CyberArk PAM SME
- Location: Remote
- Contract Length: 11 Months
We at Raise are hiring a CyberArk PAM SME for one of our top clients. After establishing themselves as an industry leader, they’re now expanding their team to meet rising demand. We’re hiring right now; if you’re interested, apply below for your chance to join a great place to work.
Roles and Responsibilities:
PAM Architecture & Design
- Design and implement CyberArk PAM solutions aligned with enterprise security standards.
- Develop PAM architecture roadmaps and migration strategies.
- Design High Availability (HA), Disaster Recovery (DR), and Business Continuity solutions.
- Define PAM governance, standards, and operational procedures.
- Provide SME leadership during PAM transformation projects.
CyberArk Platform Administration
- Install, configure, upgrade, and maintain CyberArk components:
- Digital Vault
- PVWA
- CPM
- PSM
- PSMP
- PTA
- EPM
- CCP
- AAM/CP
- Perform platform patching and version upgrades.
- Monitor system health and performance.
- Manage safes, platforms, policies, users, groups, and access controls.
Privileged Account Management
- Onboard privileged accounts and service accounts.
- Configure password rotation and reconciliation policies.
- Implement account discovery solutions.
- Manage SSH keys and privileged credentials.
- Enforce least privilege and segregation of duties controls.
Session Management
- Configure and support:
- PSM
- PSMP
- Session Monitoring
- Session Recording
- Implement privileged session auditing and reporting.
- Investigate privileged session activities.
- Support forensic analysis and security investigations.
Application Access & Secrets Management
- Integrate CyberArk Application Access Manager (AAM).
- Configure:
- Credential Providers
- Central Credential Provider (CCP)
- Credential Retrieval APIs
- Support application credential onboarding.
- Enable secure machine-to-machine authentication.
- Integrate CyberArk PAM with Conjur where required.
Cloud & Hybrid Security
- Integrate PAM with:
- Microsoft Azure
- AWS
- GCP
- Secure cloud administrative identities.
- Support hybrid datacenter and cloud deployments.
- Implement Just-In-Time (JIT) privileged access models.
Directory & Identity Integrations
- Integrate CyberArk with:
- Active Directory
- LDAP
- Microsoft Entra ID
- Okta
- SailPoint
- ServiceNow
- Configure SSO and MFA integration.
- Support identity lifecycle management integrations.
Operations & Support
- Provide L3/L4 support for CyberArk infrastructure.
- Resolve platform incidents and problem records.
- Perform root cause analysis (RCA).
- Support change management and release activities.
- Develop operational runbooks and SOPs.
- Participate in on-call support rotations.
Security & Compliance
- Support audits and compliance assessments.
- Generate evidence for:
- SOX
- PCI-DSS
- HIPAA
- ISO 27001
- NIST
- Review privileged access violations.
- Support security incident investigations.
- Drive continuous compliance initiatives.
Experience
- 8 to 15+ years of IT Security and IAM experience
- 5+ years of hands-on CyberArk PAM implementation and administration experience
- Experience supporting large-scale enterprise PAM environments
Required Technical Skills:
CyberArk Components
- Digital Vault
- PVWA
- CPM
- PSM
- PSMP
- PTA
- EPM
- AAM
- CCP
- Credential Provider
- Privilege Cloud
Identity & Access Management
- Microsoft Entra ID
- Active Directory
- LDAP
- SAML
- OAuth
- OpenID Connect
- MFA Technologies
Operating Systems
Windows
- Windows Server Administration
- Active Directory Administration
Linux/Unix
- RHEL
- CentOS
- Ubuntu
- AIX
- Solaris
Databases
- SQL Server
- Oracle
- PostgreSQL
- MySQL
Automation & Scripting
- PowerShell
- Python
- Bash Shell Scripting
- REST APIs
- Ansible
- Terraform
Networking & Security
- TCP/IP
- Firewalls
- Load Balancers
- TLS/SSL
- PKI
- DNS
- Zero Trust Architecture
Preferred Qualifications:
CyberArk Certifications
- CyberArk Defender PAM
- CyberArk Sentry PAM
- CyberArk Guardian
- CyberArk Delivery Engineer (CDE) for PAM
Looking for meaningful work? We can help!
Raise is an established hiring firm with over 65 years of experience. We believe strongly in making the world a better place through work, which is why we’re a certified B Corporation and donate 10% of our profits to charity.
We strive to build teams that reflect the diversity of the communities we work in. We encourage all qualified applicants to apply, including people from traditionally underrepresented groups such as women, visible minorities, Indigenous peoples, people identifying as LGBTQ2SI, veterans, and people with visible/nonvisible disabilities.
We have a dedicated webpage for accommodations where you can learn more about what we offer and request accommodations: https://raise.jobs/accommodations/
In order to submit candidates for roles, our clients will sometimes require personal information to confirm the identity of applicants and their legal status to work. Raise will never ask you for personal or banking information unless you have been selected for a job. If you are ever unsure about the legitimacy of this or another job posting by Raise (or have any other questions), please contact us at +1 800-567-9675 or hello@raiserecruiting.com