We're partnering with a leading organisation seeking a Senior CyberArk PAM & EPM Implementation Engineer to assess, optimise, and enhance their CyberArk Privileged Access Management environment.
This is a highly technical, hands-on role for a CyberArk specialist with deep expertise across CyberArk Cloud/SaaS, Endpoint Privilege Manager (EPM), Secure Infrastructure Access (SIA), and Just-in-Time (JIT) privileged access. The successful candidate will be responsible for evaluating the current environment, identifying security and operational improvements, defining a target-state architecture, and delivering a strategic PAM roadmap.
Key Responsibilities
- Conduct comprehensive assessments of existing CyberArk PAM environments.
- Review architecture, configurations, integrations, onboarding processes, and operational procedures.
- Identify security gaps, implementation deficiencies, technical debt, and optimisation opportunities.
- Design and implement CyberArk Cloud/SaaS solutions.
- Lead Secure Infrastructure Access (SIA) implementations and enhancements.
- Design and implement Just-in-Time (JIT) privileged access capabilities.
- Onboard privileged accounts, service accounts, applications, databases, cloud platforms, and infrastructure systems.
- Configure password rotation, reconciliation, privileged session management, and secrets management solutions.
- Design, deploy, and optimise CyberArk Endpoint Privilege Manager (EPM).
- Develop EPM policies, application control frameworks, privilege elevation strategies, and rollout plans.
- Integrate CyberArk with identity providers, cloud platforms, SIEM tools, ITSM platforms, and enterprise applications.
- Develop PAM standards, governance frameworks, operational procedures, and implementation roadmaps.
- 5+ years of hands-on CyberArk PAM engineering and implementation experience.
- Strong CyberArk Cloud/SaaS experience.
- Proven JIT privileged access implementation experience.
- Experience conducting CyberArk architecture assessments and developing strategic roadmaps.
- Strong knowledge of CPM password rotation and reconciliation.
- Experience with PSM privileged session management and recording.
- Application, service account, and privileged account onboarding.
- Windows and Linux privileged access management experience.
- PowerShell, Python, REST APIs, and automation experience.
- Ability to define target-state architecture and drive PAM maturity programmes.
Highly Desirable
- CyberArk Endpoint Privilege Manager (EPM).
- CyberArk Privileged Threat Analytics (PTA).
- AWS, Azure, or Google Cloud integrations.
- Kubernetes and container environments.
- DevOps and CI/CD integrations.
- ITSM and SIEM integrations.
- Current-state CyberArk assessment.
- PAM maturity review and gap analysis.
- CyberArk Cloud adoption strategy.
- SIA implementation roadmap.
- JIT implementation roadmap.
- Application and service account onboarding framework.
- Password rotation and secrets management strategy.
- PAM standards, governance, and operational procedures.
- Knowledge transfer and operational handover documentation.
Certifications
Preferred certifications include:
- CyberArk Sentry
- CyberArk Cloud Certifications
- CyberArk PAM Delivery Credentials
CISSP is beneficial but not essential for this hands-on engineering role.