CyberArk/Azure Privileged Access Engineer

Microgreen Technologies LLC

Montreal (administrative region)

Hybrid

CAD 171,000 - 228,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Microgreen Technologies LLC is seeking a hands-on Senior Privileged Access Engineer to design, configure, and troubleshoot CyberArk in a large Microsoft cloud environment. The role blends PAM, identity, and endpoint management, with hands-on execution and architecture input.

Location is Montreal or Alpharetta with three days per week onsite; occasional remote work may be considered. You will implement SIA, PSM, EPM, and CPM components and drive secure access across Windows 365 and Azure.

Qualifications

  • Strong hands-on CyberArk experience including PAS/Privilege Cloud, PSM, EPM, CPM/Vault, and SIA.
  • Solid Azure security knowledge: Entra ID, PIM, Conditional Access, Managed Identities, Key Vault, Azure Monitor, Windows 365, Intune, Graph.
  • Understanding PAM concepts, endpoint security, and Intune-based endpoint management.
  • Experience operating in large-scale enterprise environments.

Responsibilities

  • Design, configure, integrate, and troubleshoot CyberArk privileged access in Microsoft cloud environments.
  • Implement CyberArk Secure Infrastructure Access/Privileged Session Management and Zero Standing Privilege patterns for Windows endpoints.
  • Engineer integrations with Microsoft Entra ID including CA, MFA, and PIM.
  • Design and implement secure access paths for Windows 365 and Azure-hosted Windows environments.
  • Configure CyberArk EPM for least-privilege application and task elevation, approved/JIT workflows, endpoint policies, and coexistence with Intune.
  • Define and implement privileged-account lifecycle controls across CPM/SIA, Windows LAPS, EPM, Intune, and automation mechanisms.
  • Build and support ITSM/CMDB integrations via CyberArk APIs for access control.
  • Implement privileged-session monitoring and audit capabilities with CyberArk and Azure logging.
  • Develop PowerShell and API-based automation, tooling, runbooks, monitoring, and troubleshooting procedures.
  • Advise on architecture/design for extending PAM into cloud environments at enterprise scale.

Skills

CyberArk PAM
Privilege Cloud
PSM
EPM
CPM Vault
SIA
Entra ID
PIM
Conditional Access
Windows LAPS
Intune
Windows 365
Microsoft Graph
PowerShell
CyberArk APIs
Azure CLI
REST APIs

Tools

PowerShell
CyberArk APIs
Azure CLI
REST APIs

Job description

Role: CyberArk/Azure Privileged Access Engineer
Location: Montreal or Alpharetta, 3 days/week onsite
Overview

We're looking for a hands-on Senior Privileged Access Engineer to design, configure, integrate, and troubleshoot CyberArk privileged access capabilities within a large-scale, enterprise Microsoft cloud environment. This role sits at the intersection of PAM, identity, and endpoint management, and will play a key part in advising on architecture/design while also directly executing the engineering work --- this is not a purely advisory or purely hands-off role.

