Cybersecurity Manager

Planet Pharma

Bridgewater (MA)

On-site

USD 99,000 - 113,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this recruiter — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Planet Pharma is seeking an experienced Senior CyberArk PAM Implementation Engineer to assess, optimize, and enhance our CyberArk PAM environment. The role covers Cloud/SaaS, SIA, Just-in-Time privileged access, application onboarding, password rotation, and secrets management across Windows and Linux environments.

The engineer will define current-state architecture, propose a target-state design, and lead or support the roadmap execution with hands-on implementation and collaboration with

Qualifications

  • Demonstrated hands-on CyberArk PAM implementation and engineering experience.
  • Experience with CyberArk Cloud/SaaS and SIA deployments.
  • Ability to design and execute JIT privileged access workflows.
  • Strong skills in password rotation, session management, and secrets management.
  • Proficiency with automation (PowerShell, Python, REST APIs) to improve processes.

Responsibilities

  • Current-state CyberArk architecture assessment and health check.
  • Develop target-state CyberArk architecture and implementation roadmap.
  • Create PAM adoption plan and prioritized onboarding for systems and apps.
  • Design SIA integration and RBAC-based access controls for infrastructure.
  • Define JIT workflows: request, elevate, expiration, revocation.

Skills

CyberArk PAM
CyberArk Cloud
SIA
JIT Access
Password Rotation
Privileged Sessions
Secrets Management
Automation
Onboarding Apps
PSM/SSH

Job description

Job Summary

We are seeking an experienced Senior CyberArk PAM Implementation Engineer to assess, optimize, and enhance our existing CyberArk Privileged Access Management environment. The ideal candidate will have strong hands-on experience with CyberArk Cloud/SaaS and the ability to perform a comprehensive assessment of the existing PAM implementation, identify security and operational gaps, and develop a strategic roadmap for utilizing CyberArk capabilities to their fullest extent.

This role requires deep expertise in CyberArk PAM and Endpoint Privilege Manager (EPM), Secure Infrastructure Access (SIA), Just-in-Time (JIT) privileged access, application onboarding, password rotation, privileged session access, secrets management, and cloud integrations. The successful candidate will define the current-state architecture, recommend a target-state design based on CyberArk and industry best practices, and lead or support execution of the resulting roadmap.

Key Responsibilities
1. Existing CyberArk Environment Assessment
  • Perform a comprehensive assessment of the existing CyberArk PAM environment.
  • Review the current CyberArk architecture, configuration, integrations, policies, account onboarding processes, and operational procedures.
  • Identify security gaps, implementation deficiencies, unused capabilities, technical debt, and opportunities for optimization.
  • Evaluate the effectiveness of privileged account onboarding, password rotation, session management, access controls, and privileged access workflows.
  • Assess CyberArk platform health, scalability, resilience, availability, and operational maturity.
  • Review the existing use of CyberArk Cloud capabilities and recommend improvements.
  • Develop a current-state assessment report, including findings, risks, recommendations, and remediation priorities.
2. CyberArk Strategy and Roadmap
  • Develop a strategic PAM roadmap aligned with business requirements, cybersecurity objectives, and CyberArk best practices.
  • Define a target-state CyberArk architecture and implementation plan.
  • Develop a prioritized plan to maximize adoption and utilization of CyberArk capabilities.
  • Create implementation phases, dependencies, milestones, and technical requirements.
  • Define PAM use cases and prioritize systems, accounts, applications, and user populations for onboarding.
  • Develop a PAM maturity improvement plan.
3. CyberArk Cloud / PAM Implementation

Implement and optimize CyberArk Cloud/SaaS capabilities, including:

