Summary:
Design, implement, and continuously improve CyberArk vault and Privileged Access Management (PAM) solutions to secure privileged credentials and reduce risks such as credential theft, insider abuse, and lateral movement. Ensure high availability, monitoring, and governance of all privileged access across enterprise environments, including Windows, Linux, UNIX, databases, and cloud platforms.
Responsibilities:
- Define and own the enterprise-wide CyberArk architecture, including Vault, CPM, PSM, PVWA, and Conjur, to support technical accounts inventory.
- Design and enforce privileged-access policies (least-privilege, separation-of-duties, time-bound access) across Windows, Linux, UNIX, databases, and cloud platforms (AWS, Azure, GCP).
- Provide high-availability support for CyberArk, establishing robust monitoring, incident-response, and disaster-recovery processes.
- Drive the secret-management lifecycle, including automatic password rotation, SSH key management, API-credential vaulting, and on-demand retrieval.
- Partner with engineering, application, and cloud teams to embed secure identity controls into new service launches, migrations, or platform upgrades.
- Automate PAM processes using PowerShell, Python, and CyberArk REST APIs.
- Evaluate emerging PAM technologies and build business cases for adoption.
- Collaborate with DevSecOps, Cloud, and Application teams to embed privileged-access controls into CI/CD pipelines and cloud-native workloads.
Qualifications/Requirements:
- Minimum of 8 years of experience as a security professional.
- Bachelor's degree in Computer Science, Information Security, or a related field (Master's preferred).
- Hands-on experience architecting, deploying, and operating CyberArk PAS (Vault, CPM, PSM, PVWA) at an enterprise scale.
- L3-level expertise in Conjur, including policy-as-code (CPL/HCL), secret rotation, dynamic secrets, and Kubernetes integration.
- Deep expertise in CyberArk Core PAS components and Privileged Threat Analytics.
- Strong knowledge of Windows/UNIX/Linux authentication mechanisms, Kerberos, LDAP/AD, SSH, and database authentication.
- Experience integrating CyberArk with SSO/IdP solutions (SAML, OIDC, AD).
- Proficiency in PowerShell, Python, and CyberArk REST API for automation.
- Familiarity with cloud providers (AWS Secrets Manager, Azure Key Vault) and Hybrid-IAM environments.
- Solid understanding of Zero-Trust concepts for privileged access.
- Excellent interpersonal and communication skills; ability to handle high-pressure situations and collaborate with stakeholders.
- Preferred certifications: CyberArk Certified Defender (CCD), Secrets Manager (Conjur).