Senior Cybersecurity Technologist

The Travelers Indemnity Company

Atlanta (GA)

On-site

USD 127,000 - 209,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health Insurance
401(k) matching
Paid time off
Wellness program
Volunteer program

Job summary

The Travelers Indemnity Company is seeking a Cybersecurity Engineer II to lead the architecture, deployment, and maintenance of self-hosted CyberArk components across enterprise platforms. You will implement least-privilege access, manage privileged accounts, and drive automation using REST APIs and PowerShell.

Ideal candidates bring hands-on CyberArk PAM experience, strong PKI and identity protocols knowledge, and a track record of upgrading or migrating resilient PAM solutions in regulated

Qualifications

  • Hands-on experience operating self-hosted CyberArk PAM in a production environment.
  • Strong knowledge of CyberArk components: Vault, PVWA, CPM, PSM/PSMP; familiarity with PTA/Conjur or SaaS offerings.
  • Experience developing custom connection components and CPM plugins for non-standard platforms.
  • Proficient with CyberArk REST API and scripting in PowerShell (Python a plus).
  • Solid Windows Server and Active Directory knowledge; Linux/Unix privileged access awareness.
  • Understanding of authentication protocols and PKI concepts (LDAP, SAML, Kerberos).
  • Understanding just-in-time and zero-standing-privilege access models and epoxy access concepts.
  • Experience integrating PAM with IdP/SSO (Entra ID, Okta), ITSM (ServiceNow), SIEM, and secrets consumers via API.
  • Experience evaluating or piloting new PAM capabilities and planning phased rollouts.
  • Track record of upgrades, migrations, or resilience improvements in self-hosted deployments.
  • CyberArk certifications (Defender, Sentry, Guardian) and cloud privileged access exposure.
  • Experience in regulated industries.

Responsibilities

  • Own architecture, deployment, and lifecycle of self-hosted CyberArk components (PVWA, CPM, PSM/PSMP).
  • Maintain configurations, access policies, and least-privilege controls.
  • Onboard privileged accounts and secrets across Windows, Linux/Unix, databases, and cloud platforms; build CPM plugins as needed.
  • Lead vault resilience, DR, high availability, backups, and upgrades with minimal disruption.
  • Build automation for onboarding, reconciliation, reporting, and health monitoring via CyberArk REST API and PowerShell.
  • Troubleshoot PAM stack issues from PVWA/PSM to CPM rotation and vault performance.
  • Document standards and runbooks; contribute to team maturity.
  • Advance privileged access roadmap toward password-less and certificate-based/auth via epoxy and JIT models.

Skills

CyberArk PAM operations
PowerShell scripting
Windows Server
Active Directory
Linux/Unix privileged access
PKI concepts (LDAP, SAML, Kerberos)
Just-in-time / epoxy access
IdP/SSO integrations (Entra ID, Okta)
Secrets management & API automation
Cloud privileged access (AWS, Azure)

Education

Bachelor's degree in Computer Science or related field

Tools

CyberArk PVWA/CPM/PSM tooling
CyberArk REST API

Job description

Who Are We?

Taking care of our customers, our communities and each other. That's the Travelers Promise. By honoring this commitment, we have maintained our reputation as one of the best property casualty insurers in the industry for over 170 years. Join us to discover a culture that is rooted in innovation and thrives on collaboration. Imagine loving what you do and where you do it.

Compensation Overview

The annual base salary range provided for this position is a nationwide market range and represents a broad range of salaries for this role across the country. The actual salary for this position will be determined by a number of factors, including the scope, complexity and location of the role; the skills, education, training, credentials and experience of the candidate; and other conditions of employment. As part of our comprehensive compensation and benefits program, employees are also eligible for performance-based cash incentive awards.

Salary Range

126,500.00 - 208,700.00

Target Openings

1

What Is the Opportunity?

