Identity Engineer - Privilege Access at Ralliant. Location Information: . Role description. The Identity Engineer is responsible for administering, securing, and supporting the enterprise's privileged access management (PAM) and non-human identity (NHI) environment, with a primary focus on CyberArk Privileged Cloud and the lifecycle governance of service accounts, API keys, certificates, and machine/workload identities. This role ensures secure, reliable, and well-governed access to critical systems through platform administration, proactive troubleshooting, and strong operational security practices.. This role acts as both a platform administrator and a technical troubleshooter, resolving complex privileged access, authentication, and non-human identity issues across on-premises, cloud, and hybrid environments. The engineer partners closely with Security, Infrastructure, and Application teams to onboard privileged and machine identities, enforce least-privilege and credential hygiene, and respond quickly to incidents affecting privileged or non-human access.. The role is . hands‑on and execution‑focused. while embracing the Ralliant Business System (RBS) by embedding operational discipline, staff training, and continuous improvement into tools, workflows, and standard work so endpoint management is scalable, measurable, and repeatable. The role operates in service to the enterprise and operating companies, ensuring standardized Identity practices while adapting to regional and business-specific needs. . Key responsibilities. Administer and support the . CyberArk Privileged Cloud platform. , including user and group management, safe management, vault configuration, and PSM/CPM operations.. Configure and enforce . password, access, and workflow policies. to manage privileged account onboarding, rotation, and least-privilege access.. Own . non-human identity (NHI) management. end to end, including service accounts, API keys, secrets, certificates, and machine/workload identities.. Implement . NHI lifecycle governance. , including discovery, ownership assignment, credential rotation, expiration tracking, and decommissioning of unused or orphaned identities.. Administer . secrets management and vaulting. for applications, automation, and CI/CD pipelines, reducing hard-coded credentials and standing privileged access.. Resolve . PSM and CPM issues. , including remote access connectivity (RDP, SSH, web-based access) and privileged account management failures.. Troubleshoot . complex network and connectivity issues. , including firewall rules, NAT, DNS resolution, and certificate chain validation as they relate to privileged and non-human access.. Support . authentication and authorization. troubleshooting across Active Directory/LDAP, SAML, OAuth 2.0, multi-factor authentication (MFA), and Single Sign-On (SSO) integrations for privileged and service accounts.. Develop . PowerShell and Python/REST API. scripts to automate PAM and NHI onboarding, credential rotation, discovery, and reporting using CyberArk SDKs and vendor APIs.. Monitor and analyze . CyberArk, system, and network logs. , supporting SIEM integration, anomalous privileged/non-human activity detection, and incident response.. Apply . privileged access and non-human identity security best practices. , supporting compliance with frameworks such as SOX, PCI-DSS, NIST, and ISO 27001.. Partner with . Security, Infrastructure, and Application teams. to integrate PAM and NHI solutions across enterprise and OpCo environments.. Document . procedures, configurations, and incident reports. , and train application owners and DevOps teams on secure credential and machine-identity practices.. Build reports and Power BI dashboards. to track PAM and NHI health metrics, including credential rotation status, orphaned/unmanaged accounts, safe and vault utilization, and audit/compliance posture for leadership and stakeholder visibility.. Qualifications. Bachelor's degree recommended; equivalent experience considered.. 10+ years of experience in cybersecurity, systems administration, or identity and access management, with 5. + years hands-on experience with CyberArk Privileged Cloud. .. Strong understanding of . Privileged Access Security architecture. , including Vault, PSM, CPM, and Cloud Entitlements Manager.. Demonstrated experience managing . non-human identities. , including service accounts, API keys, secrets managers, and machine/workload identities at scale.. Familiarity with . secrets management tooling and practices. (e.g., CyberArk Conjur/Secrets Hub, HashiCorp Vault, or equivalent) and CI/CD credential hygiene.. Proficiency in . TCP/IP networking, firewalls, and DNS/certificate troubleshooting. across on-premises and cloud environments (AWS, Azure, GCP).. Experience with . Active Directory/LDAP, Entra ID, SAML, OAuth 2.0, MFA, and SSO. authentication and authorization troubleshooting.. Scripting experience in . PowerShell and Python. , with working knowledge of REST APIs and CyberArk SDKs.. Experience with . log analysis and SIEM integration. , incident response, and root cause analysis, with an emphasis on privileged and non-human activity monitoring.. Knowledge of . compliance frameworks (SOX, PCI-DSS, NIST, ISO 27001). and zero trust security principles.. CyberArk Trustee or higher certification preferred; . cloud platform or security certifications. (AWS, Azure, GCP, CISSP, CISM, Security+) a plus.. Strong communication and documentation skills, with the ability to explain technical concepts to non-technical stakeholders and train application owners and DevOps teams.. Ability to operate effectively across enterprise and OpCo environments, balancing global consistency with local context across multiple time zones and cultures.. Alignment with Ralliant values and the Ralliant Business System (RBS), including continuous improvement, transparency, and ownership.. #LI-MG1. Ralliant Corporation Overview. Ralliant, originally part of Fortive, now stands as a bold, independent public company driving innovation at the forefront of precision technology. With a global footprint and a legacy of excellence, we empower engineers to bring next-generation breakthroughs to life — faster, smarter, and more reliably. Our high-performance instruments, sensors, and subsystems fuel mission-critical advancements across industries, enabling real-world impact where it matters most. At Ralliant we’re building the future, together with those driven to push boundaries, solve complex problems, and leave a lasting mark on the world. . We Are an Equal Opportunity Employer. Ralliant Corporation and all Ralliant Companies are proud to be equal opportunity employers. We value and encourage diversity and solicit applications from all qualified applicants without regard to race, color, national origin, religion, sex, age, marital status, disability, veteran status, sexual orientation, gender identity or expression, or other characteristics protected by law. Ralliant and all Ralliant Companies are also committed to providing reasonable accommodations for applicants with disabilities. Individuals who need a reasonable accommodation because of a disability for any part of the employment application process, please contact us at [email protected]. . Bonus or Equity. This position is also eligible for bonus as part of the total compensation package.
Identity Engineer - Privilege Access at Ralliant