Mass General Brigham relies on a wide range of professionals, including doctors, nurses, business people, tech experts, researchers, and systems analysts to advance our mission. As a not-for-profit, we support patient care, research, teaching, and community service, striving to provide exceptional care. We believe that high-performing teams drive groundbreaking medical discoveries and invite all applicants to join us and experience what it means to be part of Mass General Brigham.
Job Summary
The Sr. CyberArk/PAM Engineer is responsible for designing, implementing, and optimizing privileged access management (PAM) solutions, with a focus on CyberArk. The role involves maintaining and enhancing security controls, identifying and mitigating vulnerabilities, and ensuring the effectiveness of PAM infrastructure. The engineer will work independently on complex projects, lead technical implementations, and coordinate across teams. Additionally, they will provide documentation, mentorship, and technical guidance to junior engineers.
Qualifications
Education & Certification:
Bachelor’s or Master’s degree in Computer Science or related field preferred; relevant certifications are a plus.
Principal Duties and Responsibilities:
- Owns and leads the design, implementation, and maintenance of specific PAM components.
- Acts as a technical lead, mentoring junior engineers and reviewing team contributions to ensure quality and best practices.
- Identifies and proposes innovative security solutions and technologies.
- Troubleshoots and resolves complex technical issues, including critical incidents.
- Collaborates with internal teams, vendors, and stakeholders to enhance solution effectiveness.
- Provides expert consulting support on PAM-related concerns across the organization.
- Participates in after-hours and on-call support as needed.
- Builds knowledge of Mass General Brigham systems, security policies, and service offerings.
Knowledge, Skills and Abilities
- Privileged Access Management: Strong hands-on experience with CyberArk solutions (PAM, SIA, SCA, SWS), including privileged access auditing and event monitoring using CyberArk or SIEM tools like Splunk.
- Cloud & Identity Management: Working knowledge of cloud platforms (Azure, AWS, GCP) for secrets management, and enterprise IAM tools such as Okta and Microsoft Entra, with understanding of authentication protocols (SAML, OAuth, OIDC).
- Systems & Directory Services: Proficient with Windows and Linux environments, Microsoft Active Directory (on-prem and Azure AD), Group Policy, and LDAP-based directory services.
- Communication & Collaboration: Strong communicator with the ability to engage all levels of technical and business stakeholders using tools like Microsoft Teams, email, and in-person interaction.
- Work Ethic & Problem-Solving: Self-driven, organized team player with strong troubleshooting skills and the ability to work independently or collaboratively to resolve complex issues.
- Process Knowledge: Familiarity with IT service management frameworks like ITIL.
Additional Job Details (if applicable)
- M-F Eastern Business Hours required
- Hybrid Onsite Flexible working model required weekly includes onsite in office (1-2 days per week weekly, must be flexible for business needs)
- Remote working days require stable, secure, quiet, compliant working station
Remote Type
Work Location
Scheduled Weekly Hours
Employee Type
Work Shift
Pay Range
$92,102.40 - $134,056.00/AnnualGrade
7At Mass General Brigham, we believe in recognizing and rewarding the unique value each team member brings to our organization. Our approach to determining base pay is comprehensive, and any offer extended will take into account your skills, relevant experience if applicable, education, certifications and other essential factors. The base pay information provided offers an estimate based on the minimum job qualifications; however, it does not encompass all elements contributing to your total compensation package. In addition to competitive base pay, we offer comprehensive benefits, career advancement opportunities, differentials, premiums and bonuses as applicable and recognition programs designed to celebrate your contributions and support your professional growth. We invite you to apply, and our Talent Acquisition team will provide an overview of your potential compensation and benefits package.
EEO Statement:
At Mass General Brigham, our competency framework defines what effective leadership “looks like” by specifying which behaviors are most critical for successful performance at each job level. The framework is comprised of ten competencies (half People-Focused, half Performance-Focused) and are defined by observable and measurable skills and behaviors that contribute to workplace effectiveness and career success. These competencies are used to evaluate performance, make hiring decisions, identify development needs, mobilize employees across our system, and establish a strong talent pipeline.
Top Skills
Mass General Brigham Somerville, Massachusetts, USA Office
399 Revolution Dr, Somerville, Massachusetts, United States, 02145
Mass General Brigham Boston, Massachusetts, USA Office
800 Boylston St, Boston, Massachusetts, United States, 02199
Similar Jobs
What you need to know about the Boston Tech Scene
Key Facts About Boston Tech
- Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
- Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
- Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
- Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories