Senior CyberArk PAM & EPM Implementation Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+23 more
Job description
- We are seeking an experienced Senior CyberArk PAM Implementation Engineer to assess, optimize, and enhance our existing CyberArk Privileged Access Management environment. The ideal candidate will have strong hands-on experience with CyberArk Cloud/SaaS and the ability to perform a comprehensive assessment of the existing PAM implementation, identify security and operational gaps, and develop a strategic roadmap for utilizing CyberArk capabilities to their fullest extent.
- This role requires deep expertise in CyberArk PAM and Endpoint Privilege Manager (EPM), Secure Infrastructure Access (SIA), Just-in-Time (JIT) privileged access, application onboarding, password rotation, privileged session access, secrets management, and cloud integrations. The successful candidate will define the current-state architecture, recommend a target-state design based on CyberArk and industry best practices, and lead or support execution of the resulting roadmap.
Key Responsibilities 1. Existing CyberArk Environment Assessment
- Perform a comprehensive assessment of the existing CyberArk PAM environment.
- Review the current CyberArk architecture, configuration, integrations, policies, account onboarding processes, and operational procedures.
- Identify security gaps, implementation deficiencies, unused capabilities, technical debt, and opportunities for optimization.
- Evaluate the effectiveness of privileged account onboarding, password rotation, session management, access controls, and privileged access workflows.
- Assess CyberArk platform health, scalability, resilience, availability, and operational maturity.
- Review the existing use of CyberArk Cloud capabilities and recommend improvements.
- Develop a current-state assessment report, including findings, risks, recommendations, and remediation priorities.
-
CyberArk Strategy and Roadmap * Develop a strategic PAM roadmap aligned with business requirements, cybersecurity objectives, and CyberArk best practices. * Define a target-state CyberArk architecture and implementation plan. * Develop a prioritized plan to maximize adoption and utilization of CyberArk capabilities. * Create implementation phases, dependencies, milestones, and technical requirements. * Define PAM use cases and prioritize systems, accounts, applications, and user populations for onboarding. * Develop a PAM maturity improvement plan.
-
CyberArk Cloud / PAM Implementation Implement and optimize CyberArk Cloud/SaaS capabilities, including:
- Privileged account management and onboarding
- Account discovery and lifecycle management
- Password rotation, verification, and reconciliation
- Privileged session management and recording
- Privileged session monitoring
- Application credential management
- Secrets management
- Privileged access request and approval workflows
- Cloud infrastructure privileged access
- Integration with enterprise identity and authentication platforms
-
Secure Infrastructure Access (SIA) * Design, implement, and optimize CyberArk Secure Infrastructure Access (SIA). * Enable secure, centralized access to infrastructure while minimizing exposure of privileged credentials. * Implement secure access workflows for Windows, Linux, cloud infrastructure, and other supported platforms. * Integrate SIA with enterprise identity providers and authentication mechanisms. * Implement role-based access controls for infrastructure access. * Develop standards and procedures for onboarding infrastructure to SIA. * Evaluate existing administrative access methods and identify opportunities to reduce direct credential exposure.
-
Just-in-Time (JIT) Privileged Access * Design and implement Just-in-Time (JIT) privileged access capabilities. * Implement time-bound and controlled privileged access and reduce standing privileges where feasible. * Integrate JIT workflows with identity, ITSM, cloud, and authentication platforms where appropriate. * Define access request, approval, elevation, expiration, and revocation workflows. * Develop controls for privileged access to cloud and infrastructure environments. * Monitor and optimize JIT access policies based on operational and security requirements.
-
Application, System, and Account Onboarding * Lead onboarding of applications, systems, databases, platforms, and privileged accounts into CyberArk. * Assess applications for password rotation, credential management, and secure access requirements. * Configure and implement password rotation, verification, and reconciliation. * Onboard service accounts and application accounts into CyberArk. * Work with application owners to implement credential retrieval and secure secrets consumption. * Enable users to securely access systems and administrative portals through CyberArk. * Implement session management and recording for supported systems. * Develop reusable onboarding patterns for Windows, Linux/Unix, databases, network devices, cloud platforms, SaaS applications, web portals, service accounts, application credentials, APIs, and machine identities. * Design, implement, and optimize CyberArk Endpoint Privilege Manager (EPM) to enforce least privilege and reduce local administrator rights. * Develop EPM application control and privilege elevation policies, including policy sets, rules, and baselines. * Perform EPM discovery and assessment to identify excessive local administrator privileges and privilege elevation requirements. * Plan and execute EPM agent deployment, phased rollout, and onboarding across Windows and supported endpoint platforms. * Implement application elevation, application control, credential protection, and least-privilege policies. * Define and maintain EPM policy baselines and exception management processes. * Integrate EPM with enterprise identity, security monitoring, and IT operational processes where appropriate. * Monitor EPM policy effectiveness, troubleshoot agent and policy issues, and continuously optimize configurations.
