Senior Privileged Access Management Engineer (Cyber Security Engineer)

Job Description

Company: Moderna

Location: Cambridge, US

## Senior Privileged Access Management Engineer (Cyber Security Engineer)

Joining Moderna means advancing mRNA science to transform medicine. In this role you will play a pivotal part in advancing and maturing Moderna’s Privileged Access Management (PAM) capabilities across cloud and on‑premises environments. You will act as the technical subject matter expert for the CyberArk platform and its associated components, driving design, administration, integration, and continuous improvement while partnering closely with engineering, infrastructure, security, governance, and business stakeholders.

You will manage the configuration, administration, maintenance, and ongoing optimization of the CyberArk environment and lead onboarding of privileged accounts into CyberArk. Work includes conducting stakeholder interviews, gathering application/service/infrastructure information to support onboarding activities, performing application integration assessments, and creating detailed architecture documentation, implementation plans, technical standards, and solution designs. Participation in disaster recovery planning, capacity management, performance monitoring, maintenance activities, and platform resilience efforts is expected to ensure high availability. You may be required to support emergency incidents and planned maintenance activities, including participation in 24×7 support when necessary.

The role requires close collaboration with DevOps, systems, network, cybersecurity, and infrastructure teams to ensure privileged access management standards are consistently implemented and maintained. You will develop and maintain end‑user documentation, knowledge articles, standards, and training materials to support adoption and operational excellence. Regular review and enhancement of PAM policies, procedures, and controls to maintain compliance and operational effectiveness is part of the position, as is staying current on industry trends, threat landscapes, emerging technologies, and evolving identity security practices.

### What you must have

– BS‑level technical degree or equivalent experience required; Computer Science or Math background preferred.
– 8+ years in the technology field, with 4–6+ years working in the identity and access management domain.
– 3+ years of hands‑on experience with CyberArk and Privileged Cloud technologies, including account and safe management, CyberArk administration and configuration, and management/troubleshooting of CyberArk Privileged Cloud components.
– Hands‑on experience with DevOps and Agile methodologies, including implementation and administration of CyberArk secret management technologies such as Credential Provider, Secrets Hub, and Conjur (Cloud or Enterprise).
– Proficiency in English (verbal and written) required due to global collaboration needs.

Preferred experience and technical knowledge:

– Privileged Access Management principles and best practices, familiarity with JIT, least‑privileged, and dynamic privilege concepts.
– Strong understanding of virtualization and cloud platforms, with knowledge of AWS infrastructure and architecture (Azure or GCP familiarity a plus).
– Knowledge of both Windows and Unix platforms; PowerShell scripting a plus.
– Understanding of DevOps pipelines and CI/CD tools, RESTful APIs and service‑oriented architectures.
– Familiarity with information security frameworks and security architecture frameworks.
– Experience with GxP environments and regulatory requirements is a plus.
– Relevant certifications such as CISSP, CISM, or CISA are a plus; CyberArk certification is a plus.

### Compensation, work model, and important notices

The salary range for this role is $145,900.00 – $234,200.00. This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. An individual’s position within the salary range will be based on several factors including, but not limited to, specific competencies, relevant education, qualifications, certifications, experience, skills, performance, and business or organizational needs. The successful candidate may be eligible for an annual discretionary bonus, other incentive compensation, or equity award, subject to company plan eligibility criteria and individual performance.

Moderna champions the significant benefits of in‑office collaboration by embracing a 70/30 work model. Moderna is a smoke‑free, alcohol‑free, and drug‑free work environment. Moderna is an Equal Opportunity Employer.

This position may involve access to technology or data that is subject to U.S. export control laws, including the Export Administration Regulations (EAR). Employment is contingent upon the applicant’s ability to access export‑controlled information in accordance with U.S. law. Due to the nature of the work and regulatory requirements, only individuals who qualify as U.S. persons (citizens, permanent residents, asylees, or refugees) are eligible for this position. Moderna is unable to sponsor non‑U.S. persons to apply for an export control license.

### Benefits and culture

Moderna offers competitive healthcare and voluntary benefit programs, holistic well‑being resources (fitness, mindfulness, mental health support), family planning benefits including fertility, adoption, and surrogacy support, generous paid time off (vacation, volunteer days, sabbatical, global recharge days, and a discretionary year‑end shutdown), and savings and investment programs. The company emphasizes continuous learning, digital innovation, and a culture of collaboration and impact.

Source: Bandana.com