in a culture which fosters support and unbridled collaboration.

Keyloop doesn’t require academic qualifications for this position. We select based on experience and potential, not credentials.

"At Keyloop, AI is a daily ally: We encourage and train every employee to use our AI tools to boost their creativity and productivity."

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Questions about this role

Click "Apply with AI Applyd" above. We auto-fill the application from your resume and answer screening questions in seconds. No copy and paste, no juggling tabs.

Compensation for Software Engineer roles in India varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Software Engineer hub for India medians across recent openings.

Most applications complete in under 90 seconds. You can track the status in your dashboard and watch the screenshot proof land the moment the application submits.

AI Applyd supports Greenhouse, Lever, Ashby, Workday, iCIMS, SmartRecruiters, Personio, Teamtailor and other major ATS platforms. If we can submit through the platform, we do.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.