Top Technical Requirements
- CyberArk EPM for Linux Must Have
Candidates should have hands-on experience:
- Creating and configuring CyberArk EPM policies for Linux
- Supporting RHEL/Linux environments
- Troubleshooting EPM policies and agent activity
- Reviewing CyberArk EPM logs to identify why policies or access are failing
- Understanding privilege management and elevation policies
- Ideally, migrating from another privilege management solution into CyberArk EPM
Important: The candidate must be able to explain what they personally did with EPM. Do not rely on resume keywords alone.
- Strong Linux Security Engineering Most Important Overall
The candidate should be able to work deeply in Linux security, including:
- RHEL environment is almost entirely RHEL
- Linux hardening
- PAM
- Sudo/sudoers policy management
- SSH key integration and lifecycle management
- Security logs and troubleshooting
- Authentication and privilege issues
- Bash scripting
- Understanding Linux configuration files
They should be able to troubleshoot Linux security issues at the OS level, not just manage infrastructure.
- SSSD and Active Directory Preferred
Experience with:
- SSSD
- Joining Linux machines to Active Directory
- AD-based Linux authentication
- Troubleshooting authentication and caching issues
- Kerberos/domain integration
This is preferred, but not a deal breaker if the candidate is very strong in CyberArk EPM and Linux security.
Current Project
The team is migrating from BeyondTrust/PowerBroker for Unix/Linux to CyberArk EPM.
The candidate will help:
- Build CyberArk EPM policies from the ground up
- Translate existing privilege policies into CyberArk EPM
- Troubleshoot EPM policies and Linux security logs
- Identify why policies are generating unexpected activity or failures
- Support the migration into production
The team is approximately three months into a six-month timeline, so they need someone who can come in and contribute quickly.
Previous experience migrating from BeyondTrust/PowerBroker to CyberArk would be ideal, but it is not required. Someone who has built and troubleshot CyberArk EPM policies in a production Linux environment can still be a strong fit.