
Leading company in the software industry
PAM and Secrets Management Engineer
Who We Are
Applied Materials is a global leader in materials engineering solutions used to produce virtually every new chip and advanced display in the world. We design, build and service cutting-edge equipment that helps our customers manufacture display and semiconductor chips – the brains of devices we use every day. As the foundation of the global electronics industry, Applied enables the exciting technologies that literally connect our world – like AI and IoT. If you want to push the boundaries of materials science and engineering to create next generation technology, join us to deliver material innovation that changes the world.
What We Offer
Location:
Bangalore,IND
You’ll benefit from a supportive work culture that encourages you to learn, develop, and grow your career as you take on challenges and drive innovative solutions for our customers. We empower our team to push the boundaries of what is possible—while learning every day in a supportive leading global company. Visit our Careers website to learn more.
At Applied Materials, we care about the health and wellbeing of our employees. We’re committed to providing programs and support that encourage personal and professional growth and care for you at work, at home, or wherever you may go. Learn more about our benefits.
About the Role
Join Applied Materials as a PAM & Secrets Management Engineer to lead privileged access management and secrets management initiatives across our global enterprise infrastructure. You'll architect and operate enterprise-scale PAM solutions (Cyber Ark) and Hashi Corp Vault, working at the intersection of security, DevOps, and cloud platforms to protect critical systems and enable secure development.
Key Responsibilities Privileged Access Management (PAM)
- Design, implement, and manage enterprise PAM solutions at scale (500+ concurrent sessions, 2K+ daily logins, 2.5K+ targets)
- Operate and maintain Cyber Ark self-hosted environment lead evaluation of alternatives (Delinea, Beyond Trust, Cyber Ark Privilege Cloud)
- Architect privileged session management (PSM) for RDP, SSH with native client support and passwordless credential injection
- Implement automated account discovery and onboarding workflows (Windows local, AD, Linux/Unix accounts)
- Configure session recording, monitoring, and alerting for compliance and security
- Troubleshoot and resolve PAM infrastructure stability issues (eliminating outages)
Secrets Management
- Architect and operate Hashi Corp Vault Enterprise at scale across multi-cloud environments
- Implement Vault secrets engines: KV v2, Dynamic Secrets (LDAP, Azure, databases), PKI, Transit Encryption
- Design and deploy Vault authentication methods: OIDC/JWT, Kubernetes, App Role, AWS IAM, Azure AD
- Configure Vault policies and namespaces for multi-tenant secret isolation
- Integrate Vault with CI/CD pipelines (Jenkins, GitLab, GitHub Actions, Azure DevOps) for secure secret injection
- Implement Vault Agent and sidecar injectors for application secret delivery
- Configure Vault auto-unseal with cloud KMS (AWS KMS, Azure Key Vault, GCP Cloud KMS)
- Manage Vault high availability, disaster recovery, and performance tuning
- Implement secret rotation automation for databases, cloud credentials, and API keys
Cross-Functional Collaboration
- Partner with CI/CD, Network, Cloud, and Platform teams to integrate PAM/SM controls
- Lead incident response for privileged access breaches and secrets exposure events
- Conduct security assessments and ensure compliance with SOX, PCI-DSS, ISO 27001
- Automate PAM and Secret Management workflows using Python, Bash, PowerShell, Terraform, Ansible
Required Qualifications Privileged Access Management (PAM) Expertise:
- 5+ years hands-on experience with enterprise PAM solutions at scale (10,000+ employees or global infrastructure)
- Deep experience with privileged session management: RDP, SSH session recording, monitoring, and credential injection
- Strong understanding of account lifecycle management: discovery, onboarding, rotation for Windows local, AD, Linux/Unix accounts
- Experience with PAM platforms: Cyber Ark (PAS, PVWA, CPM, PSM) or equivalent (Beyond Trust, Delinea, Arcon)
- Knowledge of least privilege principles and privilege elevation workflows
- Experience integrating PAM with approval workflows (Service Now, ITSM tools)
- Understanding of session isolation, credential vaulting, and password/SSH key rotation
- Familiarity with PAM architecture: high availability, disaster recovery, horizontal scaling
Secrets Management Expertise:
- 3+ years hands-on experience with Hashi Corp Vault in production environments
- Deep knowledge of Vault secrets engines: KV (v1/v2), Dynamic Secrets (databases, AWS, Azure), PKI, Transit, SSH, TOTP
- Experience with Vault authentication methods: Kubernetes, App Role, OIDC/JWT, AWS IAM, Azure AD, LDAP, TLS Certificates
- Strong understanding of Vault policies, namespaces, and entity/identity management
- Experience with Vault Agent, sidecar injectors, and application integration patterns
- Knowledge of Vault operations: auto-unseal (HSM), replication (DR/Performance), backup/restore, upgrades
- Experience integrating Vault with CI/CD pipelines for dynamic secret injection
- Understanding of secret zero problem and secure secret bootstrap mechanisms
Technical & Cloud Skills:
- Multi-cloud secrets management: AWS Secrets Manager/IAM, Azure Key Vault/Managed Identity, GCP Secret Manager
- Experience with Kubernetes: Vault sidecar injection, CSI secret driver, external secrets operator
- Proficiency in scripting and automation: Python, Bash, PowerShell, Go (preferred)
- Experience with Infrastructure-as-Code: Terraform, Ansible (Vault configuration automation)
- Understanding of PKI fundamentals: certificate lifecycle, CA hierarchies, mTLS, certificate-based authentication
- Experience with Directory services: Active Directory, LDAP (for PAM/Vault integration)
Collaboration & Communication Skills:
- Proven track record working with DevOps, Platform Engineering, Cloud, and Network teams
- Strong communication skills with technical and non-technical stakeholders
- Ability to lead cross-functional PAM/SM initiatives and provide technical mentorship
- Experience in incident response for privileged access and secret exposure events
Preferred Qualifications (Advantages)
- Cyber Ark Certified: Cyber Ark Defender, Sentry, or Trustee certifications
- Hands-on experience in Delinea Secret Server, Beyond Trust, Arcon, Cyber Ark Privilege Cloud
- Experience with account discovery automation and policy-based onboarding at scale
- Hashi Corp Certified: Vault Associate or Vault Professional certification
- Deep knowledge of Vault database secrets engine: PostgreSQL, MySQL, MongoDB, MSSQL, Oracle dynamic credentials
- Hands-on with Vault Transit engine: encryption-as-a-service, key derivation, convergent encryption
- Experience with Vault SSH secrets engine: signed SSH certificates, OTP SSH, CA-based SSH access
- Experience with Vault KMIP secrets engine for legacy application encryption key management
- Experience with Vault monitoring: metrics (Prometheus), logging, audit logs, performance tuning
Certifications & Education:
- Bachelor's degree in Computer Science, Information Security, or related field
- Professional certifications: Cyber Ark CDE/Sentry, Hashi Corp Vault Associate/Professional, CISSP, CISM, CISA, CEH
- Cloud certifications: AWS Security Specialty, Azure Security Engineer, GCP Security Engineer
Compliance & Architecture:
- Deep knowledge of compliance frameworks: SOX, PCI-DSS, NIST CSF, ISO 27001, GDPR, HIPAA
- Experience with zero-trust architecture and secrets management in zero-trust models
- Understanding of threat modeling for privileged access and secret exposure risks
Additional Information Time Type:
Full time
Employee Type:
Assignee / Regular
Travel:
Yes, 10% of the Time
Relocation Eligible:
Yes
Applied Materials is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, national origin, citizenship, ancestry, religion, creed, sex, sexual orientation, gender identity, age, disability, veteran or military status, or any other basis prohibited by law.
閲覧数
0
応募クリック
0
Mock Apply
0
スクラップ
0
類似の求人

