Posted on: 11/09/2026
CyberArk PAM - L3/L4
Position Overview :
Position : CyberArk PAM L3/L4 Engineer
Experience : Senior-level CyberArk PAM administration and support experience
Core Platform : CyberArk Vault, CPM, PVWA, PSM/PSMP, PTA; AAM/Conjur and EPM where applicable
Job Summary :
We are looking for an experienced CyberArk PAM L3/L4 Engineer to support the administration, monitoring, troubleshooting, configuration, incident resolution, and continuous improvement of a CyberArk Privileged Access Management environment. The role will handle advanced L3 issues and, at L4 level, architecture-level troubleshooting, upgrades, complex root-cause analysis, vendor escalation, and technical governance.
Key Responsibilities :
- Administer, monitor, troubleshoot, and maintain CyberArk PAM components including Digital Vault, CPM, PVWA, PSM/PSMP, and PTA.
- Manage privileged accounts, safes, platforms, policies, and the complete account lifecycle.
- Perform advanced troubleshooting for issues escalated from L1/L2 support.
- Investigate and resolve failed password/SSH key rotations, reconciliations, and account onboarding issues.
- Perform safe, platform, and account configuration and policy tuning.
- Coordinate with Windows, Unix/Linux, database, network, and application teams for target-system onboarding and access issues.
- Execute approved configuration changes, patches, and upgrades across non-production and production environments.
- Conduct health checks, performance monitoring, capacity assessment, and log management.
- Perform root-cause analysis for recurring and complex incidents and track preventive actions.
- Support audits, compliance reviews, access certification, and privileged-access recertification.
- Maintain runbooks, SOPs, knowledge articles, and technical documentation.
- Participate in change management and CAB activities for PAM-related changes.
- At L4 level, troubleshoot HA/DR and Vault replication issues and provide architecture-level technical guidance.
- Design and review platform upgrades, patches, configuration changes, and security-hardening recommendations.
- Own complex RCAs involving multiple CyberArk components and coordinate with CyberArk vendor support/TAM.
- Provide governance input on policy standards, naming conventions, safe design, and least-privilege models.
- Mentor L1/L2 resources and provide technical oversight and quality review of L3 deliverables.
Required Technical Skills :
- Hands-on experience administering CyberArk PAM, including Vault, CPM, PVWA, and PSM/PSMP.
- Strong understanding of privileged account onboarding, safes, platforms, password management, rotation, and reconciliation.
- Experience with CyberArk PTA; exposure to AAM/Conjur and EPM is an advantage.
- Strong knowledge of Windows and Unix/Linux administration.
- Good understanding of Active Directory and networking fundamentals including ports, certificates, and load balancers.
- Experience with ITSM processes covering incident, problem, and change management.
- Strong troubleshooting and root-cause analysis skills for complex PAM issues.
- Knowledge of security principles such as least privilege, credential lifecycle, session isolation, audit, and compliance.
- PowerShell or Python scripting knowledge for automation and reporting is desirable, particularly for L4 roles.
Preferred Certification :
CyberArk Defender / Sentry certification preferred, at a level appropriate to the L3 or L4 role.
L3 vs. L4 Scope :
- Troubleshooting : Advanced troubleshooting of Vault, CPM, PVWA, PSM and non-standard issues - Architecture-level troubleshooting, including HA/DR and Vault replication
- Changes & Upgrades : Execute approved configuration changes, patches and upgrades - Design/review upgrades, patches and complex configuration changes before rollout
- Integrations / Environment : Active Directory, SIEM, ServiceNow / ITSM, Windows and Unix/Linux target systems, Databases and network devices, Cloud IAM environments
Key Deliverables :
- Resolution of L3/L4 incidents and tickets within agreed SLAs.
- CyberArk Vault/CPM/PVWA/PSM health-check reporting.
- RCA documentation for major incidents.
- Support for periodic privileged-access reviews and recertification.
- Documented and CAB-approved change records.
- Updated runbooks, SOPs, and knowledge-base documentation.
Role Expectations :
- Strong ownership of complex CyberArk incidents from investigation through resolution.
- Ability to work collaboratively with application, infrastructure, security, and PAM teams.
- Ability to communicate technical issues and RCA findings clearly.
- Willingness to support planned after-hours/weekend changes when scheduled in advance.
- Ability to mentor junior support resources and contribute to operational improvements.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1670873