  • Privileged account management and onboarding
  • Account discovery and lifecycle management
  • Password rotation, verification, and reconciliation
  • Privileged session management and recording
  • Privileged session monitoring
  • Application credential management
  • Secrets management
  • Privileged access request and approval workflows
  • Cloud infrastructure privileged access
  • Integration with enterprise identity and authentication platforms
4. Secure Infrastructure Access (SIA)
  • Design, implement, and optimize CyberArk Secure Infrastructure Access (SIA).
  • Enable secure, centralized access to infrastructure while minimizing exposure of privileged credentials.
  • Implement secure access workflows for Windows, Linux, cloud infrastructure, and other supported platforms.
  • Integrate SIA with enterprise identity providers and authentication mechanisms.
  • Implement role-based access controls for infrastructure access.
  • Develop standards and procedures for onboarding infrastructure to SIA.
  • Evaluate existing administrative access methods and identify opportunities to reduce direct credential exposure.
5. Just-in-Time (JIT) Privileged Access
  • Design and implement Just-in-Time (JIT) privileged access capabilities.
  • Implement time-bound and controlled privileged access and reduce standing privileges where feasible.
  • Integrate JIT workflows with identity, ITSM, cloud, and authentication platforms where appropriate.
  • Define access request, approval, elevation, expiration, and revocation workflows.
  • Develop controls for privileged access to cloud and infrastructure environments.
  • Monitor and optimize JIT access policies based on operational and security requirements.
6. Application, System, and Account Onboarding
  • Lead onboarding of applications, systems, databases, platforms, and privileged accounts into CyberArk.
  • Assess applications for password rotation, credential management, and secure access requirements.
  • Configure and implement password rotation, verification, and reconciliation.
  • Onboard service accounts and application accounts into CyberArk.
  • Work with application owners to implement credential retrieval and secure secrets consumption.
6A. CyberArk Endpoint Privilege Manager (EPM)
7. Integrations and Automation
  • Integrate CyberArk with enterprise identity and authentication platforms.
  • Integrate CyberArk with cloud platforms and infrastructure services.
  • Work with application teams to integrate applications with CyberArk secrets management capabilities.
  • Integrate CyberArk with ITSM, SIEM, monitoring, and ticketing platforms where required.
  • Develop automation for privileged account discovery, onboarding, reporting, and operational processes.
  • Use PowerShell, Python, REST APIs, and CyberArk automation capabilities to improve efficiency.
8. Standards, Governance, and Best Practices
  • Develop CyberArk architecture standards and implementation guidelines.
  • Define PAM onboarding standards and security requirements.
  • Develop SOPs and operational runbooks for CyberArk administration.
  • Define privileged account ownership and lifecycle processes.
  • Establish policies for password rotation, reconciliation, session recording, privileged access, and emergency access.
  • Develop privileged account inventory and classification standards.
  • Ensure implementation aligns with CyberArk best practices and organizational security requirements.
Technical Requirements
Required
  • CyberArk PAM and CyberArk Cloud/SaaS
  • Privileged Account Security
  • Central Policy Manager (CPM)
  • Privileged Session Manager (PSM)
  • Privileged Session Manager for SSH (PSMP), where applicable
  • Password rotation and reconciliation
  • Privileged account onboarding
  • Application account and service account management
  • Secrets management
  • CyberArk Secure Infrastructure Access (SIA)
  • Just-in-Time (JIT) privileged access
Strongly Preferred
  • CyberArk Endpoint Privilege Manager (EPM) design, implementation, policy development, deployment, and operational support
  • Privileged Threat Analytics (PTA), where applicable to the environment
  • CyberArk application access and secrets capabilities
  • AWS, Microsoft Azure, and/or Google Cloud integration
  • Kubernetes or container environments
  • DevOps and CI/CD integrations
  • ITSM and SIEM integrations
  • Hands-on experience designing, deploying, configuring, and supporting CyberArk Endpoint Privilege Manager (EPM), including policy development, application control, privilege elevation, agent rollout, and operational optimization.
Experience Requirements
  • Minimum of 5-8 years of hands-on CyberArk PAM implementation and engineering experience.
  • Demonstrated experience assessing an existing CyberArk environment and developing a remediation or enhancement roadmap.
  • Strong hands-on experience with CyberArk Cloud/SaaS.
  • Demonstrated implementation experience with CyberArk SIA.
  • Demonstrated implementation experience with Just-in-Time privileged access.
  • Experience onboarding complex applications and systems for password rotation, password reconciliation, session access, privileged session management, and secrets management.
  • Experience integrating CyberArk with enterprise applications and cloud platforms.
  • Experience migrating or transforming legacy privileged access processes into CyberArk-based workflows.
  • Strong understanding of privileged account lifecycle management.
  • Experience working with application owners, infrastructure teams, cloud teams, IAM teams, and vendors.
  • EPM operational and exception-management procedures
  • EPM application control and privilege elevation use-case catalogue
  • EPM agent deployment and phased rollout plan
  • EPM policy and baseline design
  • EPM target-state architecture and deployment strategy
  • EPM current-state assessment and maturity review
Required Deliverables
  • Current-state CyberArk architecture assessment
  • CyberArk health and configuration assessment
  • PAM maturity and gap assessment
  • Privileged account inventory and classification
  • Target-state CyberArk architecture
  • CyberArk Cloud adoption strategy
  • SIA implementation strategy
  • JIT implementation strategy
  • Application and service account onboarding framework
  • Password rotation onboarding plan
  • Session access and portal access onboarding plan
  • Prioritized remediation and implementation roadmap
  • PAM standards and operating procedures
  • Use-case catalogue
  • Integration architecture and implementation plan
  • Knowledge-transfer and operational handover documentation