At Travelers, our Cybersecurity Engineering teams are responsible for the overall implementation and management of strategic platforms that provide oversight, process management, protection and enablement of security control processes and allow for an effective Cybersecurity practice.
As a Cybersecurity Engineer II, you will provide subject matter expertise and consultation on complex cybersecurity platforms to ensure correct installation, configuration, and maintenance. You will consult with business partners on any changes and/or enhancements and will effectively communicate potential operational impacts. Leveraging your technical expertise on strategic platforms, you will troubleshoot complex issues that may be escalated and provide guidance and coaching to team members.

What Will You Do?
  • Own the architecture, deployment, and lifecycle of self-hosted CyberArk components, including the Password Vault Web Access (PVWA), Central Policy Manager (CPM), and Privileged Session Manager (PSM/PSMP).
  • Maintain platform configurations, safe structures, access policies, and master policy settings that align with least-privilege and separation-of-duties principles.
  • Onboard privileged accounts and secrets across Windows, Linux/Unix, databases, network devices, and cloud platforms, developing custom CPM plugins and connectors where out-of-the-box support falls short.
  • Lead vault resilience efforts, including disaster recovery, high-availability configuration, backup validation, and version upgrades with minimal disruption.
  • Build automation for onboarding, reconciliation, reporting, and health monitoring using the CyberArk REST API, PowerShell, and related tooling.
  • Troubleshoot complex issues across the PAM stack, from connection component failures and PSM recordings to CPM rotation errors and vault performance tuning.
  • Document standards and runbooks and contribute to the technical maturity of the broader team.
  • Help advance our privileged access roadmap toward password-less and modern authentication by reducing reliance on static credentials through epoxy, certificate-based, and just-in-time access models, and tighter integration with our broader identity platform.
What Will Our Ideal Candidate Have?
  • Hands-on experience operating self-hosted (on-premises) CyberArk PAM in a production enterprise environment.
  • Strong working knowledge of the full CyberArk component set: Vault, PVWA, CPM, PSM/PSMP, and familiarity with PTA, Conjur, or CyberArk's SaaS offerings.
  • Experience developing custom connection components and CPM plugins for non-standard platforms.
  • Proficiency with the CyberArk REST API and scripting in PowerShell (Python a plus) to automate operational tasks.
  • Solid command of Windows Server and Active Directory, with working knowledge of Linux/Unix privileged access models.
  • Practical understanding of authentication protocols and PKI concepts (LDAP, SAML, Kerberos, certificates) as they relate to PAM.
  • Understanding of just-in-time and zero-standing-privilege access models, and how to move a program from static, always-on credentials toward epoxy access.
  • Working knowledge of password-less and certificate-based authentication concepts, and how they apply to privileged access.
  • Experience integrating PAM with the surrounding identity and operations ecosystem IdP/SSO (Entra ID, Okta), ITSM (ServiceNow), SIEM, and secrets consumers via API.
  • Experience evaluating, piloting, or integrating new capabilities into an existing PAM program - able to weigh build-vs-buy tradeoffs and plan phased rollouts.
  • A track record of leading upgrades, migrations, or resilience improvements in a self-hosted deployment.
  • CyberArk certifications (Defender, Sentry, or Guardian).
  • Exposure to hybrid and cloud privileged access patterns (AWS, Azure).
  • Experience supporting privileged access in a regulated industry.
What is a Must Have?
  • Bachelor's degree in Computer Science, similar degree, or its equivalent in work experience.
  • 4 years of experience in Information Technology Security Engineering or Software engineering.
What Is in It for You?
  • Health Insurance:Employees and their eligible family members - including spouses, domestic partners, and children - are eligible for coverage from the first day of employment.
  • Retirement:Travelers matches your 401(k) contributions dollar-for-dollar up to your first 5% of eligible pay, subject to an annual maximum. If you have student loan debt, you can enroll in the Paying it Forward Savings Program. When you make a payment toward your student loan, Travelers will make an annual contribution into your 401(k) account. You are also eligible for a Pension Plan that is 100% funded by Travelers.
  • Paid Time Off:Start your career at Travelers with a minimum of 20 days Paid Time Off annually, plus nine paid company Holidays.
  • Wellness Program:The Travelers wellness program is comprised of tools, discounts and resources that empower you to achieve your wellness goals and caregiving needs. In addition, our mental health program provides access to free professional counseling services, health coaching and other resources to support your daily life needs.
  • Volunteer Encouragement:We have a deep commitment to the communities we serve and encourage our employees to get involved. Travelers has a Matching Gift and Volunteer Rewards program that enables you to give back to the charity of your choice.
Employment Practices

