CyberArk Engineer @ Mumbai

Quess IT Solutions

Mumbai

On-site

INR 1,800,000 - 3,000,000

Full time

7 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Quess IT Solutions is seeking an L2 PIM/PAM Engineer to manage day-to-day Privileged Access Management operations across major PAM platforms including CyberArk, BeyondTrust, and Microsoft Entra PIM. You will handle onboarding, incident troubleshooting, and ensure strict zero-trust and least-privilege controls.

This role emphasizes audits, policy validation, and collaboration with IT and security teams to maintain credential rotation, MFA enforcement, and compliance with CIS/ISO standards.

Qualifications

  • Proficient with at least one enterprise PAM tool (CyberArk/BeyondTrust/Delinea) and Cloud PIM (MS Entra ID PIM).
  • Experience with Windows Server, Linux, SSH, and AD/GPOs desirable.
  • Basic scripting (PowerShell/Bash/Python) for automation tasks.

Responsibilities

  • Handle day-2 PAM operations, onboarding, and incident resolution for PAM components.
  • Manage JIT access, time-bound approvals, and role activation in Entra PIM and PAM solutions.
  • Monitor health checks for PAM services and coordinate with support teams for outages.
  • Configure and maintain custom plugins, policies, and connection components.

Skills

PAM operations
Scripting
Zero Trust
Least Privilege
MFA
Incident management

Tools

CyberArk PAS/Privilege Cloud
BeyondTrust Password Safe
Delinea/Thycotic
Microsoft Entra ID PIM

Job description

The L2 PIM/PAM Engineer is responsible for day-to-day administration, onboarding, and incident troubleshooting across enterprise Privileged Access Management platforms (e.g., CyberArk, BeyondTrust, Microsoft Entra PIM). In addition to operational maintenance, this role actively validates, audits, and assesses technical controls to ensure privileged accounts adhere to strict zero-trust and least-privilege standards.

Key Responsibilities
Implementation & Support (L2 Operations)
  • Handle Day-2 operations, ticket escalations, and incident resolution for PAM components (Safe management, account onboarding, CPM/PSM failures, and policy errors).
  • Onboard target systems (Windows, Linux, databases, network devices, and cloud infrastructure) into PAM vaults with automated credential rotation.
  • Manage Just-In-Time (JIT) access requests, time-bound approvals, and role-activation workflows in Microsoft Entra PIM and PAM solutions.
  • Monitor health checks for core PAM services (Vaults, Proxies, Discovery agents, Session Recording servers) and coordinate with vendor support or L3 teams for complex outages.
  • Configure, test, and maintain custom plugins, CPM platform management policies, and connection components.
Technical Controls Assessment & Validation
  • Conduct routine technical assessments to verify that credential auto-rotation, check-in/check-out policies, and password complexity controls function across all onboarded targets.
  • Validate that Privileged Session Monitoring (PSM) and keylogging controls capture and index administrative sessions without bypassing.
  • Audit Entra PIM policies: verify mandatory MFA triggers, justification requirements, approval chains, and maximum activation duration limits.
  • Perform discovery scans to identify unmanaged privileged accounts, service accounts, and shadow admins across Active Directory, cloud, and hybrid environments.
  • Generate compliance evidence and remediate gaps aligned with audit standards (CIS Benchmarks, ISO 27001, SOC 2).
Required Skills & Qualifications
  • Core Platforms: Hands-on experience with at least one enterprise PAM tool (CyberArk PAS/Privilege Cloud, BeyondTrust Password Safe, Delinea/Thycotic) and Cloud PIM (Microsoft Entra ID PIM).
  • Operating Systems & Networking: Working knowledge of Windows Server (Active Directory, Kerberos, GPOs), Linux/Unix (SSH, PAM modules, sudoers), and networking fundamentals (firewall ports, DNS, RDP, SSH).
  • Scripting: Basic PowerShell, Bash, or Python scripting skills to assist with automated onboarding, discovery parsing, and API calls.
  • Security Principles: Solid understanding of Least Privilege, Zero Trust, MFA, Session Isolation, and Break-Glass procedures.
Preferred Certifications
  • CyberArk Defender (PAM-DEF) or Sentry (PAM-SEN)
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

CyberArk Security Engineer(PAM or EPM)
CyberArk Security Engineer(PAM or EPM)

Alike Thoughts • India

On-site
INR 1,800,000 - 2,800,000
CyberArk Security Engineer
CyberArk Security Engineer

Delta Tech Hub • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Opening for Cyberark Engineer @ Mumbai
Opening for Cyberark Engineer @ Mumbai

Quess IT Solutions • Mumbai

On-site
INR 1,200,000 - 2,400,000
CyberArk core Implementaion-L3/L4
CyberArk core Implementaion-L3/L4

Capgemini • Hyderabad, Chennai District, Bengaluru

Hybrid
INR 1,500,000 - 3,000,000
Cyber Security Engineer
Cyber Security Engineer

Acesoft Labs • Bengaluru

On-site
INR 1,500,000 - 3,000,000
CyberArk Engineer
CyberArk Engineer

JUARA IT SOLUTIONS • Chennai District

On-site
INR 1,500,000 - 2,300,000
CyberArk EPM
CyberArk Secrets Manager
CyberArk Identity
+7
Cyberark Engineer
Cyberark Engineer

Cloudxtreme • Bengaluru

On-site
INR 1,200,000 - 1,800,000
PAM Automation Engineer - Remote - Contract opportunity
PAM Automation Engineer - Remote - Contract opportunity

World Wide Technology • India

On-site
INR 1,200,000 - 2,000,000
CS PAM Analyst- Hyderabad
CS PAM Analyst- Hyderabad

Cloudxtreme • Hyderabad

On-site
INR 800,000 - 1,500,000
DTICI_IAM_CYBERARK_T7
DTICI_IAM_CYBERARK_T7

Daimler Trucks North America LLC • Bengaluru

On-site
INR 1,800,000 - 2,400,000