Haden Grey is hiring a CyberArk Engineer into its Identity and Access Management practice. This is a hands-on delivery role. You will implement, configure, and operate CyberArk Privileged Access Management platforms for enterprise clients across healthcare, public sector, and commercial industries, working on everything from greenfield deployments and version upgrades to privileged account onboarding at scale and ongoing managed services support.
You will report to the practice lead and work alongside solution architects, project managers, and client security teams. On most engagements you will own the technical delivery of your assigned workstream end to end, including the documentation that goes with it. Expect to spend the majority of your week in the product rather than in meetings.
Key Responsibilities
- Install, configure, and upgrade core CyberArk PAM components including the Digital Vault, Password Vault Web Access, Central Policy Manager, and Privileged Session Manager, including PSM for SSH.
- Onboard privileged accounts at scale using discovery, bulk upload, and automated onboarding rules, covering Windows and Linux administrator accounts, service accounts, database credentials, network device accounts, and cloud console access.
- Build and tune CPM plugins and PSM connection components for applications not covered by out-of-the-box platform support.
- Configure Safes, platform policies, master policy settings, and access controls that align with client least-privilege and segregation-of-duty requirements.
- Implement and support CyberArk Endpoint Privilege Manager and Secrets Manager or Conjur where those products are in engagement scope.
- Integrate CyberArk with SIEM, ITSM, multi-factor authentication, and identity governance platforms, and configure LDAP, Active Directory, and SAML authentication.
- Troubleshoot vault replication, failover, session recording, and credential rotation failures, and perform root cause analysis on production incidents.
- Support disaster recovery design, failover testing, and documented recovery procedures.
- Produce design documents, runbooks, test plans, and as-built documentation that meet Haden Grey delivery standards.
- Lead client-facing working sessions, status calls, and knowledge transfer for handoff to managed services or the client operations team.
- Track time against project tasks and track scope, schedule, or technical risk to the engagement lead early.
Required Qualifications
Technical Experience
- Three to five years of hands-on engineering experience with CyberArk PAM in production enterprise environments.
- Demonstrated working experience with the Digital Vault, PVWA, CPM, and PSM.
- Experience onboarding privileged accounts at scale, including account discovery and rule-based automated onboarding.
- Windows Server administration and Active Directory fundamentals, including Group Policy, DNS, certificate services, and service account management.
- Working Linux and Unix administration skills, including SSH key management.
- Scripting for automation. PowerShell is required; Python and experience with the CyberArk REST API are a strong plus.
- Understanding of PKI, TLS certificate lifecycle management, and server hardening standards such as CIS Benchmarks.
- Networking fundamentals as they affect PAM deployments, including firewall rules, load balancing, and segmented or DMZ architectures.
Professional Skills
- Clear technical writing. Documentation is a graded deliverable on every engagement, not an afterthought.
- Comfort working directly with client stakeholders, including security leadership and system owners who do not work in PAM every day.
- Ability to carry multiple concurrent client engagements and manage your own time against them.
- Judgment about when to solve a problem independently and when to escal
- United States citizenship is required. Several of the client environments this role supports restrict system access to U.S. citizens, and visa sponsorship is not available for this position.
- Ability to pass client-required background screening and, where applicable, agency clearance processes.
Preferred Qualifications
- CyberArk Defender or Sentry certification. CDE certification is strongly preferred.
- Experience with Endpoint Privilege Manager, Secrets Manager, Conjur, or Privilege Cloud.
- Prior experience delivering in a professional services or consulting model.
- Exposure to adjacent identity platforms such as SailPoint, Saviynt, Okta, or Ping.
- Privileged access work in AWS, Azure, or Google Cloud environments.
- Experience supporting regulated environments subject to HIPAA, CMS, CJIS, PCI DSS, or FedRAMP requirements.
Education and Certifications
Bachelor degree in computer science, information systems, or a related field, or equivalent professional experience. Haden Grey weighs demonstrated delivery experience more heavily than academic credentials.
An active CyberArk certification is expected, or the willingness to earn one within the first six months. Haden Grey funds exam fees.