Live opening · Posted 1 day ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Responsibilities:
Design, deploy, and maintain CyberArk Privileged Access Management (PAM) solutions including Vault, CPM, PSM, PTA and Privilege Cloud for hybrid and cloud-native environments.
Administer and optimise CyberArk Endpoint Privilege Manager (EPM) policies to enforce least privilege and application control on servers and end-user endpoints.
Implement and manage CyberArk Privilege Cloud, including onboarding of accounts, proxy-based access, session recording, and periodic password rotation.
Configure and support CyberArk Identity (IDaaS/SSO/MFA) integrations with enterprise applications, directories, and cloud platforms.
Own end-to-end CyberArk infrastructure on AWS: sizing and deploying components, HA/DR design, backup and recovery, patching, and performance tuning.
Integrate CyberArk with LDAP/AD, RADIUS, SMTP, SIEM/Syslog, ticketing tools, and other security platforms following best practices.
Develop and maintain onboarding workflows, platforms, and policies for privileged accounts and secrets across on-prem, cloud, and SaaS workloads.
Monitor, troubleshoot, and resolve complex issues in PAM/EPM/Privilege Cloud/Identity environments, including advanced PSM and CPM configurations.
Collaborate with security architecture, IAM, cloud, and application teams to design secure privileged access patterns and controls.
Produce and maintain technical documentation, runbooks, and diagrams for CyberArk solutions and related integrations.
Support audits and compliance activities by providing reports, evidence of control effectiveness, and remediation plans for findings.
Requirements:
Bachelor's degree in Computer Science, Information Security, Engineering, or a related discipline, or equivalent practical experience.
5-12 years total experience in information security with at least 5+ years dedicated to CyberArk PAM engineering.
Strong hands-on experience with CyberArk components: Enterprise Password Vault (EPV), CPM, PSM, PTA, and Application Access Manager/Secrets management.
Proven experience implementing and operating CyberArk Privilege Cloud in production, including migrations from on-prem PAM where applicable.
Practical experience with CyberArk EPM: policy design, least-privilege enforcement, elevation rules, and endpoint hardening.
Working knowledge of CyberArk Identity (SSO, MFA, lifecycle flows) and its integration with AD, Entra ID (Azure AD), and major SaaS apps.
Strong AWS experience operating security or IAM-related workloads (EC2 RDS, networking, load balancers, security groups, IAM roles/policies) supporting CyberArk infrastructure.
Familiarity with common operating systems (Windows, Linux/UNIX) and directory services (AD/LDAP) from a PAM perspective.
Experience integrating CyberArk with SIEM/SOC, ITSM, and ticketing tools, and building monitoring and alerting around PAM/EPM services.
Scripting skills (PowerShell, Python, or similar) for automation, bulk onboarding, health checks, and reporting.
Solid understanding of identity security, least privilege, Just-In-Time (JIT), Zero Trust, and privileged threat detection concepts.
Design and implement security controls for Non-Human Identities (NHIs), including service accounts, machine identities, API credentials, application secrets, certificates, and AI-enabled workloads.
Partner with AI, Data, Platform, and Cloud Engineering teams to establish secure privileged access patterns for AI/ML platforms and agentic workflows.
Implement controls to mitigate emerging threats associated with AI agents, including over-privileged access, credential abuse, unauthorised actions, and prompt-injection-induced privilege misuse.
Leverage PAM telemetry, SIEM integrations, and AI/ML-driven monitoring solutions to detect abnormal privileged behaviour involving both human and non-human identities.
Good to have:
Mandatory: CyberArk Sentry-level certification (e. g., CyberArk Sentry PAM / CyberArk Sentry Privilege Cloud / equivalent) or above.
Experience implementing CyberArk Secrets Manager, Conjur, or machine identity security solutions at enterprise scale.
Experience securing AI agents, Generative AI applications, AI-powered automation platforms, and agentic architectures.
Experience designing governance and lifecycle management controls for Non-Human Identities (NHIs) across large enterprise environments.
Expertise in Zero Standing Privilege (ZSP), Just-In-Time (JIT) access, and advanced privileged access workflows.
Experience integrating CyberArk solutions into DevSecOps, CI/CD pipelines, Infrastructure-as-Code, containerised workloads, and cloud-native platforms.
Familiarity with AWS Bedrock, Lambda, or other AI/ML platforms from a security and privileged access perspective.
Experience leveraging behavioural analytics, AI-assisted security monitoring, and advanced threat detection capabilities.
Knowledge of emerging AI security risks, including prompt injection attacks, autonomous agent privilege escalation, credential abuse, and secure AI governance practices.
Proven ability to lead enterprise PAM transformation initiatives, cloud migrations, and modernisation programs.
Strong stakeholder management, consulting, and technical leadership capabilities with the ability to influence architecture and security decisions across the organisation.
Experience
5-8 yrs
More openings worth a look
Recently tracked roles with full details and direct application links.