Cybersecurity Architect (CyberArk)

NEWTONE CONSULTING PTE. LTD.

Singapore

On-site

SGD 120,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

NEWTONE CONSULTING PTE. LTD. is seeking an experienced CyberArk PAM architect to design, implement, and continuously improve privileged access controls across Windows, UNIX, databases, and cloud platforms.

You will own the enterprise CyberArk architecture, enforce least-privilege policies, and automate PAM workflows using PowerShell and Python. Join a team focused on high availability, monitoring, and governance of privileged credentials, with expertise in Conjur and cloud IAM integrations.

Qualifications

  • Minimum of 8 years of experience as a security professional.
  • Bachelor's degree in Computer Science, Information Security, or a related field (Master's preferred).
  • Hands-on experience architecting, deploying, and operating CyberArk PAS (Vault, CPM, PSM, PVWA) at an enterprise scale.
  • L3-level expertise in Conjur, including policy-as-code (CPL/HCL), secret rotation, dynamic secrets, and Kubernetes integration.
  • Deep expertise in CyberArk Core PAS components and Privileged Threat Analytics.
  • Strong knowledge of Windows/UNIX/Linux authentication mechanisms, Kerberos, LDAP/AD, SSH, and database authentication.
  • Experience integrating CyberArk with SSO/IdP solutions (SAML, OIDC, AD).
  • Proficiency in PowerShell, Python, and CyberArk REST API for automation.
  • Familiarity with cloud providers (AWS Secrets Manager, Azure Key Vault) and Hybrid-IAM environments.
  • Solid understanding of Zero-Trust concepts for privileged access.
  • Excellent interpersonal and communication skills; ability to handle high‑pressure situations and collaborate with stakeholders.
  • Preferred certifications: CyberArk Certified Defender (CCD), Secrets Manager (Conjur).

Responsibilities

  • Define and own the enterprise-wide CyberArk architecture, including Vault, CPM, PSM, PVWA, and Conjur, to support technical accounts inventory.
  • Design and enforce privileged-access policies (least-privilege, separation-of-duties, time-bound access) across Windows, Linux, UNIX, databases, and cloud platforms (AWS, Azure, GCP).
  • Provide high-availability support for CyberArk, establishing robust monitoring, incident-response, and disaster-recovery processes.
  • Drive the secret-management lifecycle, including automatic password rotation, SSH key management, API-credential vaulting, and on-demand retrieval.
  • Partner with engineering, application, and cloud teams to embed secure identity controls into new service launches, migrations, or platform upgrades.
  • Automate PAM processes using PowerShell, Python, and CyberArk REST APIs.
  • Evaluate emerging PAM technologies and build business cases for adoption.
  • Collaborate with DevSecOps, Cloud, and Application teams to embed privileged-access controls into CI/CD pipelines and cloud-native workloads.

Skills

CyberArk PAS
Conjur
PowerShell
Python
CyberArk REST API
SSO/IdP
Kubernetes integration
Policy-as-code
Secret rotation
Dynamic secrets
Zero-Trust
Windows authentication
UNIX/Linux authentication
Cloud IAM
LDAP/AD

Education

Bachelor's degree in CS/InfoSec

Tools

AWS Secrets Manager
Azure Key Vault
CyberArk PVWA

Job description

Summary:

Design, implement, and continuously improve CyberArk vault and Privileged Access Management (PAM) solutions to secure privileged credentials and reduce risks such as credential theft, insider abuse, and lateral movement. Ensure high availability, monitoring, and governance of all privileged access across enterprise environments, including Windows, Linux, UNIX, databases, and cloud platforms.

