CyberArk Architect

Consult

Reading

Hybrid

GBP 110,000 - 160,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Consult seeks an senior CyberArk architect to lead identity and access management transformations in Reading or Newbury. You will design end-to-end vault migrations, manage phased cutovers, and ensure secure, auditable changes across on-prem and cloud deployments.

Responsibilities include federation design to Entra ID, MFA migrations, and governance across regulatory environments. You will mentor engineers and liaise with executives to drive secure PAM programs.

Qualifications

  • 15+ years in Identity and Access Management, CyberArk PAM architecture.
  • Deep hands-on knowledge of CyberArk EPV, PVWA, CPM, PSM, AAM/CCP, Vault across on-prem and Privilege Cloud deployments.
  • Proven experience migrating CyberArk versions enterprise-scale (v10/v11/v12 to v13/v14).
  • Strong working knowledge of SAML 2.0 and OIDC federation design with enterprise IdP integrations.
  • Experience with credential provider architectures (CP, CCP) and on-boarding 100+ applications.
  • Familiarity with MFA migration projects (RSA SecurID to cloud MFA/CA).
  • Experience in regulated environments with change control and audit evidence requirements.
  • Strong client-facing communication and executive-level presentations.

Responsibilities

  • Design end-to-end migration architecture for CyberArk Vault, including extraction, transformation and staged loading.
  • Define staged-ingestion model with disabled import → CPM soft-verification → dual-run mirroring → cutover rotation.
  • Produce migration runbooks, RAID logs, and effort-sizing models across Safes, Accounts, Platforms, and Policies.
  • Lead discovery to segment dependent applications by integration pattern (CP agent, CCP, Conjur, direct SSO).
  • Design CP/CCP re-onboarding, AppID re-provisioning and certificate re-issuance.
  • Define rollback and dual-run strategy with read-only fallback on source vault.
  • Design PVWA federation to Entra ID via SAML/OIDC with claims mapping.
  • Architect MFA migration from RSA SecurID to Entra MFA with CA policies.
  • Ensure governance and audit evidence for TSA compliance reporting, and mentor CyberArk engineers.

Skills

CyberArk PAM architecture
Identity & Access Management
CyberArk components
Enterprise migration
SAML 2.0 & OIDC
Entra ID federation
App onboarding at scale
MFA migration
Regulated environments
Stakeholder communication

Tools

CyberArk EPV
PVWA
CPM
PSM
AAM/CCP
Vault architecture
SAML/OIDC federation
Entra ID/Okta
MFA tooling
Hydden (identity discovery)

Job description

Work Location: Reading or Newbury (hybrid 2 to 3 days a week)

This is an immediate and urgent requirement hence immediate joiners preferred.

Required experience & skills

  • 15+ years in Identity and Access Management, specifically in CyberArk PAM architecture and design.
  • Deep hands-on knowledge of CyberArk EPV, PVWA, CPM, PSM, AAM/CCP, and Vault architecture across on-prem and Privilege Cloud deployments.
  • Proven experience leading a CyberArk version migration (v10/v11/v12 → v13/v14) at enterprise scale.
  • Strong working knowledge of SAML 2.0 and OIDC federation design, including experience integrating CyberArk PVWA with an enterprise IdP (Entra ID, Okta, or equivalent).
  • Experience with credential provider architectures (CP, CCP) and application onboarding at scale (100+ application estates).
  • Familiarity with MFA migration projects (e.g. RSA SecurID to a cloud MFA/Conditional Access model).
  • Experience operating in regulated environments (financial services, telecom, or government) with formal change control and audit evidence requirements.
  • Strong client-facing communication skills; able to present architecture to both technical and executive stakeholders.

Migration & vault architecture

  • Design the end-to-end migration architecture from CyberArk , covering entity extraction (REST API primary, PACLI fallback), transformation, reconciliation, and staged loading into the target vault.
  • Define the staged-ingestion model: disabled import → CPM soft-verification → dual-run mirroring → forced rotation at cutover — ensuring no credential is exposed to a script or human during migration.
  • Produce migration runbooks, RAID logs, and effort-sizing models across Safes, Accounts, Platforms, and Policies.
  • Lead discovery to segment the dependent applications by integration pattern (CP agent, CCP centralized, Conjur, direct SSO) — the primary driver of onboarding sequencing and timeline risk.
  • Design the CP/CCP re-onboarding approach, including AppID re-provisioning, certificate/mTLS re-issuance, and phased cutover waves.
  • Define rollback and dual-run strategy per wave, including the read-only fallback window on the source vault.

Identity federation & MFA

  • Design PVWA federation to Entra ID via SAML/OIDC, including claims mapping from Entra groups to CyberArk Vault Users and Safe membership.
  • Architect the RSA SecurID → Entra MFA migration as a re-enrolment exercise, covering Conditional Access policy design and non-web/legacy client bridging (PrivateArk, PACLI, RADIUS-dependent flows).
  • Ensure High Side / Low Side segregation is preserved across all federation and migration data flows, with no entitlement detail crossing the DMZ boundary.

Governance, compliance & stakeholder leadership

  • Own architecture decisions and trade-offs; present designs to client security, compliance, and PAM leadership for sign-off.
  • Ensure all migration and access-control designs produce audit evidence sufficient for TSA compliance reporting.
  • Evaluate and position complementary tooling (e.g. Hydden for continuous identity discovery) against native CyberArk capability.
  • Define acceptance criteria and go/no-go gates for pilot and production wave sign-off.
  • Mentor and provide technical direction to CyberArk Senior Engineers delivering the build.
Required Skills

cyberark identity and access management pam architecture vault migration saml oidc enterprise security

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

CyberArk Architect
CyberArk Architect

Bounteous • Newbury

On-site
GBP 110,000 - 150,000
CyberArk Architect
CyberArk Architect

Bounteous • Greater London

On-site
GBP 120,000 - 185,000
Senior CyberArk PAM Architect — Vault Migration Lead
Senior CyberArk PAM Architect — Vault Migration Lead

Consult • Reading

Hybrid
GBP 110,000 - 160,000
CyberArk Engineer
CyberArk Engineer

Eames Consulting Group • Greater London

Hybrid
GBP 92,000 - 148,000
CyberArk SME
CyberArk SME

Project Global Limited • Wokingham

On-site
GBP 92,000 - 148,000
CyberArk PAM Architect: Enterprise Migration Lead
CyberArk PAM Architect: Enterprise Migration Lead

Bounteous • Greater London

On-site
GBP 120,000 - 185,000
CyberArk PAM Architect: Enterprise Migration & Federation
CyberArk PAM Architect: Enterprise Migration & Federation

Bounteous • Newbury

On-site
GBP 110,000 - 150,000
CyberArk Implementation Engineer / PAM Engineer
CyberArk Implementation Engineer / PAM Engineer

Scot Lewis Associates • Greater London

Hybrid
GBP 80,000 - 134,000
CyberArk Security Engineer
CyberArk Security Engineer

MM International, LLC • Greater London

On-site
GBP 70,000 - 110,000
CyberArk Engineer
CyberArk Engineer

Addition • City of Edinburgh

On-site
GBP 70,000 - 95,000