Travelers is an equal opportunity employer. We value the unique abilities and talents each individual brings to our organization and recognize that we benefit in numerous ways from our differences.

In accordance with local law, candidates seeking employment in Colorado are not required to disclose dates of attendance at or graduation from educational institutions.

If you are a candidate and have specific questions regarding the physical requirements of this role, please send us an email so we may assist you.

Travelers reserves the right to fill this position at a level above or below the level included in this posting.

To learn more about our comprehensive benefit programs please visit http://careers.travelers.com/life-at-travelers/benefits/.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Cyber Risk Services
Manager, Cyber Risk Services

The Travelers Indemnity Company • Hartford (CT)

On-site
USD 120,000 - 199,000
Health Insurance
Retirement plan
Paid Time Off
+2
Senior Associate Cybersecurity Specialist - Third Party Risk Management Program
Senior Associate Cybersecurity Specialist - Third Party Risk Management Program

The Travelers Indemnity Company • Hartford (CT), Northern (KY)

Hybrid
USD 82,000 - 135,000
Health Insurance
401(k) Match
Paid Time Off
+2
Senior Associate Cybersecurity Specialist - Third Party Risk Management Program
Senior Associate Cybersecurity Specialist - Third Party Risk Management Program

Travelers • Hartford (CT)

On-site
USD 82,000 - 135,000
Health Insurance
401(k) Matching
Paid Time Off
+2
Software Engineer II (AI, Python, Typescript)
Software Engineer II (AI, Python, Typescript)

The Travelers Indemnity Company • Hartford (CT)

On-site
USD 120,000 - 199,000
Health Insurance
401(k) Matching
Paid Time Off
+2
Technical Product Owner (IAM - Cybersecurity)
Technical Product Owner (IAM - Cybersecurity)

The Travelers Indemnity Company • Atlanta (GA)

On-site
USD 99,000 - 163,000
Health Insurance
Retirement: 401(k) matching
Paid Time Off
+2
Technical Product Owner (IAM - Cybersecurity)
Technical Product Owner (IAM - Cybersecurity)

Travelers • Atlanta (GA)

On-site
USD 99,000 - 163,000
Health Insurance
Paid Time Off
401(k) Matching
+1
Cybersecurity Ops Technologist I (Email Security)
Cybersecurity Ops Technologist I (Email Security)

The Travelers Indemnity Company • Hartford (CT)

Hybrid
USD 99,000 - 163,000
Health Insurance
401(k) Retirement Plan
Paid Time Off
+1
Software Engineer II (.NET, AWS)
Software Engineer II (.NET, AWS)

The Travelers Indemnity Company • Hartford (CT), Northern (KY)

On-site
USD 120,000 - 199,000
Health Insurance
401(k) match
Paid Time Off
+2
Sr Software Engineer
Sr Software Engineer

Travelers • Hartford (CT)

On-site
USD 139,000 - 230,000
Health Insurance
401(k) match
Paid time off
+2
Cybersecurity Ops Technologist - Splunk SIEM Engineer
Cybersecurity Ops Technologist - Splunk SIEM Engineer

The Travelers Indemnity Company • Hartford (CT)

On-site
USD 99,000 - 164,000
Health Insurance
Retirement program
Paid Time Off