EPM experience should be considered a core requirement for this role, including architecture, design, policy development, agent deployment, rollout, troubleshooting, and optimization.

Must-Have Skills for Candidate Screening
  • CyberArk PAM implementation experience
  • CyberArk Cloud/SaaS experience
  • CyberArk SIA implementation
  • JIT privileged access implementation
  • CyberArk assessment and architecture review experience
  • CPM password rotation and reconciliation
  • PSM privileged session access
  • Application and service account onboarding
  • Secrets management
  • Windows and Linux privileged access
  • PowerShell, Python, and/or API automation
  • Ability to develop a PAM roadmap and target-state architecture
Preferred Certifications
  • Relevant CyberArk Defender certification
  • Relevant CyberArk Sentry certification
  • CyberArk Cloud-related training or certifications
  • CyberArk PAM implementation or delivery credentials
  • CISSP is beneficial but not mandatory for this hands-on engineering role

Pay Range: $72-82/hr *based on experience

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CyberArk / Privileged Access Management Systems Analyst
CyberArk / Privileged Access Management Systems Analyst

STL 1st • Missouri

On-site
USD 90,000 - 130,000
Senior Technology Security Engineer (IAM)
Senior Technology Security Engineer (IAM)

Pointwest-North America • Des Moines (IA)

On-site
USD 100,000 - 130,000
PAM Lead Engineer - Remote
PAM Lead Engineer - Remote

Experian • Austin (TX)

Remote
USD 180,000 - 240,000
Great compensation package and bonus plan
Core benefits including medical, dental, vision, and matching 401K
Flexible time off including volunteer and vacation
+2
Privileged Access Management (PAM) Engineer - CyberArk Specialist | Cross-Border Banking and Ma[...]
Privileged Access Management (PAM) Engineer - CyberArk Specialist | Cross-Border Banking and Ma[...]

Techfellow Limited • Woodbridge Township (NJ)

On-site
USD 135,000 - 165,000
CyberArk Engineer
CyberArk Engineer

CBTS • Plano (TX)

On-site
USD 95,000 - 130,000
PAM Engineering Lead
PAM Engineering Lead

WTW • Minneapolis (MN)

On-site
USD 130,000 - 170,000
Health benefits
401(k) plan with company contribution
Paid time off
Principal Architect SME – CyberArk
Principal Architect SME – CyberArk

Antimony LLC • Washington

On-site
USD 160,000 - 230,000
Principal Architect SME - CyberArk
Principal Architect SME - CyberArk

Jazz Solutions Inc • Rockville (MD)

Hybrid
USD 180,000 - 240,000
Security Engineer
Security Engineer

Insight Global • United States

On-site
Medical, dental, and vision insurance
HSA, FSA, and DCFSA account options
401k retirement account access with employer matching
+1
Identity and Access Management (IAM) Senior Analyst
Identity and Access Management (IAM) Senior Analyst

Synergy Business Consulting, Inc. • Miami (FL)

Hybrid
USD 100,000 - 130,000