Senior CyberArk Operations Engineer

Bristol-Myers Squibb

United States

On-site

USD 140,000 - 170,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Bristol Myers Squibb seeks an experienced Senior CyberArk Operations Engineer to own CyberArk privileged access management infrastructure and SaaS migrations. You will drive automation, design secrets management for DevOps, and own privileged access control decisions across enterprise systems.

You will oversee installation, optimization, and integration with Active Directory/LDAP/SSO, while orchestrating migration waves and decommissioning legacy components.

Qualifications

  • Experience operating CyberArk in a SaaS deployment and migration from self-hosted to SaaS.
  • Ability to design and deliver secrets management for applications and DevOps teams.
  • Experience with privileged access control decisions and audit support.

Responsibilities

  • Own the installation, configuration, and maintenance of CyberArk vault server infrastructure; ensure integration with third-party systems.
  • Operate and optimise the CyberArk SaaS environment; manage tenant/connector architecture and release adoption.
  • Lead migration waves to the SaaS platform; re-establish integrations and plan cutovers; decommission legacy components.
  • Design and delivery of secrets management for applications and DevOps teams; integrate secrets retrieval into CI/CD pipelines.
  • Define target scope and control model for privileged access; transition operations accordingly.
  • Collaborate to identify integration requirements and design secure solutions.
  • Configure and maintain integrations between CyberArk and AD/LDAP/SSO and cloud identity providers.
  • Monitor health and performance; troubleshoot issues and optimize configurations; escalate complex faults.
  • Develop automation scripts and API integrations to reduce privileged access tickets via self-service.

Skills

PAM operations
CyberArk SaaS
Automation scripting

Tools

CyberArk
BeyondTrust
Active Directory
LDAP
SSO

Job description

At Bristol Myers Squibb, our employees often ask, "Who are you working for?"-a question that fuels collaboration, accountability, and urgency in our work. Our purpose-driven culture inspires us to discover, develop, and deliver innovative medicines to prevail over serious diseases. We offer uniquely interesting and meaningful work, opportunities for growth, and a supportive environment that values inclusion, wellbeing, flexibility, and comprehensive benefits. This is work that transforms the lives of patients, and the careers of those who do it.

Overview:

We are seeking an experienced Senior CyberArk Operations Engineer to take ownership of our CyberArk privileged access management infrastructure and the integrations that support password management and retrieval across the enterprise. Our privileged access estate is moving to the CyberArk SaaS model, and the successful candidate must bring hands‑on experience of operating CyberArk in a SaaS deployment together with a working understanding of the migration path from self‑hosted to SaaS - whether to complete remaining migration waves or to stabilise, optimise, and run the platform once the transition is complete. The role also holds design and delivery ownership for the introduction of secrets management for application and DevOps teams and the redesign of the PMUL and ADB scope and control model. Beyond day‑to‑day responsibility for platform health, upgrades, and third‑party integration, the successful candidate will act as the accountable owner for privileged access control decisions, progressively convert routine operational work into automation and self‑service, and build PAM capability across the wider team.

Responsibilities:
  • Own the installation, configuration, and maintenance of CyberArk vault server infrastructure, ensuring compatibility and seamless integration with third‑party systems for password management and retrieval.
  • Own the operation and optimisation of the CyberArk SaaS environment - tenant and connector architecture, connector capacity and resilience, integration health, vendor release and feature adoption, and validation that privileged access controls operate as designed in the SaaS model.
  • Lead any remaining migration or onboarding waves to the SaaS platform, including integration re‑establishment, cutover sequencing, rollback planning, and post‑migration control validation, and drive the decommissioning and clean‑up of legacy self‑hosted components.
  • Design and deliver the introduction of secrets management for application and DevOps teams, including the onboarding pattern, integration of secrets retrieval into build and deployment pipelines, and the retirement of hard‑coded and embedded credentials.
  • Define the target scope and control model for PMUL and ADB and own the operational transition to it.
  • Collaborate with cross‑functional teams to identify integration requirements and design solutions that meet business needs while adhering to security and operational standards.
  • Configure and maintain integrations between CyberArk and other password management products, such as Active Directory, LDAP, SSO solutions, and cloud‑based identity providers.
  • Monitor the health and performance of integrated systems, troubleshooting issues and optimising configurations to ensure smooth operation, and act as the final escalation point for complex CyberArk and BeyondTrust faults.
  • Develop custom scripts, automation workflows, and API‑based integrations to streamline password management processes and enhance system interoperability, with a standing mandate to reduce recurring privileged access ticket volume through self‑service and automation.
  • Plan and execute software upgrades, patches, and maintenance activities for CyberArk and integrated systems, including impact assessment and control validation, ensuring minimal disruption to operations.
  • Act as the accountable owner for privileged access control decisions - approval judgement on elevated and non‑standard requests, break‑glass authorisation, exception handling, and the technical response to internal and external audit.
  • Own the platform, safe, policy, and permission model for the privileged access estate and approve changes to it.
  • Support and enhance endpoint privilege management and just‑in‑time administrator access through BeyondTrust, including policy design and troubleshooting across Windows, Linux, and macOS.
  • Collaborate with IT Security teams to implement and enforce security policies and best practices for password management across integrated systems.
  • Provide technical support, direction, and review to end‑users, IT teams, and operations engineers on privileged access processes and integrations.
  • Develop and maintain documentation, runbooks, and standards, and deliver structured cross‑training so that privileged access coverage is held by multiple engineers rather than a single individual.
  • Stay informed about industry trends and emerging technologies in password management and p
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior CyberArk & PAM Platform Engineer
Senior CyberArk & PAM Platform Engineer

Bristol-Myers Squibb • United States

On-site
USD 140,000 - 170,000
Privileged Access Management (PAM) Senior Specialist (HashiCorp Vault experience required)
Privileged Access Management (PAM) Senior Specialist (HashiCorp Vault experience required)

Bank of America • Jersey City (NJ)

On-site
USD 110,000 - 140,000
Salary commensurate with experience
Privileged Access Management (PAM) Senior Specialist (HashiCorp Vault experience required)
Privileged Access Management (PAM) Senior Specialist (HashiCorp Vault experience required)

Bank of America • Washington

On-site
USD 130,000 - 190,000
CyberArk / Privileged Access Management Systems Analyst
CyberArk / Privileged Access Management Systems Analyst

STL 1st • Missouri

On-site
USD 90,000 - 130,000
CyberArk Engineer
CyberArk Engineer

CBTS • Plano (TX)

On-site
USD 95,000 - 130,000
Privileged Access Management (PAM) Engineer - CyberArk Specialist | Cross-Border Banking and Ma[...]
Privileged Access Management (PAM) Engineer - CyberArk Specialist | Cross-Border Banking and Ma[...]

Techfellow Limited • Woodbridge Township (NJ)

Hybrid
USD 127,000 - 150,000
Senior CyberArk Engineer
Senior CyberArk Engineer

CBTS • Berkeley Heights (NJ)

On-site
USD 100,000 - 130,000
PAM Engineering Lead
PAM Engineering Lead

WTW • Minneapolis (MN)

On-site
USD 130,000 - 170,000
Health benefits
401(k) plan with company contribution
Paid time off
Senior Technology Security Engineer (IAM)
Senior Technology Security Engineer (IAM)

Pointwest-North America • Des Moines (IA)

On-site
USD 100,000 - 130,000
PAM Engineering Lead
PAM Engineering Lead

Willis Towers Watson • Minneapolis (MN)

On-site
USD 130,000 - 170,000
Health and wellbeing benefits
401(k) and pension plan
Paid holidays and PTO