Posted on: 25/06/2026
About the job :
Job Description - CyberArk PAM Engineer / Architect - L3+ :
Position Summary :
The CyberArk PAM Engineer / Architect is responsible for the design, implementation, operation, and governance of the CyberArk Privileged Access Management platform. The role provides L3+ engineering support and architectural leadership for securing privileged accounts, service accounts, application credentials, and privileged sessions across on-premises, cloud, and hybrid environments.
Experience Requirements :
- 15+ years in Cybersecurity or IAM.
- 12+ years administering and engineering CyberArk PAM.
- Experience with large-scale CyberArk deployments.
- Experience with service account governance and secrets management.
- Experience supporting enterprise environments with strict compliance requirements.
Preferred Certifications :
- CyberArk Defender PAM
- CyberArk Sentry PAM
- CyberArk Guardian
- CISSP
- CISM
- Microsoft SC-300
- Microsoft SC-100
Expected Seniority (L3+) :
For both roles, the resource should be capable of :
- Leading technical design workshops.
- Acting as an escalation point for L1/L2 teams.
- Creating architecture standards and governance frameworks.
- Driving remediation of security findings.
- Leading IAM/PAM projects independently.
- Mentoring junior engineers and operations teams.
- Engaging with auditors, security architects, and senior stakeholders.
Key Responsibilities :
1. CyberArk Platform Management :
- Design, deploy, and maintain CyberArk PAM solutions.
- Manage CyberArk components including :
1. Digital Vault
2. PVWA
3. CPM
4. PSM
5. PSM for SSH
6. PTA
7. AAM / Conjur
- Perform upgrades, migrations, and platform optimization.
- Ensure platform availability and resiliency.
2. Privileged Account Governance :
- Onboard privileged accounts and systems.
- Define password rotation policies.
- Implement least privilege controls.
- Manage privileged account lifecycle processes.
- Conduct access reviews and compliance reporting.
3. Service Account & Application Credential Management :
- Discover and onboard service accounts.
- Implement credential rotation and reconciliation.
- Manage application secrets using :
1. CyberArk AAM
2. CyberArk Conjur
- Secure DevOps and CI/CD privileged credentials.
4. Session Management & Monitoring :
- Configure privileged session monitoring and recording.
- Review session recordings during investigations.
- Define alerting and anomaly detection rules.
- Support incident response and forensic investigations.
5. Cloud & Hybrid PAM :
- Integrate CyberArk with :
1. Microsoft Entra ID
2. Active Directory
3. Azure
4. AWS
5. GCP
6. Kubernetes
- Implement cloud privilege governance.
- Secure privileged access for SaaS platforms.
6. Architecture & Governance :
- Define CyberArk standards and best practices.
- Develop PAM roadmaps and implementation strategies.
- Support audits and compliance initiatives.
- Create technical documentation and operational procedures.
Required Technical Skills :
1. CyberArk Technologies :
- CyberArk PAM, Digital Vault, CPM, PVWA, PSM, PTA, AAM, Conjur, EPM.
2. Infrastructure Technologies :
- Active Directory, LDAP, Windows Server, Linux, VMware, IIS, SQL Server.
3. Scripting & Automation :
- PowerShell, REST APIs, Python, CyberArk REST API.
4. Security & Governance :
- PAM Architecture, Zero Trust, Privileged Session Management, Credential Management, Secrets Management.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Technical / Solution Architect
Job Code
1648525