Key Responsibilities
  • Design, configure, integrate, and troubleshoot CyberArk privileged access capabilities, including SIA, PAS/Privilege Cloud, PSM, EPM, and CPM/Vault components, along with privileged-session controls in Microsoft cloud environments.
  • Implement CyberArk Secure Infrastructure Access/Privileged Session Management and Zero Standing Privilege patterns for Windows endpoints --- including ephemeraadministrative access, account provisioning, connector deployment, session brokering, credential rotation, revocation, and recovery workflows.
  • Engineer integrations with Microsoft Entra ID, including Conditional Access, phishing-resistant MFA, privileged identity separation, service principals/workload identities, and appropriate use of Entra Privileged Identity Management (PIM).
  • Design and implement secure access paths for Windows 365 and Azure-hosted Windows environments, including private connectivity, firewall requirements, connector placement, RDP/SMB/RPC dependencies, regional resiliency, and network troubleshooting.
  • Configure CyberArk EPM for least-privilege application and task elevation, approved/JIT workflows, endpoint policies, local group controls, and coexistence with Microsoft Intune, Windows LAPS, Entra PIM, and other endpoint-management technologies.
  • Define and implement privileged-account lifecycle controls with clear ownership across CyberArk CPM/SIA, Windows LAPS, EPM, Intune, and other automation mechanisms --- ensuring password rotation, local-group membership, and privilege activation controls don't conflict with one another.
  • Build and support integrations with ITSM, CMDB, identity, and workflow platforms using CyberArk APIs, so privileged access can be restricted by user, device, business approval, requested action, scope, and duration.
  • Implement privileged-session monitoring and audit capabilities, including CyberArk session recording, audit APIs, Azure-native logging, and integration with enterprise security monitoring and evidence-retention platforms.
  • Perform hands-on validation of privilege activation, expiration, emergency revocation, disconnected-session behavior, ephemera-account cleanup, LAPS recovery, connector failures, resiliency, and privileged-session controls.
  • Develop PowerShell and API-based automation, deployment tooling, configuration-as-code, operational runbooks, monitoring, health checks, and troubleshooting procedures.
  • Advise on architecture and design decisions for extending privileged access management into cloud environments at enterprise scale, in addition to hands-on implementation.
Required Skills & Experience
  • Strong, demonstrated hands-on CyberArk experience (PAS/Privilege Cloud, PSM, EPM, CPM/Vault, SIA).
  • Strong practical Azure and Microsoft security knowledge, including Entra ID, PIM, Conditional Access, Managed Identities, service principals, Key Vault, Azure networking, Azure Monitor, Windows 365, Intune, Windows LAPS, and Microsoft Graph.
  • Solid understanding of PAM concepts, endpoint security, and Intune-based endpoint management.
  • Experience operating in large-scale enterprise environments.
Preferred Skills & Experience
  • Deep Windows security experience, including local accounts/groups, Windows authentication, RDP, WinRM/PowerShell remoting, UAC, credential protections, and endpoint hardening.
  • Experience with large-enterprise CyberArk implementations.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Privileged Access Engineer
Privileged Access Engineer

Tekgence Inc • Montreal (administrative region)

Hybrid
CAD 90,000 - 120,000
Security Engineer
Security Engineer

LanceSoft, Inc. • Montreal

On-site
CAD 198,000 - 242,000
CyberArk EPAM Consultant
CyberArk EPAM Consultant

Astra-North Infoteck Inc. ~ Conquering today’s challenges, achieving tomorrow’s vision! • Montreal

On-site
CAD 75,768 - 82,656
Cloud and Security Administrator
Cloud and Security Administrator

Joseph Ribkoff Inc. • Dorval

Hybrid
CAD 110,000 - 150,000
PAM Analyst
PAM Analyst

Insight Global • Canada

On-site
CAD 75,768 - 89,544
Senior Cybersecurity Specialist
Senior Cybersecurity Specialist

STACK IT Recruitment • Burlington

On-site
CAD 154,000 - 181,000
Paid vacation and personal days
Annual bonus
Cybersecurity Technical Lead - CrowdStrike, Proofpoint, MDE, MDI, and MDCA
Cybersecurity Technical Lead - CrowdStrike, Proofpoint, MDE, MDI, and MDCA

Astra-North Infoteck Inc. ~ Conquering today’s challenges, achieving tomorrow’s vision! • Calgary

On-site
CAD 120,000 - 160,000
Azure Specialist
Azure Specialist

TEEMA • Montreal (administrative region)

On-site
CAD 110,000 - 150,000
Sr. Cyber Security Analyst
Sr. Cyber Security Analyst

10 Percent Recruiting Ltd. • Canada

Hybrid
CAD 110,000 - 140,000
Azure 365 Administrator
Azure 365 Administrator

PACT • Mississauga

On-site
CAD 90,000 - 120,000