CyberArk/PAM

Hybrid in Alpharetta, GA, US • Posted 1 hour ago • Updated 1 hour ago
Full Time
No Travel Required
Hybrid
Depends on Experience
Company Branding Image
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • EPM
  • Auditing
  • Authentication
  • Configuration Management Database
  • CyberArk
  • Cloud Computing
  • Computer Networking
  • Critical Path Method
  • Endpoint Protection
  • Firewall
  • Hardening
  • IT Service Management
  • Identity Management
  • PSM
  • Provisioning
  • RPC
  • Recovery
  • SMB
  • Microsoft Windows
  • Multi-factor Authentication
  • PIM
  • RDP
  • Server Message Block
  • API
  • JIT
  • Management
  • Microsoft
  • Microsoft Azure
  • Network
  • Windows PowerShell
  • Workflow
  • Privileged Access Engineer
  • Privileged
  • azure

Summary

Job Title: CyberArk/Azure Privileged Access Engineer

Location: Alpharetta, 3 days/week onsite

Duration: Long Term

 

Overview

·       We're looking for a hands-on Senior Privileged Access Engineer to design, configure, integrate, and troubleshoot CyberArk privileged access capabilities within a large-scale, enterprise Microsoft cloud environment. This role sits at the intersection of PAM, identity, and endpoint management, and will play a key part in advising on architecture/design while also directly executing the engineering work — this is not a purely advisory or purely hands-off role.

 

Required Skills & Experience

 

·       Strong, demonstrated hands-on CyberArk experience (PAS/Privilege Cloud, PSM, EPM, CPM/Vault, SIA).

 

Key Responsibilities

 

·       Design, configure, integrate, and troubleshoot CyberArk privileged access capabilities, including SIA, PAS/Privilege Cloud, PSM, EPM, and CPM/Vault components, along with privileged-session controls in Microsoft cloud environments.

·       Implement CyberArk Secure Infrastructure Access/Privileged Session Management and Zero Standing Privilege patterns for Windows endpoints — including ephemeral administrative access, account provisioning, connector deployment, session brokering, credential rotation, revocation, and recovery workflows.

·       Engineer integrations with Microsoft Entra ID, including Conditional Access, phishing-resistant MFA, privileged identity separation, service principals/workload identities, and appropriate use of Entra Privileged Identity Management (PIM).

·       Design and implement secure access paths for Windows 365 and Azure-hosted Windows environments, including private connectivity, firewall requirements, connector placement, RDP/SMB/RPC dependencies, regional resiliency, and network troubleshooting.

·       Configure CyberArk EPM for least-privilege application and task elevation, approved/JIT workflows, endpoint policies, local group controls, and coexistence with Microsoft Intune, Windows LAPS, Entra PIM, and other endpoint-management technologies.

·       Define and implement privileged-account lifecycle controls with clear ownership across CyberArk CPM/SIA, Windows LAPS, EPM, Intune, and other automation mechanisms — ensuring password rotation, local-group membership, and privilege activation controls don't conflict with one another.

·       Build and support integrations with ITSM, CMDB, identity, and workflow platforms using CyberArk APIs, so privileged access can be restricted by user, device, business approval, requested action, scope, and duration.

·       Implement privileged-session monitoring and audit capabilities, including CyberArk session recording, audit APIs, Azure-native logging, and integration with enterprise security monitoring and evidence-retention platforms.

·       Perform hands-on validation of privilege activation, expiration, emergency revocation, disconnected-session behavior, ephemeral-account cleanup, LAPS recovery, connector failures, resiliency, and privileged-session controls.

·       Develop PowerShell and API-based automation, deployment tooling, configuration-as-code, operational runbooks, monitoring, health checks, and troubleshooting procedures.

·       Advise on architecture and design decisions for extending privileged access management into cloud environments at enterprise scale, in addition to hands-on implementation.

·       Strong practical Azure and Microsoft security knowledge, including Entra ID, PIM, Conditional Access, Managed Identities, service principals, Key Vault, Azure networking, Azure Monitor, Windows 365, Intune, Windows LAPS, and Microsoft Graph.

·       Solid understanding of PAM concepts, endpoint security, and Intune-based endpoint management.

    Experience operating in large-scale enterprise environments.

 

Preferred Skills & Experience

 

·       Deep Windows security experience, including local accounts/groups, Windows authentication, RDP, WinRM/PowerShell remoting, UAC, credential protections, and endpoint hardening.

·       Experience with large-enterprise CyberArk implementations.

 

 

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: PTP88pCqqBqe0nD
  • Position Id: 186
  • Posted 1 hour ago

Company Info

About TEKEngineersInc

Founded in 2010, TEKEngineers stands out as a prominent global IT services and solutions company. Our core focus revolves around delivering comprehensive enterprise digital transformation and modernization solutions spanning diverse business verticals. Collaborating closely with our clients, we drive innovation, reimagine workflows, and facilitate transformative experiences, enabling businesses to maintain a competitive edge in today's dynamic landscape.

Within TEKEngineers, we actively cultivate an entrepreneurial mindset among our employees, encouraging them to thrive. Our commitment to inclusivity, integrity, and providing opportunities for promising growth underscores our pledge to accelerate your career within an environment that values both personal and professional development.

About_Company_OneAbout_Company_Two
Contact the job poster
KM

krishna murthy

Recruiter @ TEKEngineersInc
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Hybrid in Alpharetta, Georgia

•

Today

Easy Apply

Full-time

Depends on Experience

Hybrid in Dallas, Texas

•

Today

Easy Apply

Full-time, Third Party

Depends on Experience

Search all similar jobs