Posted on: 15/07/2026
Required Technical Skills :
1. CyberArk PAM Vault Operations (Primary Platform) :
- Operational proficiency in CyberArk Privileged Access Manager : navigating the vault, understanding Safe architecture, retrieving credentials through the CyberArk web interface and PVWA (Password Vault Web Access), reviewing session recordings via PSM (Privileged Session Manager), and Understanding account status (active, locked, rotation pending, compliance failures). Must be able to operate the platform confidently without L2 assistance for routine tasks.
2. Privileged Account Lifecycle and Operational Knowledge :
- Understanding of how privileged accounts are onboarded, rotated, and offboarded in a managed PAM environment : account discovery outputs, onboarding queue management, rotation verification, account reconciliation, and the difference between managed and unmanaged privileged accounts.
3. Password Rotation Monitoring & Validation :
- Ability to monitor CyberArk's automated password rotation schedules : verify rotations completed successfully, identify and log failed rotations, escalate to the PAM Engineer when rotation failures indicate a connector or account issue, and confirm resolution.
4. Session Recording Review & Anomaly Detection :
- Ability to review flagged CyberArk PSM session recordings : identify anomalous activity patterns (unexpected commands, access to files outside the expected scope, lateral movement indicators, unusual session duration), document findings, and escalate to the PAM Engineer or SOC as appropriate.
5. Privileged Account Ticket Queue Management :
- Ability to manage the ITSM ticket queue for PAM service requests : access requests for privileged credentials, password retrieval issues, account unlock requests, onboarding requests for new privileged accounts, and offboarding requests for terminated accounts. Triage by priority, respond within SLA, and resolve or escalate as appropriate.
6. Safe Health Checks & Compliance Monitoring :
- Ability to run and interpret CyberArk safe health reports : identify safes with non-compliant accounts (overdue rotation, accounts not meeting policy), orphaned accounts (no associated identity in the identity source), and safes with incorrect member configurations. Document findings and escalate for remediation.
7. Active Directory, Operational Knowledge :
- Ability to look up privileged AD accounts, verify group membership, and confirm account status, supports PAM operational tasks such as verifying that a leaver's privileged AD account has been removed from all privileged groups and disabled or deleted per policy.
8. ITSM Tooling (ServiceNow or Jira) :
- Proficiency in managing the PAM ticket queue : triage, prioritize, update status, log resolution notes, escalate correctly, and close with full documentation. PAM tickets carry higher audit significance than standard IT tickets, every action must be logged.
Certifications :
Required Certifications :
- CyberArk Trustee (Defender) required at hire.
- CompTIA Security+ required at hire.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1654378