SECURITY ARCHITECT (CNI - Critical National Infrastructure)
hace 2 días
Warwick
Job Description: Mandatory Skills: Privilege Password Management CyberArk SC cleared/SC eligible candidates only Key Responsibilities Architecture & Design o Support high-level and detailed architecture for CyberArk PAM Self Hosted (Vault, PVWA, CPM, PSM, PSMP, PTA, DR) and CyberArk Conjur/Secrets Manager, ensuring resilience, scalability, and compliance with CNI standards. o Develop reference architectures, design patterns, and standards for seamless integration into infrastructure, applications, DevOps pipelines, containers, and multi cloud environments. Integration & Cross Team Collaboration o Integrate CyberArk with corporate systems: AD/LDAP, SAML/OIDC, MFA providers, SIEM platforms (eg, Splunk), and ITSM tools. o Collaborate with security, infrastructure, IAM, DevOps, and application teams to ensure alignment with CNI policies and controls. CNI-Specific Security & Compliance o Apply CNI security frameworks (eg, NCSC, NIST, ISO27001, FCA/Financial) in threat modelling, control selection, and architecture decisions. o Perform assessments, audits, and vulnerability analyses to maintain compliance with critical infrastructure regulations. Migration & Transition o Lead migration from self hosted or Legacy PAM systems to CyberArk Privilege Cloud or modern on prem/cloud infrastructure. Develop migration roadmaps, runbooks, cutover strategies, and success metrics. o Execute migration tasks: safe/platform migration, account and platform mapping, connector replacement, policy transformation, key rotation, and integration cut over. Implementation & Handover o Manage installation, configuration, testing, and deployment of solution components; then transition them to operational monitor and maintain teams. o Document HLDs/LLDs, runbooks, operational procedures, and deliver training to internal teams. Operational Support & Upgrades o Provide expert-level L2/L3 support, incident response, troubleshooting (eg, rotation issues, connector failures), troubleshooting root causes, and recommending issue resolution. o Oversee platform health, patching, upgrades, and system hardening for CNI-level resilience.