> Markdown version of [/jobs/ext/737790-cyberark-icam-application-engineer-remote](https://www.wearedevelopers.com/jobs/ext/737790-cyberark-icam-application-engineer-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # CyberArk ICAM Application Engineer (Remote) - **Company:** GRIMMER TECHNOLOGY AND OPERATIONS INC. - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Temporary contract - **Skills:** Microsoft Windows, Active Directory, Active Directory Federation Services, Application Integration Architecture, JIRA, Audit Trail, User Authentication, Cloud Computing, Configuration Management Databases, Databases, Multi-Factor Authentication, Identity and Access Management, Python (Programming Language), Kerberos (Protocol), Lightweight Directory Access Protocols (LDAP), Linux System Administration, Linux Servers, OAuth, OpenID, Ping (Networking Utility), Public Key Infrastructure, Windows PowerShell, Systems Development Life Cycle, Role-Based Access Control, Cloud Services, Runbook, Security Assertion Markup Language (SAML), Session Management, Systems Integration, Web Applications, Scripting, Okta, Cyberark, Test Scripts, Break Fix, SC Clearance, Sentry, SailPoint, Restful APIs, Servicenow - **Published:** June 29, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9001338/cyberark-icam-application-engineer-remote ## About the Role * Must have an active Secret Clearance. * Bachelor's degree and 10 years of IT, cybersecurity, or IAM experience, or 14 years of experience in lieu of degree. * Must have a current CASP+ or CISSP. * Minimum 5 years of hands-on CyberArk PAM, CyberArk Privilege Cloud, or CyberArk Core Privileged Access Security experience, including application onboarding and configuration. * Minimum 10 years of experience with Microsoft Active Directory and directory services, including privileged groups, service accounts, GPOs, LDAPS, Kerberos, and account lifecycle management. * Experience configuring CyberArk Safes, platforms, CPM rotation/reconciliation, PVWA access, PSM/PSMP session management, and privileged account discovery. * Experience integrating applications with CyberArk AAM/CCP, Credential Provider, REST APIs, Conjur/Secrets Manager, or equivalent secret-management patterns. * Identity Management and Authentication/Authorization integration experience to include identity attribute management, credential management, access management, MFA, SAML, OAuth 2.0, OIDC, federation, and governance. * Extensive experience in a secure government environment supporting business-critical, secure, and highly available systems. * Some experience with Public Key Infrastructure (PKI), Certification Authorities, CRL, and OCSP is preferred. * Experience with government security processes and documentation requirements such as FedRAMP, System Security Plans (SSPs), Authority to Operate (ATO), audit evidence, and DoD compliance is preferred. * Ability to create, explain, and maintain technical documentation, configuration records, onboarding decisions, operational procedures, risks, issues, and remediation plans. * Strong analytical, troubleshooting, follow-through, written, and verbal communication skills, with the ability to present technical ideas in a business-friendly and user-friendly language. * Ability to coordinate with multiple IT, application, security, and vendor teams, work independently on defined tasks, and work well as part of a distributed team. Desired Skills/Knowledge: * CyberArk Defender, Sentry, CDE, CPC, or equivalent CyberArk certification. * PowerShell, Python, REST API, or scripting experience for account discovery, onboarding automation, reporting, and operational support. * Experience with ServiceNow, Jira, change control, CMDB/application inventory, and ticket-driven onboarding workflows. * Experience with Windows/Linux administration, database/service account management, cloud IAM, and privileged session recording/monitoring. * Experience producing onboarding intake forms, test scripts, implementation plans, SOPs, knowledge articles, user guides, and training materials. * Familiarity with SailPoint, Okta, Ping, ADFS, MIM, SecureAuth, or other ICAM tools as they interact with privileged access workflows. ## Description Remotely supporting USACE, the CyberArk / ICAM Application Onboarding Engineer will configure current and new applications for onboarding into CyberArk and related ICAM services. This role will partner with application owners, server/database/cloud teams, and security stakeholders to inventory privileged accounts, define onboarding requirements, configure CyberArk Safes, platforms, and session controls, test credential rotation, document integrations, and support transition to production., * Coordinate with application owners to identify dependencies, credential use cases, account ownership, rotation limitations, service restart impacts, break-glass requirements, and application readiness. * Configure and maintain CyberArk Safes, groups, permissions, platforms, policies, password/credential rotation, reconciliation, verification, and check-in/check-out workflows. * Configure CyberArk components and integrations such as PVWA, CPM, PSM/PSMP, CyberArk AAM/CCP, and Conjur/Secrets Manager where applicable. * Assist application teams through SDLC and change-management activities, including requirements gathering, onboarding design, build/configuration, testing, validation, cutover, and production support. * Replace, reduce, or protect hard-coded, embedded, shared, and unmanaged privileged credentials using CyberArk-approved patterns and ICAM controls. * Validate application functionality after onboarding, including password rotation, reconciliation, session brokering, application-to-application credential retrieval, audit logging, and rollback procedures. * Develop and maintain onboarding checklists, runbooks, integration diagrams, Safe/platform standards, user guides, operational procedures, and evidence for ATO, SSP, audit, and compliance needs. * Troubleshoot CyberArk onboarding and integration issues across Active Directory/LDAP, Windows/Linux servers, databases, web applications, cloud services, and network/security controls. * Support privileged access lifecycle management, least privilege, segregation of duties, MFA/federation alignment, access reviews, governance, and recertification processes. * Work with CyberArk, ICAM, security, application, server, database, and cloud teams to remediate technical gaps and ensure secure enterprise adoption. * Monitor platform health and support day-to-day CyberArk/ICAM administration, incident response, break-fix, patching, and vendor escalation. * Must be able to travel up to 10% of the time. ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [The Best Job Search Websites of 2025](https://www.wearedevelopers.com/magazine/368-the-best-job-search-websites-of-2025)