Turn this role into an interview — a resume and cover letter built around what this employer wants.
Paramount Assure in Dubai seeks an experienced cybersecurity infrastructure engineer to design and operate CyberArk Vaults CPM PVWA and PSM clusters. You will manage secrets, onboard privileged accounts and automate onboarding workflows while developing plugins and connectors for automation.
The role requires strong ZTNA expertise, Netskope and IAM integration, along with patching, DR readiness and MFA enforcement in a secure enterprise environment.
PAM amp ZTNA
Design and scale Vaults CPMs PVWAs and PSM clusters Manage secrets Configure application identity manager AIM and CCP secrets rotation Onboard accounts Automate privileged account discovery and onboarding workflows Develop plugins Create custom CPM and PSM connection components Resolve escalations Fix complex replication vault database and credential provider failures Lead upgrades Execute patch management and major version upgrades independently Netskope ZTNA SASEDefine policies Build context-aware access control policies based on device posture Deploy steering Configure Netskope steering clients and network tunnel integrations Manage gateways Administer Netskope Publisher appliances in hybrid cloud environments Troubleshoot traffic Analyze packet captures to resolve application routing issues Enforce Zero Trust Migrate legacy VPN users to continuous verification models
strong CyberArk CDE Certified Delivery Engineer certification Knowledge of Active Directory and IAM Experience with SIEM tools integration strong Implementation amp Architecture Design strong CyberArk architecture Deploy core components Install EPV CPM PVWA and PSM Configure distributed architectures Set up disaster recovery sites Build custom plugins Develop universal connectors Integrate APIs for automation strong Implementation amp Deployment strong Deploy components Install CyberArk Vault CPM PVWA and PSM Configure connectors Set up standard platforms and connection components Integrate systems Connect PAM with Active Directory and SIEM tools Define Master Policy settings Optimize platform settings Structure safe permissions Streamline onboarding processes Manage dual-control workflows Refine connection component settings Troubleshoot complex replication errors Resolve credential provider failures strong Policy amp Safe Management strong Design safes Establish safe structures retention periods and permissions Tune policies Optimize Master Policy rules and platform settings Manage accounts Onboard privileged IDs service accounts and SSH keys strong Operations amp Administration strong Account onboarding Integrate privileged accounts into CyberArk Policy management Configure Master Policy and platform settings Safe management Create safes and manage user permissions Access provisioning Grant or revoke user access rights Resolve incidents Troubleshoot CPM rotation failures and PSM session errors Monitor health Track Vault replication component services and system logs Patch systems Apply minor upgrades patches and security hotfixes strong Maintenance amp Monitoring strong Health checks Monitor CyberArk component operational status daily Component oversight Watch Vault CPM PVWA and PSM Log analysis Review system logs to identify errors Service management Restart failed CyberArk services promptly strong Troubleshooting amp Support strong Ticket resolution Resolve escalated L2 technical support incidents Password failures Fix Central Policy Manager CPM rotation errors Connection issues Troubleshoot Privileged Session Manager PSM failures Vendor coordination Escalate unresolved bugs to CyberArk support strong Security Posture Improvement strong Enforce MFA Implement multi-factor authentication for all PAM access Audit behaviour Review privileged session recordings and anomalous activities Reduce risk Identify unmanaged privileged accounts for onboarding Enforce Least Privilege models Eliminate hardcoded application credentials Deploy CyberArk Secrets Manager Analyze PTA security events Remediate anomalous privilege behavior Conduct regular vault hardening Align policies with CIS benchmarks Lead audit compliance mapping
strong Required Technical Skills strong CyberArk tools Deep knowledge of PVWA CPM PSM and Vault Operating systems Strong Windows Server and Linux administration Directory services Clear understanding of Active Directory and LDAP Networking basics Familiarity with firewalls routing and TCP IP Scripting skills Basic PowerShell or Python for automation
strong Secondary Responsibilities DLP strong Symantec Data Loss PreventionTriage incidents Investigate high-severity data leakage alerts across endpoints and network Tune policies Modify DLP rules to reduce false positives for data-at-rest and data-in-motion Maintain agents Oversee the health and deployment of Symantec DLP endpoint agents Support audits Generate compliance reports for GDPR HIPAA or PCI-DSS requirements
strong General L3 Operational Duties strong Root cause analysis Lead post-mortem investigations for major security infrastructure outages Automation Write PowerShell Python or Bash scripts to automate routine security checks Mentor teams Provide technical training and documentation to L1 L2 operational SOC teams Vendor management Open and drive high-priority technical support cases with CyberArk and Qualifications & SkillsRequired Experience8+ years in cybersecurity infrastructure engineering.4+ years of hands-on L3 support for CyberArk core components.2+ years implementing ZTNA architectures (Netskope preferred).Technical ProficienciesProtocols: SAML 2.0, OIDC, RADIUS, LDAP, TCP/IP, TLS.OS: Windows Server administration, Linux/Unix system hardening.Cloud: AWS or Azure enterprise networking integration.Certifications (Highly Desired)CyberArk Certified Delivery Engineer (CDE) or Sentry.Netskope Cloud Security Professional (NCSP) or Architect.