CyberArk PAM Engineer

Nova Ltd.
United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Microsoft Access Microsoft Windows Active Directory Application Programming Interfaces (APIs) Amazon Web Services Microsoft Azure Cloud Engineering Cyber Security Computer Networks Disaster Recovery Multi-Factor Authentication
+25 more
Identity and Access Management Key Management Lightweight Directory Access Protocols (LDAP) Simple Mail Transfer Protocols Windows Servers Public Key Infrastructure Windows PowerShell Remote Access Technology Zero Trust Network Access Session Manager SubSystems Security Information and Event Management Software Deployment Systems Integration Software Vulnerability Management Google Cloud Enterprise Software Applications Okta Cyberark QRadar Sentry Hashicorp Restful APIs Splunk Devsecops User Administration

Job description

We are seeking an experienced CyberArk PAM Engineer to lead the implementation, administration, and support of enterprise Privileged Access Management (PAM) solutions. The ideal candidate will have extensive hands-on experience with CyberArk Privileged Access Security (PAS), including greenfield deployments, integrations, upgrades, operational support, and automation.

This role requires expertise in designing, deploying, and maintaining highly available CyberArk environments while ensuring security best practices, compliance requirements, and operational excellence., CyberArk Implementation & Deployment

  • Lead end-to-end CyberArk greenfield implementations from initial design through production deployment.
  • Install, configure, and support CyberArk components including:
  • Primary Vault
  • Privileged Vault Web Access (PVWA)
  • Central Policy Manager (CPM)
  • Privileged Session Manager (PSM)
  • Privileged Session Manager for SSH (PSMP)
  • Disaster Recovery (DR) Vault
  • On-Demand Privileges Manager (OPM/EPM)
  • Configure CyberArk environments across development, testing, staging, and production environments.
  • Perform CyberArk upgrades, patching, migrations, and platform onboarding activities.

CyberArk Administration & Operations

  • Manage day-to-day CyberArk administration activities.
  • Configure and maintain:
  • Safes
  • Platforms
  • User Policies
  • Privileged Accounts
  • User Access Management
  • Password Rotation Policies
  • Session Monitoring Policies
  • Support privileged account onboarding and lifecycle management.
  • Perform health checks and ongoing maintenance of CyberArk infrastructure.

Integrations & Automation

  • Integrate CyberArk with enterprise systems including:
  • LDAP / Active Directory
  • Okta
  • PKI Infrastructure
  • SMTP
  • RADIUS
  • Multi-Factor Authentication (MFA) Solutions
  • Develop and implement automation solutions using:
  • AutoIT
  • PowerShell
  • REST APIs
  • CyberArk APIs
  • Automate operational and administrative PAM activities.

Monitoring & Troubleshooting

  • Analyze CyberArk system logs, application logs, and network logs to identify and resolve issues.
  • Troubleshoot CPM, PSM, PSMP, Vault, and PVWA-related incidents.
  • Maintain platform stability, availability, and performance.
  • Act as an escalation point for CyberArk-related issues.
  • Coordinate with CyberArk support and third-party vendors for issue resolution.
  • Conduct root cause analysis and implement preventive measures.

Security & Compliance

  • Ensure PAM solutions align with enterprise security policies and compliance requirements.
  • Support security audits and compliance initiatives.
  • Monitor privileged access activities and security events.
  • Participate in vulnerability remediation and security hardening activities.

Architecture & Design

  • Design highly available and scalable CyberArk PAM architectures.
  • Implement disaster recovery and business continuity strategies.
  • Support enterprise-wide PAM adoption and expansion initiatives.
  • Recommend security improvements and PAM best practices.

Requirements

Do you have experience in Windows?, * 5+ years of hands-on CyberArk PAM experience.

  • Experience leading CyberArk greenfield implementations.
  • Experience supporting large-scale enterprise PAM environments.
  • Strong troubleshooting and operational support experience., * Experience integrating CyberArk with:
  • Active Directory
  • LDAP
  • Okta
  • PKI
  • SMTP
  • RADIUS
  • Strong knowledge of:
  • Windows Server Administration
  • Linux/Unix Administration
  • Networking Concepts
  • Security Architecture
  • Identity and Access Management (IAM)
  • Experience with scripting and automation using:
  • PowerShell
  • AutoIT
  • REST APIs, * Strong analytical and problem-solving skills.
  • Ability to work independently and manage multiple priorities.
  • Excellent verbal and written communication skills.
  • Strong customer and stakeholder management experience.
  • Ability to operate in a 24×7 support environment when required., * Experience with BeyondTrust Privileged Remote Access (PRA) and Privileged Password Safe (PS).
  • Experience with HashiCorp Vault administration and integration.Knowledge of cloud PAM solutions (AWS, Azure, GCP).
  • Experience with DevSecOps and secrets management.CyberArk certifications such as:
  • CyberArk Defender
  • CyberArk Sentry
  • CyberArk Guardian
  • CyberArk CDE
  • Familiarity with SIEM platforms such as:
  • Splunk
  • QRadar
  • Sentinel

Nice to Have:

  • Experience in financial services, healthcare, government, or highly regulated industries.
  • Knowledge of Zero Trust Security frameworks.
  • Experience implementing privileged access governance programs.
  • Exposure to cloud-native secrets management and container security.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · WWC 2023

Videos

See all

Related articles

See all