Early Warning Logo

Early Warning

Systems Engineer II - PAM

Reposted 13 Days Ago
Be an Early Applicant
In-Office
Chicago, IL, USA
99K-121K Annually
Mid level
In-Office
Chicago, IL, USA
99K-121K Annually
Mid level
The Systems Engineer II engineers and supports privileged access management, oversees identity controls, and manages service account lifecycles and certificate management across platforms.
The summary above was generated by AI

At Early Warning, we’ve powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle®, Paze℠, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.

Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.

Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.

Overall Purpose 

This role engineers and supports privileged and non-human identity controls across enterprise and cloud platforms. The Engineer II is responsible for implementing and maintaining service account lifecycle controls, secrets management automation, certificate lifecycle management, and privileged session governance. 

Essential Functions 

  • Engineer, implement, and support Privileged Access Management (PAM) solutions including vaulting, session control, and Just-In-Time (JIT) privileged access. 

  • Administer and maintain secrets management platforms including credential onboarding, vault configuration, and automated password/secret rotation. 

  • Support lifecycle management of non-human identities (service and workload accounts) including provisioning, governance, ownership validation, and deprovisioning. 

  • Support enterprise certificate lifecycle management including issuance, renewal, revocation, and automation via approved platforms. 

  • Participate in the design, testing, and implementation of automation workflows related to privileged identity and certificate management. 

  • Provide operational support including system configuration, troubleshooting, incident response, and participation in 24x7 on-call rotation. 

  • Produce reporting and analytics related to privileged access, secrets rotation posture, certificate health, and non-human identity governance. 

  • Maintain technical documentation, policies, configuration standards, and operational runbooks to ensure secure and consistent platform management. 

  • Collaborate with Security, Infrastructure, Cloud, DevOps, Audit, and external partners to resolve issues, support compliance requirements (e.g., PCI), and protect the integrity and confidentiality of systems and data. 

 

Minimum Qualifications 

  • Bachelor’s degree or equivalent experience. 

  • 3–5 years of experience in IAM, Security Engineering, or Infrastructure Security. 

  • Hands-on experience with one or more: 

  • PAM platforms (Delinea, CyberArk, etc.) 

  • Secrets management tools (Vault, Secret Server) 

  • AWS IAM 

  • Enterprise PKI / certificate management 

  • Experience administering Active Directory service accounts. 

  • Working knowledge of: 

  • RBAC and least privilege principles 

  • JIT access concepts 

  • Service/workload identity security 

  • Scripting experience (PowerShell, Python, or Bash). 

  • Familiarity with REST APIs and automation tooling. 

  • Network troubleshooting knowledge (TCP/IP, DNS, firewall rules). 

  • Experience in regulated environments (PCI preferred). 

  • Strong troubleshooting and documentation skills. 

  • Ability to deliver in a fast-paced environment. 

  • Excellent interpersonal skills and highly customer oriented. 

  • Excellent written and verbal communication skills. 

  • Background and drug screen. 

 

Preferred Qualifications 

  • Hands-on experience with best-in-class platforms used in managing privileged session management and credential rotation. 

  • Experience implementing or supporting enterprise security vaults (dynamic secrets, workload identity, policy configuration). 

  • Experience engineering AWS IAM environments, including role-based access, cross-account trust, and least-privilege policy design. 

  • Experience eliminating long-lived access keys and transitioning workloads to role-based or federated authentication. 

  • Experience with Certificate Management platforms, enterprise PKI, or automated certificate lifecycle management platforms. 

  • Familiarity with service account governance and non-human identity lifecycle controls within an IGA platform. 

  • Exposure to DevSecOps practices, including embedding secrets management and certificate automation into CI/CD pipelines. 

  • Experience working in regulated environments (PCI, SOX, NIST, ISO) with audit evidence support responsibilities. 

  • Relevant technical certifications (e.g., AWS Security Specialty, HashiCorp Vault Associate, Delinea Engineer, or similar). 

 

The above job description is not intended to be an all-inclusive list of duties and standards of the position.  Incumbents will follow instructions and perform other related duties as assigned by their supervisor. 

