Overview
Skills
Job Details
Job Description:-
-
Design and document CyberArk PAM architecture to meet enterprise security and compliance requirements.
-
Lead architectural decisions for implementation of core CyberArk components: Vault, CPM, PVWA, PSM, PTA, Conjur, etc.
-
Evaluate business needs and translate them into scalable and secure PAM solutions.
-
Lead or support deployment and configuration of CyberArk tools across hybrid/cloud environments.
-
Integrate CyberArk with identity management systems, SIEM, ticketing platforms, and other infrastructure.
-
Develop custom plug-ins, connectors, and scripts to support onboarding of new platforms and applications.
-
Enforce policies around privileged access control, credential management, session recording, and monitoring.
-
Define and implement standards for account onboarding, rotation policies, and access approvals.
-
Ensure compliance with security frameworks (e.g., NIST, ISO 27001, SOX, HIPAA) and internal policies.
-
Provide guidance and mentorship to CyberArk engineers and administrators.
-
Monitor system health, troubleshoot performance issues, and lead continuous improvement initiatives.
-
Participate in audits and risk assessments related to privileged access.
Required:
-
Bachelor's degree in Computer Science, Information Security, or related field
-
9+ years of experience with CyberArk suite, including at least 2 years in an architecture or lead role
-
Deep understanding of CyberArk core modules, including PAS, PSM, CPM, PVWA, and PTA
-
Strong scripting experience (e.g., PowerShell, Python) for automation and integration
-
Experience with PAM in cloud and hybrid environments (AWS, Azure, Google Cloud Platform)
-
Solid knowledge of identity and access management (IAM), network security, and Windows/Linux system administration
Preferred:
-
CyberArk certifications (e.g., CyberArk Certified Delivery Engineer (CDE) or Sentry)
-
Familiarity with DevOps and secrets management tools like CyberArk Conjur
-
Experience with regulatory standards and audit practices
-
Knowledge of LDAP, SAML, OAuth, and API-based integrations