CyberArk Architect-Secrets Manager / Conjur (Contract)
Location: USA, remote
Employment Type: Contract, Immediate Start through March 2027
What You'll Do:
- Design and implement enterprise CyberArk PAM, Secrets Manager, and Conjur On-Prem solutions.
- Integrate Secrets Manager/Conjur with existing CyberArk PAM/Vault environments without redesigning the current vault architecture.
- Define PAM and secrets management architecture, security controls, access models, and implementation roadmaps.
- Configure RBAC, policies, credential rotation, Safes, CPM, and secret retrieval workflows.
- Integrate Secrets Manager/Conjur with OpenShift/Kubernetes workloads, including service accounts, namespaces, workload identities, and manifests.
- Support GitLab CI/CD secret injection and runtime secret retrieval.
- Design and implement HA/DR, TLS/certificates, audit logging, backup/recovery, and monitoring.
- Develop secure application onboarding and secret management patterns.
- Work with infrastructure and security teams across networking, DNS, firewalls, load balancers, Linux/server environments, and enterprise authentication.
- Lead technical discussions, troubleshoot complex issues, and provide guidance to engineers and clients.
Who We're Looking For:
- 8+ years of experience in PAM, cybersecurity, identity, or security architecture.
- Bachelor's or Master's Degree in Computer Science, Computer Engineering, Management Information Systems, Cybersecurity, or equivalent experience
- Strong hands-on experience with CyberArk PAM/Vault and CyberArk Secrets Manager.
- Experience with Conjur On-Prem deployment, configuration, and integration.
- Experience integrating secrets management with OpenShift/Kubernetes and GitLab CI/CD.
- Strong knowledge of RBAC, credential rotation, Safes, CPM, policies, secret retrieval, and privileged access controls.
- Experience with HA/DR, TLS/certificates, audit logging, networking, and security hardening.
- Strong troubleshooting, communication, and client-facing skills.
- Ability to design solutions while working independently and collaboratively
Preferred Qualifications:
- CyberArk Sentry – Secrets Manager (SECRET-SEN) or CyberArk CDE – Secrets certification is strongly preferred.
- Additional CyberArk certifications, such as CDE – PAM, Sentry PAM, or Defender.
- DevSecOps, APIs, automation, Infrastructure as Code, and CI/CD experience.
- Experience with container security and automated application onboarding.
- Knowledge of security/compliance frameworks and vulnerability management.
- Programming/scripting experience such as Python, Java, or PowerShell.