Responsibilities:
  • Define and own the enterprise-wide CyberArk architecture, including Vault, CPM, PSM, PVWA, and Conjur, to support technical accounts inventory.
  • Design and enforce privileged-access policies (least-privilege, separation-of-duties, time-bound access) across Windows, Linux, UNIX, databases, and cloud platforms (AWS, Azure, GCP).
  • Provide high-availability support for CyberArk, establishing robust monitoring, incident-response, and disaster-recovery processes.
  • Drive the secret-management lifecycle, including automatic password rotation, SSH key management, API-credential vaulting, and on-demand retrieval.
  • Partner with engineering, application, and cloud teams to embed secure identity controls into new service launches, migrations, or platform upgrades.
  • Automate PAM processes using PowerShell, Python, and CyberArk REST APIs.
  • Evaluate emerging PAM technologies and build business cases for adoption.
  • Collaborate with DevSecOps, Cloud, and Application teams to embed privileged-access controls into CI/CD pipelines and cloud-native workloads.
Qualifications/Requirements:
  • Minimum of 8 years of experience as a security professional.
  • Bachelor's degree in Computer Science, Information Security, or a related field (Master's preferred).
  • Hands-on experience architecting, deploying, and operating CyberArk PAS (Vault, CPM, PSM, PVWA) at an enterprise scale.
  • L3-level expertise in Conjur, including policy-as-code (CPL/HCL), secret rotation, dynamic secrets, and Kubernetes integration.
  • Deep expertise in CyberArk Core PAS components and Privileged Threat Analytics.
  • Strong knowledge of Windows/UNIX/Linux authentication mechanisms, Kerberos, LDAP/AD, SSH, and database authentication.
  • Experience integrating CyberArk with SSO/IdP solutions (SAML, OIDC, AD).
  • Proficiency in PowerShell, Python, and CyberArk REST API for automation.
  • Familiarity with cloud providers (AWS Secrets Manager, Azure Key Vault) and Hybrid-IAM environments.
  • Solid understanding of Zero-Trust concepts for privileged access.
  • Excellent interpersonal and communication skills; ability to handle high‑pressure situations and collaborate with stakeholders.
  • Preferred certifications: CyberArk Certified Defender (CCD), Secrets Manager (Conjur).
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Architect
Cybersecurity Architect

WE-PLUS PTE. LTD. • Singapore

On-site
SGD 180,000 - 240,000
Cybersecurity Architect (CyberArk)
Cybersecurity Architect (CyberArk)

Argyll Scott • Singapore

On-site
SGD 180,000 - 260,000
Associate, Cyberark Engineer, Information Security Services, Group Technology
Associate, Cyberark Engineer, Information Security Services, Group Technology

DBS Bank • Singapore

On-site
SGD 90,000 - 150,000
Cybersecurity Architect(Vault / CPM / PSM / PVWA / PowerShell / Python)
Cybersecurity Architect(Vault / CPM / PSM / PVWA / PowerShell / Python)

Maltem Asia-Pacific • Singapore

On-site
SGD 180,000 - 240,000
Cybersecurity Operations and Support Engineer (CyberArk)
Cybersecurity Operations and Support Engineer (CyberArk)

Ensign InfoSecurity • Singapore

Hybrid
SGD 90,000 - 130,000
CyberArk PAM Architect – Enterprise Vault & Automation
CyberArk PAM Architect – Enterprise Vault & Automation

NEWTONE CONSULTING PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Security Engineer
Security Engineer

Fujitsu Careers • Singapore

On-site
SGD 90,000 - 130,000
SL2495 - Privileged Access Management Security Officer
SL2495 - Privileged Access Management Security Officer

FPT Asia Pacific Pte Ltd • Singapore

On-site
SGD 90,000 - 150,000
CyberArk PAM Architect - APAC IAM & Privileged Access
CyberArk PAM Architect - APAC IAM & Privileged Access

WE-PLUS PTE. LTD. • Singapore

On-site
SGD 180,000 - 240,000
CyberArk PAM Architect – Zero Trust & Conjur Lead (APAC)
CyberArk PAM Architect – Zero Trust & Conjur Lead (APAC)

Argyll Scott • Singapore

On-site
SGD 180,000 - 260,000