6A. CyberArk Endpoint Privilege Manager (EPM) 7. Integrations and Automation
- Integrate CyberArk with enterprise identity and authentication platforms.
- Integrate CyberArk with cloud platforms and infrastructure services.
- Work with application teams to integrate applications with CyberArk secrets management capabilities.
- Integrate CyberArk with ITSM, SIEM, monitoring, and ticketing platforms where required.
- Develop automation for privileged account discovery, onboarding, reporting, and operational processes.
- Use PowerShell, Python, REST APIs, and CyberArk automation capabilities to improve efficiency.
- Standards, Governance, and Best Practices * Develop CyberArk architecture standards and implementation guidelines. * Define PAM onboarding standards and security requirements. * Develop SOPs and operational runbooks for CyberArk administration. * Define privileged account ownership and lifecycle processes. * Establish policies for password rotation, reconciliation, session recording, privileged access, and emergency access. * Develop privileged account inventory and classification standards. * Ensure implementation aligns with CyberArk best practices and organizational security requirements.
Technical Requirements Required
- CyberArk PAM and CyberArk Cloud/SaaS
- Privileged Account Security
- Central Policy Manager (CPM)
- Privileged Session Manager (PSM)
- Privileged Session Manager for SSH (PSMP), where applicable
- Password rotation and reconciliation
- Privileged account onboarding
- Application account and service account management
- Secrets management
- CyberArk Secure Infrastructure Access (SIA)
- Just-in-Time (JIT) privileged access
- Privileged session access and recording
- REST API integration
- Identity provider integration
- Windows and Linux privileged access
Strongly Preferred
- CyberArk Endpoint Privilege Manager (EPM) design, implementation, policy development, deployment, and operational support
- Privileged Threat Analytics (PTA), where applicable to the environment
- CyberArk application access and secrets capabilities
- AWS, Microsoft Azure, and/or Google Cloud integration
- Kubernetes or container environments
- DevOps and CI/CD integrations
- ITSM and SIEM integrations
- Hands-on experience designing, deploying, configuring, and supporting CyberArk Endpoint Privilege Manager (EPM), including policy development, application control, privilege elevation, agent rollout, and operational optimization.
Requirements
- Minimum of 5 8 years of hands-on CyberArk PAM implementation and engineering experience.
- Demonstrated experience assessing an existing CyberArk environment and developing a remediation or enhancement roadmap.
- Strong hands-on experience with CyberArk Cloud/SaaS.
- Demonstrated implementation experience with CyberArk SIA.
- Demonstrated implementation experience with Just-in-Time privileged access.
- Experience onboarding complex applications and systems for password rotation, password reconciliation, session access, privileged session management, and secrets management.
- Experience integrating CyberArk with enterprise applications and cloud platforms.
- Experience migrating or transforming legacy privileged access processes into CyberArk-based workflows.
- Strong understanding of privileged account lifecycle management.
- Experience working with application owners, infrastructure teams, cloud teams, IAM teams, and vendors.
- EPM operational and exception-management procedures
- EPM application control and privilege elevation use-case catalogue
- EPM agent deployment and phased rollout plan
- EPM policy and baseline design
- EPM target-state architecture and deployment strategy
- EPM current-state assessment and maturity review
Required Deliverables
- Current-state CyberArk architecture assessment
- CyberArk health and configuration assessment
- PAM maturity and gap assessment
- Privileged account inventory and classification
- Target-state CyberArk architecture
- CyberArk Cloud adoption strategy
- SIA implementation strategy
- JIT implementation strategy
- Application and service account onboarding framework
- Password rotation onboarding plan
- Session access and portal access onboarding plan
- Prioritized remediation and implementation roadmap
- PAM standards and operating procedures
- Use-case catalogue
- Integration architecture and implementation plan
- Knowledge-transfer and operational handover documentation
EPM experience should be considered a core requirement for this role, including architecture, design, policy development, agent deployment, rollout, troubleshooting, and optimization. Must-Have Skills for Candidate Screening
- CyberArk PAM implementation experience
- CyberArk Cloud/SaaS experience
- CyberArk SIA implementation
- JIT privileged access implementation
- CyberArk assessment and architecture review experience
- CPM password rotation and reconciliation
- PSM privileged session access
- Application and service account onboarding
- Secrets management
- Windows and Linux privileged access
- PowerShell, Python, and/or API automation
- Ability to develop a PAM roadmap and target-state architecture
Preferred Certifications
- Relevant CyberArk Defender certification
- Relevant CyberArk Sentry certification
- CyberArk Cloud-related training or certifications
- CyberArk PAM implementation or delivery credentials
- CISSP is beneficial but not mandatory for this hands-on engineering role
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
9 Ways to Make Money Hacking
Everything a Developer Needs to Know About MCP with Neo4j