CyberArk (PAM) Architect
IBM · Houston, TX · 1 wk ago
HybridArt & CreativeFull-time
About the role
This position serves as a core contributor to the CyberArk PAM team, leveraging extensive expertise in the design, implementation, upgrade, and administration of enterprise-grade CyberArk security solutions across complex hybrid environments. The role is responsible for securing privileged identities, mitigating insider threats, and ensuring compliance with industry standards and regulatory requirements. The ideal candidate demonstrates a proven track record of delivering robust privileged access management solutions, optimizing security controls, and supporting the organization's cybersecurity and governance objectives.
What you'll do
- Design and implement CyberArk PAM architectures aligned with business and security requirements
- Lead CyberArk deployments, upgrades, migrations, and platform hardening activities
- Configure safes, platforms, account onboarding, password rotation, and session management policies
- Integrate CyberArk with Active Directory, SIEM, MFA, ServiceNow, and cloud services
- Develop security standards, operational procedures, and PAM governance models
- Conduct risk assessments and recommend privileged access controls based on Zero Trust principles
- Provide L3 support, troubleshooting, performance tuning, and capacity planning
- Collaborate with security, infrastructure, cloud, and application teams to secure privileged accounts and secrets
Technical expertise
- CyberArk PAM Suite Architecture and Design
- Privileged Access Security & Identity Governance
- CyberArk PAS Components: Digital Vault, Privileged Vault Web Access (PVWA), Central Policy Manager (CPM), Privileged Session Manager (PSM), Privileged Threat Analytics (PTA), Enterprise Secret Manager (Conjur), Credential Providers (CP)
- CyberArk SaaS and Self-Hosted Deployments
- Discovery and Onboarding of Privileged Accounts
- Session Monitoring, Recording, and Auditing
- Password Management and Rotation
- Secrets Management & DevSecOps Integration
- Zero Trust and Least Privilege Implementation
- Access Certification and Compliance Management
- High Availability, Disaster Recovery, and Migration Strategies
- Secrets Manager (Conjur)
Required technical and professional experience
- 10+ years of Information Security experience
- 5+ years specializing in CyberArk Privileged Access Management solutions
- Operating Systems: Windows Server, Linux, Unix
- Cloud Platforms: Azure, AWS, Google Cloud Platform
- Directory Services: Active Directory, LDAP, Entra ID (Azure AD)
- SIEM Integration: Splunk, QRadar, ArcSight, Sentinel
- Ticketing & ITSM: ServiceNow, Remedy
- Automation/Scripting: PowerShell, Python, REST APIs
- DevOps Tools: Jenkins, Kubernetes, Docker, OpenShift
- Databases: SQL Server, Oracle, PostgreSQL
Compliance & security frameworks
- NIST Cybersecurity Framework
- CIS Controls
- ISO 27001
- SOX
- PCI-DSS
- HIPAA
- GDPR
- Zero Trust Security Architecture