Role:Privileged Access Engineer (PAM) with AI Capabilities
Location: Montreal
Hybrid: 3 days a week in office
Role Overview
The Privileged Access Engineer (PAM) with AI Capabilities is responsible for
securing privileged access across enterprise systems by implementing advanced
PAM solutions while leveraging Artificial Intelligence (AI) and Machine
Learning (ML) to enhance threat detection, automation, and decision-making.
This role blends cybersecurity engineering with AI-driven analytics to
proactively identify risks, automate privileged access controls, and enable
adaptive security frameworks.
Key Responsibilities
1. PAM Engineering & Implementation
Design, implement, and manage PAM solutions:
CyberArk, BeyondTrust, Delinea, HashiCorp Vault
Configure:
Privileged account onboarding and lifecycle management
Password vaulting, rotation, and credential management
Privileged Session Management (PSM)
Implement Just-In-Time (JIT) and Just-Enough-Access (JEA) models
2. AI-Driven Security & Automation
Develop and integrate AI/ML models to:
Detect anomalous privileged access behavior
Identify insider threats and suspicious activity
Predict and prevent access misuse
Use AI for:
Behavioral analytics (UEBA – User & Entity Behavior Analytics)
Risk-based authentication and access decisions
Implement intelligent automation for:
Privileged account onboarding/offboarding
Access approvals and policy enforcement
3. Advanced Monitoring & Threat Detection
Leverage AI-enabled SIEM tools (e.g., Splunk, Microsoft Sentinel) for:
Real-time monitoring of privileged sessions
Automated alert prioritization
Implement:
Session recording and playback
AI-driven anomaly detection and alert tuning
Support incident response and forensic investigations
4. Integration & Data Engineering
Integrate PAM with:
IAM systems (Entra ID, Okta, SailPoint)
Security tools (SIEM, SOAR, EDR/XDR)
Cloud platforms (AWS, Azure, GCP)
Work with:
APIs, REST services, JSON
Data pipelines for feeding security analytics platforms
Build AI-ready datasets from logs and access activity
5. Governance, Risk & Compliance
Enforce:
Least privilege access
Zero Trust principles
Support compliance with:
SOX, GDPR, PCI-DSS, ISO 27001
Generate AI-assisted compliance reports and audit insights
Contribute to policy definition and governance frameworks
6. Automation & DevSecOps
Develop scripts and automation workflows using:
Python, PowerShell, Bash
Integrate PAM into:
CI/CD pipelines (DevSecOps)
Implement AI-assisted remediation workflows using SOAR tools
7. Collaboration & Innovation
Partner with:
Security operations (SOC) teams
Data science / AI teams
IAM architects and cloud engineers
Evaluate emerging AI-driven security tools
Drive innovation in Intelligent Identity Security and Autonomous Access
Management
