CyberArk Architect

Bounteous

Newbury

On-site

GBP 110,000 - 150,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Bounteous is seeking a CyberArk Architect to lead solution design for a large-scale PAM migration and merger consolidation programme, delivering vault migration, identity federation, and onboarding strategy across thousands of accounts and 250+ applications against a fixed regulatory deadline.

You will own migration architecture from CyberArk v12.2 to v14.2, define staged ingestion, manage risk, and mentor engineers while ensuring TSA audit readiness.

Qualifications

  • 10+ years in Identity and Access Management
  • 5+ years in CyberArk PAM architecture and design
  • Experience migrating CyberArk versions at enterprise scale
  • Strong knowledge of SAML 2.0 and OIDC federation
  • Experience with CP/CCP credential providers and large-scale onboarding
  • Experience in regulated environments with audit evidence requirements
  • Strong client-facing communication skills

Responsibilities

  • Lead end-to-end migration architecture from CyberArk v12.2 to v14.2.
  • Design PVWA federation with Entra ID, including MFA migration strategy.
  • Define rollback, cutover waves, and TSA audit evidence.
  • Mentor CyberArk engineers and present designs to stakeholders.
  • Evaluate tooling and onboarding approaches and governance for pilots and production waves

Skills

IAM
CyberArk PAM
Enterprise migration
SAML/OIDC
Stakeholder leadership
Hands-on architecture

Tools

CyberArk PVWA
CyberArk CPM
CyberArk EPV
PSM

Job description

We are seeking a CyberArk Architect to lead solution design for a large-scale, TSA-regulated Privileged Access Management (PAM) migration and merger consolidation programme. This is a hands‑on architecture role spanning vault migration design, identity federation, and application onboarding strategy for an estate spanning thousands of accounts and 250+ dependent applications, delivered against a fixed regulatory deadline.

Key responsibilities
Migration & vault architecture
  • Design the end-to-end migration architecture from CyberArk v12.2 to v14.2, covering entity extraction (REST API primary, PACLI fallback), transformation, reconciliation, and staged loading into the target vault.
  • Define the staged-ingestion model: disabled import → CPM soft-verification → dual-run mirroring → forced rotation at cutover — ensuring no credential is exposed to a script or human during migration.
  • Own name-collision resolution, platform normalisation, and policy reconciliation rules between source and target environments.
  • Produce migration runbooks, RAID logs, and effort-sizing models across Safes, Accounts, Platforms, and Policies.
  • Lead discovery to segment the 250+ dependent applications by integration pattern (CP agent, CCP centralised, Conjur, direct SSO) — the primary driver of onboarding sequencing and timeline risk.
  • Design the CP/CCP re-onboarding approach, including AppID re-provisioning, certificate/mTLS re-issuance, and phased cutover waves.
  • Define rollback and dual-run strategy per wave, including the read-only fallback window on the source vault.
Identity federation & MFA
  • Design PVWA federation to Entra ID via SAML/OIDC, including claims mapping from Entra groups to CyberArk Vault Users and Safe membership.
  • Architect the RSA SecurID → Entra MFA migration as a re-enrolment exercise, covering Conditional Access policy design and non-web/legacy client bridging (PrivateArk, PACLI, RADIUS-dependent flows).
  • Ensure High Side / Low Side segregation is preserved across all federation and migration data flows, with no entitlement detail crossing the DMZ boundary.
Governance, compliance & stakeholder leadership
  • Own architecture decisions and trade-offs; present designs to client security, compliance, and PAM leadership for sign-off.
  • Ensure all migration and access-control designs produce audit evidence sufficient for TSA compliance reporting.
  • Evaluate and position complementary tooling (e.g. Hydden for continuous identity discovery) against native CyberArk capability.
  • Define acceptance criteria and go/no-go gates for pilot and production wave sign-off.
  • Mentor and provide technical direction to CyberArk Senior Engineers delivering the build.
Required experience & skills
  • 10+ years in Identity and Access Management, with 5+ years specifically in CyberArk PAM architecture and design.
  • Deep hands-on knowledge of CyberArk EPV, PVWA, CPM, PSM, AAM/CCP, and Vault architecture across on-prem and Privilege Cloud deployments.
  • Proven experience leading a CyberArk version migration (v10/v11/v12 → v13/v14) at enterprise scale.
  • Strong working knowledge of SAML 2.0 and OIDC federation design, including experience integrating CyberArk PVWA with an enterprise IdP (Entra ID, Okta, or equivalent).
  • Experience with credential provider architectures (CP, CCP) and application onboarding at scale (100+ application estates).
  • Familiarity with MFA migration projects (e.g. RSA SecurID to a cloud MFA/Conditional Access model).
  • Experience operating in regulated environments (financial services, telecom, or government) with formal change control and audit evidence requirements.
  • Strong client-facing communication skills; able to present architecture to both technical and executive stakeholders.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

CyberArk Architect
CyberArk Architect

Consult • Reading

Hybrid
GBP 110,000 - 160,000
CyberArk Architect
CyberArk Architect

Bounteous • Greater London

On-site
GBP 120,000 - 185,000
CyberArk PAM Architect: Enterprise Migration & Federation
CyberArk PAM Architect: Enterprise Migration & Federation

Bounteous • Newbury

On-site
GBP 110,000 - 150,000
CyberArk PAM Architect: Enterprise Migration Lead
CyberArk PAM Architect: Enterprise Migration Lead

Bounteous • Greater London

On-site
GBP 120,000 - 185,000
CyberArk SME
CyberArk SME

Project Global Limited • Wokingham

On-site
GBP 92,000 - 148,000
CyberArk Engineer
CyberArk Engineer

Eames Consulting Group • Greater London

Hybrid
GBP 92,000 - 148,000
Senior CyberArk PAM Architect — Vault Migration Lead
Senior CyberArk PAM Architect — Vault Migration Lead

Consult • Reading

Hybrid
GBP 110,000 - 160,000
CyberArk Engineer
CyberArk Engineer

Addition • City of Edinburgh

On-site
GBP 70,000 - 95,000
CyberArk Implementation Engineer / PAM Engineer
CyberArk Implementation Engineer / PAM Engineer

Scot Lewis Associates • Greater London

Hybrid
GBP 80,000 - 134,000
CyberArk Security Engineer
CyberArk Security Engineer

MM International, LLC • Greater London

On-site
GBP 70,000 - 110,000