The Senior PAM Engineer will play a key role in securing Mattelβs most sensitive accounts and systems by implementing, managing, and supporting privileged access solutions. This role will focus on designing, operating, and troubleshooting PAM platforms and integrations, ensuring privileged identities are properly managed, monitored, and protected across on-premises, cloud, and hybrid environments. 
As a senior engineer, this position serves as an escalation point for complex PAM issues, privileged account lifecycle management, secrets management, and access control enforcement. The Sr. PAM Engineer will work closely with IAM Architects, IAM Engineers, and ITDR Analysts to strengthen privileged account security, ensure compliance with regulatory requirements, and contribute to operational resilience through automation, monitoring, and risk remediation. 
 
Objectives of this Role 
β’ Implement, support, and enhance PAM solutions including CyberArk, Okta OPA, BeyondTrust, Delinea, Admin By Request and Cerby for privileged account and secrets management. 
β’ Administer and monitor Windows/Linux server privilege management and endpoint privilege management (Windows/macOS). 
β’ Provide escalation support for complex PAM integrations, API connections, and secrets management issues. 
β’ Ensure privileged accounts follow lifecycle management, rotation, and access control best practices. 
β’ Support incident management, disaster recovery planning, and risk remediation specific to privileged accounts. 
β’ Collaborate with IAM Engineers and ITDR Analysts on threat detection, incident response, and privileged access misuse investigations. 
β’ Maintain compliance with SOX, PCI, and audit requirements, including User Access Reviews (UARs) and reporting. 
β’ Develop and maintain runbooks, playbooks, workflows, and technical documentation for PAM operations. 
β’ Develop, and maintain monitoring dashboards with tools such as Grafana, Splunk, and Sumo Logic for PAM metrics and alerts. 
β’ Drive automation of privileged access tasks (e.g. PowerShell, VBScript, Python, REST APIs, Ansible, or Terraform). 
β’ Mentor other engineers and promote PAM best practices across the enterprise. 
β’ Additional duties may be assigned as necessary to meet the ongoing needs of the organization. 
β’ Work hours may vary, and the position may require availability during off-business hours as dictated by project needs, system changes, or security events. 
 
Skills and Qualifications 
 
Required: 
β’ 5+ years of strong hands-on experience in Privileged Access Management or identity security tools (e.g. CyberArk, Okta OPA, BeyondTrust, Delinea, and Cerby for PAM and secrets management). 
β’ Hands-on expertise in secure password rotation, credential vaulting, and secrets management for privileged accounts across Windows/Linux servers and Windows/macOS endpoints. 
β’ Proven experience designing and enforcing least privilege access, Just-in-Time (JIT) provisioning, and role-based access control (RBAC) models within enterprise PAM solutions. 
β’ Hands-on experience with Active Directory/LDAP, Entra ID (Azure AD), and cloud PAM integrations (e.g. AWS, GCP and Azure). 
β’ Experience supporting incident response, disaster recovery, and risk remediation in PAM environments. 
β’ Knowledge of compliance requirements (SOX, PCI) and experience supporting User Access Reviews (UARs) and audit reporting. 
β’ Proficiency with monitoring and analytics platforms (e.g. Grafana, Sumo Logic, CrowdStrike ITP etc.). 
β’ Excellent communication and collaboration skills with the ability to support cross-functional security initiatives. 
β’ Experience developing operational dashboards, metrics, and compliance reporting. 
β’ Advanced Microsoft Excel, including pivot tables, formulas, and data analysis. 
β’ Certification in CyberArk or comparable PAM technologies, with demonstrated ability to design, implement, and maintain secure privileged access environments. 
β’ Participate in after-hours rotations or on-call duties to support critical incident response as needed. 
 
Preferred: 
β’ Bachelorβs degree in technology or applicable experience. 
β’ CISSP, CISMP certification, or other security certifications. 
β’ Familiarity with endpoint detection and response (EDR) integrations for PAM (e.g., CrowdStrike ITP). 
β’ Background in scripting and automation with PowerShell, Python, and REST APIs. 
β’ Strong troubleshooting skills across Windows/Linux platforms, middleware, load balancers, SSL certs, and cloud components. 
β’ Familiarity with authentication and federation protocols (SAML, OAuth, OIDC, SCIM). 
β’ Experience with automation and infrastructure tools (Ansible, Terraform, CI/CD pipelines).