ZEISS

Senior Security Engineer - Privileged Access Management (f/m/x)

ZEISS

2 LocationsFull timePosted Aug 3, 2026

Job description

Welcome to ZEISS – a company that combines innovation and responsibility! Our corporate functions are diverse and make a decisive contribution to the strategic orientation and sustainable success of ZEISS. As a Senior Security Engineer (Privileged Access Management) you will be responsible for engineering, evolution and operations of our Privileged Access Management ecosystem, specifically leveraging Beyond.

Trust Password Safe. As an engineer you will also provide escalation support and resolution for complex incidents that cannot be resolved at the L2 level to ensure reliable and compliant service delivery in collaboration with internal stakeholders and external providers. Primary Responsibilities: Implementation & Configuration: Deploy, configure and support PAM solution using Beyond.

Trust Password Safe Migration & Optimization: Support ongoing efforts to migrate legacy privileged accounts into the Beyond. Trust vault and optimize existing workflow Identity Infrastructure (AD & Entra ID): Manage the integration of Beyond. Trust with Active Directory (OU structures, GPOs, and Kerberos) and Microsoft Entra ID API & Scripting: Design and deploy Power.

Shell or Python scripts using Beyond. Trust REST APIs to automate bulk onboarding, secret rotation, and session monitoring alerts. Incident Response Support: Investigate, troubleshoot and resolve security incidents involving endpoint compromise or privilege escalation. Operational Excellence: Perform regular platform upgrades, patching, and health checks.

Technical Mentorship: Provide guidance and training to junior security analysts on Privileged Access Management best practices and incident handling.

Your profile

8+ years in Cybersecurity, with 3+ years of dedicated PAM experience in Beyond. Trust Password Safe or equivalent PAM solutions i.e. Cyber. Ark Strong proficiency in Microsoft Entra ID (Azure AD) and on-premise Active Directory architectures. Advanced knowledge of Active Directory (Kerberos, LDAP, GPO) and Microsoft Entra ID (Service Principals, Managed Identities, App Registrations).

Experience participating in at least one large-scale IAM or PAM migration (e.g., tool-to-tool or on-prem to cloud) is highly preferred Strong background in IT Service Management, product ownership, or service delivery for security‑critical service Excellent communication skills in English, with the ability to collaborate across global teams Your ZEISS Recruiting Team: Markus Repp

See all open roles at ZEISS or explore thousands more companies on TheJobsMap.