Jobs · Connecticut

Senior Cybersecurity Technologist

Travelers · Hartford, CT · 1 mo ago
Hybrid$127k–$209k/yrFull-time

Compensation Overview

The annual base salary range provided for this position is a nationwide market range and represents a broad range of salaries for this role across the country. The actual salary for this position will be determined by a number of factors, including the scope, complexity and location of the role; the skills, education, training, credentials and experience of the candidate; and other conditions of employment. As part of our comprehensive compensation and benefits program, employees are also eligible for performance-based cash incentive awards. Salary Range $126,500.00 - $208,700.00 Target Openings 1

What Is the Opportunity?

At Travelers, our Cybersecurity Engineering teams are responsible for the overall implementation and management of strategic platforms that provide oversight, process management, protection and enablement of security control processes and allow for an effective Cybersecurity practice. As a Cybersecurity Engineer II, you will provide subject matter expertise and consultation on complex cybersecurity platforms to ensure correct installation, configuration, and maintenance. You will consult with business partners on any changes and/or enhancements and will effectively communicate potential operational impacts.

What Will You Do?

  • Own the architecture, deployment, and lifecycle of self-hosted CyberArk components, including the Password Vault Web Access (PVWA), Central Policy Manager (CPM), and Privileged Session Manager (PSM/PSMP).

  • Maintain platform configurations, safe structures, access policies, and master policy settings that align with least-privilege and separation-of-duties principles.

  • Onboard privileged accounts and secrets across Windows, Linux/Unix, databases, network devices, and cloud platforms, developing custom CPM plugins and connectors where out-of-the-box support falls short.

  • Lead vault resilience efforts, including disaster recovery, high-availability configuration, backup validation, and version upgrades with minimal disruption.

  • Build automation for onboarding, reconciliation, reporting, and health monitoring using the CyberArk REST API, PowerShell, and related tooling.

  • Troubleshoot complex issues across the PAM stack, from connection component failures and PSM recordings to CPM rotation errors and vault performance tuning.

  • Document standards and runbooks and contribute to the technical maturity of the broader team.

  • Help advance our privileged access roadmap toward password-less and modern authentication by reducing reliance on static credentials through ephemeral, certificate-based, and just-in-time access models, and tighter integration with our broader identity platform.

What Will Our Ideal Candidate Have?

  • Hands-on experience operating self-hosted (on-premises) CyberArk PAM in a production enterprise environment.

  • Strong working knowledge of the full CyberArk component set: Vault, PVWA, CPM, PSM/PSMP, and familiarity with PTA, Conjur, or CyberArk's SaaS offerings.

  • Experience developing custom connection components and CPM plugins for non-standard platforms.

  • Proficiency with the CyberArk REST API and scripting in PowerShell (Python a plus) to automate operational tasks.

  • Solid command of Windows Server and Active Directory, with working knowledge of Linux/Unix privileged access models.

  • Practical understanding of authentication protocols and PKI concepts (LDAP, SAML, Kerberos, certificates) as they relate to PAM.

  • Understanding of just-in-time and zero-standing-privilege access models, and how to move a program from static, always-on credentials toward ephemeral access.

  • Experience integrating PAM with the surrounding identity and operations ecosystem IdP/SSO (Entra ID, Okta), ITSM (ServiceNow), SIEM, and secrets consumers via API.

  • Experience evaluating, piloting, or integrating new capabilities into an existing PAM program — able to weigh build-vs-buy tradeoffs and plan phased rollouts.

  • Track record of leading upgrades, migrations, or resilience improvements in a self-hosted deployment.

  • CyberArk certifications (Defender, Sentry, or Guardian).

  • Exposure to hybrid and cloud privileged access patterns (AWS, Azure).

  • Experience supporting privileged access in a regulated industry.

What is a Must Have?

  • Bachelor’s degree in Computer Science, similar degree, or its equivalent in work experience.

  • 4 years of experience in Information Technology Security Engineering or Software engineering.

Similar jobs