 

The base pay scale for this position in:
Phoenix, AZ/ Chicago, IL in USD per year is: $99,000 - $121,000.
Additionally, candidates are eligible for a discretionary incentive plan and benefits.

This pay scale is subject to change and is not necessarily reflective of actual compensation that may be earned, nor a promise of any specific pay for any specific candidate, which is always dependent on legitimate factors considered at the time of job offer. Early Warning Services takes into consideration a variety of factors when determining a competitive salary offer, including, but not limited to, the job scope, market rates and geographic location of a position, candidate’s education, experience, training, and specialized skills or certification(s) in relation to the job requirements and compared with internal equity (peers). The business actively supports and reviews wage equity to ensure that pay decisions are not based on gender, race, national origin, or any other protected classes.

Some of the Ways We Prioritize Your Health and Happiness 

  •  Healthcare Coverage – Competitive medical (PPO/HDHP), dental, and vision plans as well as company contributions to your Health Savings Account (HSA) or pre-tax savings through flexible spending accounts (FSA) for commuting, health & dependent care expenses.

  • 401(k) Retirement Plan – Featuring a 100% Company Safe Harbor Match on your first 6% deferral immediately upon eligibility.

  • Paid Time Off – Flexible Time Off for Exempt (salaried) employees, as well as generous PTO for Non-Exempt (hourly) employees, plus 11 paid company holidays and a paid volunteer day.

  • 12 weeks of Paid Parental Leave

  • Maven Family Planning – provides support through your Parenting journey including egg freezing, fertility, adoption, surrogacy, pregnancy, postpartum, early pediatrics, and returning to work.

 

And SO much more! We continue to enhance our program, so be sure to check our Benefits page here for the latest. Our team can share more during the interview process!

 

Early Warning Services, LLC (“Early Warning”) considers for employment, hires, retains and promotes qualified candidates on the basis of ability, potential, and valid qualifications without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote equal employment opportunity and affirmative action, in accordance with all applicable federal, state, and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our employees. 

Early Warning Services LLC is a proud participant in E-Verify, a federal program to help ensure a legal and authorized workforce. As part of our hiring process, we electronically verify the employment eligibility of all new hires through E-Verify. For more information on your rights and responsibilities under E-Verify please visit Home | E-Verify.

Early Warning Chicago, Illinois, USA Office

Chicago, United States

Similar Jobs

6 Minutes Ago
Remote or Hybrid
USA
140K-215K Annually
Senior level
140K-215K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Design, build, deploy, and iterate production-ready AI agents and LLM-based solutions that integrate with enterprise workflows. Rapidly prototype, evaluate, and optimize agents for performance, cost, and adoption. Partner across functions to redesign workflows, contribute to an AI Center of Excellence, and ensure responsible, secure, and scalable agent development.
Top Skills: Ai AgentsGenerative AiLarge Language ModelsPython
16 Minutes Ago
Hybrid
Chicago, IL, USA
125K-150K Annually
Senior level
125K-150K Annually
Senior level
Artificial Intelligence • Big Data • Healthtech • Machine Learning • Analytics • Biotech • Generative AI
Lead design and validation of molecular assays for IVD and CDx programs. Manage cross-functional teams, author validation plans and documentation, ensure regulatory compliance (FDA/EUA), troubleshoot assays, establish SOPs, track project timelines and budgets, and support FDA submissions with technical reports.
Top Skills: CdxIvdNgsNucleic Acid TechnologiesPcrQpcr
16 Minutes Ago
Hybrid
Chicago, IL, USA
85K-130K Annually
Mid level
85K-130K Annually
Mid level
Artificial Intelligence • Big Data • Healthtech • Machine Learning • Analytics • Biotech • Generative AI
Join the SRE team to design, deploy, and operate resilient cloud infrastructure. Recommend solutions, automate workflows, configure Terraform and CI, implement monitoring and alerts, and support developers and users.
Top Skills: AnsibleAurora MysqlAWSAzureBashChefCloudFormationComposerConcourseDataprocDockerGCPGoHipaaHitrustIsoKubernetesPackerPostgresPuppetPythonRubySaltSlackTerraform

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account