JobsAmerican Family Insurance

Cybersecurity Engineer - PAM (Hybrid)

American Family Insurance · WI

Posted Sep 8, 2026 · We last checked this listing on Sep 20, 2026

Apply at American Family Insurance

Likely interview questions for this role

Written from this job description, not a generic list. Each one notes what the interviewer is really checking.

Behavioral

Tell me about a time you had to convince a business team to accept a security control they didn't want, like tighter privileged access restrictions.

stakeholder influence skills and ability to balance security needs against business friction

Tell me about a time you found a gap in an existing security process or system. What did you do about it?

proactive risk identification and follow-through on remediation

Tell me about a time cybersecurity risk and business speed were in tension. How did you resolve it?

judgment on trading off risk mitigation against operational velocity, which this role explicitly values

Describe a situation where you had to explain a technical vulnerability to a non-technical stakeholder. How did you make sure they understood the risk?

communication skill across the IT-and-business collaboration this job requires

Technical

Walk me through a PAM solution you built or helped build from the ground up. What was the framework, and how did you handle the rollout across teams?

whether the candidate has real hands-on experience designing PAM architecture versus just administering an existing tool

What's your experience with directory services and identity stores, and how do they tie into how you'd design or troubleshoot a PAM integration?

depth of foundational IAM knowledge versus surface familiarity

Have you automated any part of an access review or provisioning process using Python or PowerShell? Tell me what you built.

actual scripting ability and initiative to reduce manual toil, not just resume claims

What's the difference between identity governance and privileged access management, and where do they overlap in your experience?

conceptual clarity on IAM domains and whether they've actually worked across both

How do you approach documenting standards and procedures for IAM operations so they actually get used by the team?

whether they treat documentation as a real deliverable or an afterthought

What do you know about cloud security in a hybrid environment, and how does privileged access management change when you move from on-prem to cloud?

awareness of how PAM principles shift across environments, relevant given the hybrid infrastructure mentioned

What relevant security frameworks or regulatory requirements have you had to design controls against, and how did that shape your PAM work?

grounding in compliance-driven engineering rather than just technical preference

Situational

Say we have a privileged account that's been flagged for unusual access at 2am. Walk me through how you'd triage that incident.

structured incident response thinking and ability to assess impact under pressure

If you inherited a legacy PAM environment with inconsistent vaulting practices and no clear roadmap, what would your first 90 days look like?

ability to build structure and prioritize in ambiguous, high-velocity conditions

Practice this interview out loud.

Offer builds a real interview for this exact role at American Family Insurance from your resume and this job description, asks the questions one at a time, and tells you what landed. The first one is free.

Practice this out loud

The full job description

As published by American Family Insurance.

As a Cybersecurity Engineer with American Family Insurance, you will primarily be responsible for creating PAM (Privileged Access Management) solutions. You will also develop a framework, roadmap, and program optimization. Additionally, you will work on process engineering, risk remediation, and mitigation of operational risk. To achieve this, you will introduce technology, requirements, deliverables, gaps, and systems design in a high-velocity culture. Analyze competitive strategies, cyber technologies, metrics models, and performance indicators. You will report to the Senior Manager, Cybersecurity. Role not eligible for sponsorship. Relocation available for qualified candidates. #LI-Hybrid Position Compensation Range: $90,000.00 - $147,000.00 Pay Rate Type: Salary Compensation may vary based on the job level and your geographic work location. Relocation support is offered for eligible candidates. Primary Responsibilities: • Participate in the development, integration, and testing of cyber product • Research, engineer, and integrate new security solution • Perform Cyber Identity incident triage, determine potential impact, and identify specific vulnerability • Participate in the development and maintenance of security system and solution • Build relationship with peers throughout the company through collaborative engineering operations. • Participate in the design and implementation of automated solution to meet security need • Demonstrate strong understanding of Privileged Access Management (PAM) solution • Collaborate with IT and business team to identify, assess, and mitigate cybersecurity risk • Maintain documentation, procedure, and standard related to IAM cybersecurity operation • Develop system-security measure to ensure PAM cybersecurity is fully integrated • Manage, analyze, and respond to changing system and data access needs for the company and clients Specialized Knowledge & Skills Requirements: • Demonstrated experience providing customer-driven solution, support, or service • Basic knowledge and understanding of software engineering architecture, system/software design, and system deployment • Basic knowledge and understanding of Cyber Security, Cyber Engineering, Computer Science, Software Engineering • Basic knowledge and understanding of security technology and application development methodology • Demonstrated experience performing cyber threat analysis and incident response • Working knowledge of penetration testing • Solid knowledge and understanding of directory service and identity store Preferred Qualifications: • Professional certification such as CISSP, CISM, CompTIA Security+, or similar • Experience with cloud security and hybrid environment • Hands on experience with identity governance, technical script writing and automation. • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field; OR minimum 5 years professional experience in cybersecurity • Demonstrated experience in Identity and Access Management (IAM) • Experience in network security and infrastructure management • Solid understanding of security framework, best practice, and regulatory requirement. • Python and PowerShell. Licenses: •Not Applicable. Travel Requirements •Up to 10%. Physical Requirements •Work that primarily involves sitting/standing. Working Conditions •Not Applicable. Additional Information • To ensure a strong start, all employees participate in our New Employee Orientation during their first week.  This experience is held in person at our Madison, WI Headquarters or one of our AmFam core locations to help you connect with our mission, meet key team members and build relationships that support your growth.  At times, sessions may be delivered virtually based on scheduling and availability.  • Offer to selected candidate will be made contingent on the results of applicable background checks • Offer to selected candidate is contingent on signing a non-disclosure agreement for proprietary information, trade secrets, and inventions • Sponsorship will not be considered for this position unless specified in the posting In this hybrid role you will be expected to work a minimum of 10 days per month out of the Madison, WI or Boston, MA offices. We provide benefits that support your physical, emotional, and financial wellbeing. You will have access to comprehensive medical, dental, vision and wellbeing benefits that enable you to take care of your health. We also offer a competitive 401(k) contribution, a pension plan, an annual incentive, 9 paid holidays and a paid time off program (23 days accrued annually for full-time employees). In addition, our student loan repayment program and paid-family leave are available to support our employees and their families. Interns and contingent workers are not eligible for American Family Insurance Group benefits. We are an equal opportunity employer. It is our policy to comply with all applicable federal, state and local laws pertaining to non-discrimination, non-harassment and equal opportunity. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. American Family Insurance is committed to the full inclusion of all qualified individuals. If a reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please email AskHR@AmFam.com to request a reasonable accommodation. #LI-AB1

Apply at American Family Insurance

Related jobs

Desk Adjuster

American Family Insurance · Madison, WI

Posted Sep 17 · Verified Sep 20

Lead Engineer

American Family Insurance · Madison, WI

Posted Sep 16 · Verified Sep 20

Lead Data Engineer

American Family Insurance · Madison, WI

Posted Sep 16 · Verified Sep 20

Senior Manager, Insurance Product Analytics (Hybrid)

American Family Insurance · Madison, WI

Posted Sep 15 · Verified Sep 20

Sales District Leader - South Milwaukee, WI (Primarily Field)

American Family Insurance · Milwaukee, WI

Posted Sep 10 · Verified Sep 20

Senior Network Engineer

American Family Insurance · Madison, WI

Posted Sep 9 · Verified Sep 20