Platform Engineer
Cargill · Bangalore, Karnataka, India

Administrator - Jenkins,Windows PowerShell
HCL Technologies · Bangalore, India

Administrator - Jenkins,Windows PowerShell
HCL Technologies · Bangalore, India

Active Directory Engineer
Dell · Bangalore, India
DevOps Platform Engineer
NetApp · Bangalore, Karnataka, IN
Applied Materialsについて

Applied Materials
PublicApplied Materials, Inc. is an American corporation that supplies equipment, services and software for the manufacture of semiconductor chips for electronics, flat panel displays for computers, smartphones, televisions, and solar products.
10,001+
従業員数
Santa Clara
本社所在地
$57B
企業価値
レビュー
10件のレビュー
3.8
10件のレビュー
ワークライフバランス
3.2
報酬
3.5
企業文化
3.8
キャリア
3.3
経営陣
3.9
72%
知人への推奨率
良い点
Supportive and approachable management
Good benefits and training programs
Cutting-edge technology and interesting projects
改善点
Heavy workload and frequent overtime
Fast-paced and stressful environment
Limited growth opportunities
給与レンジ
53件のデータ
L2
L6
L3
L4
L5
L2 · Cybersecurity Analyst L2
0件のレポート
$76,440
年収総額
基本給
$30,576
ストック
$38,220
ボーナス
$7,644
$53,508
$99,372
面接レビュー
レビュー4件
難易度
3.0
/ 5
期間
14-28週間
面接プロセス
1
Application Review
2
Recruiter Screen
3
Technical/Hiring Manager Interview
4
Final Round Interview
5
Offer
よくある質問
Technical Knowledge
Behavioral/STAR
Past Experience
Problem Solving
Culture Fit
最新情報
China Exposure Hits Lam Research, Applied Materials, KLA Stocks - Electronics For You BUSINESS
Electronics For You BUSINESS
News
·
1w ago
Applied Materials Stock Falls as U.S. Curbs Put China Chip-Tool Sales Back in Focus - TechStock²
TechStock²
News
·
1w ago
Exclusive: US orders chip equipment companies to halt some shipments to China's No. 2 chipmaker Hua Hong - Reuters
Reuters
News
·
1w ago
Zacks Industry Outlook Highlights Broadcom, Applied Materials and Credo Technology - Yahoo Finance
Yahoo Finance
News
·
1w ago