CyberArk PAM Architect - W2
hace 4 días
Jersey City
Role :- CyberArk PAM Architect \n Location :- Jersey City, NJ(Onsite) \n \n Key Note: Must be authorized to work in the U.S. on a W2 basis without current or future visa sponsorship. Qualified candidates who meet the requirements are encouraged to apply. \n \n Years of Experience \n\n • 10+ years of relevant experience in designing, architecting, and implementing PAM and EPM solutions across complex enterprise environments.\n\n \n General Description \n\n • Serve as the subject matter expert for Privileged Access Management (PAM), providing architecture guidance and best practices across CyberArk platforms.\n, • Partner with business, security, infrastructure, and application teams to assess privileged access risks, define PAM roadmaps, and deliver secure, scalable solutions aligned with organizational objectives.\n, • Evaluate existing PAM and identity security environments, recommend modernization and optimization strategies, and drive adoption of industry-leading privileged access controls.\n, • Lead client-facing discussions, workshops, and design reviews with US-based stakeholders, translating business and compliance requirements into effective PAM solutions.\n, • Provide governance, operational oversight, and lifecycle management for PAM platforms, including continuous improvement, upgrade planning, troubleshooting, documentation, and adherence to security and regulatory standards. \n\n \n Technical Requirements \n\n • Creating and implementing strategies for managing privileged access using CyberArk, designing PAM solutions, and ensuring the secure storage, management, and retrieval of sensitive credentials in enterprise environments.\n, • Developing and enforcing security policies, access controls, and privileged access management procedures using CyberArk capabilities to mitigate security risks and support compliance requirements.\n, • Design secure and scalable CyberArk PAM solutions, creating High-Level Designs (HLDs) and Low-Level Designs (LLDs) for cloud, on-premises, and hybrid environments while working closely with US-based stakeholders.\n, • Implement, oversee, and document high-level and low-level designs for CyberArk deployments, defining PAM strategies aligned with business, security, and regulatory requirements.\n, • Collaborate with automation SPOCs, application teams, and onsite stakeholders to build, test, and optimize PAM-related automation solutions.\n, • Design, deploy, and support high-performance, highly available CyberArk PAM environments with large-scale target endpoints, creating workflows, custom connectors, policies, and integrations.\n, • Should be capable of deploying, installing, and configuring CyberArk components (Vault, CPM, PVWA, PSM, PSMP, AIM/CCP) as per client requirements.\n, • Develop custom plugins, integrations, and connectors for CyberArk CPM/PSM Password Safe/PRA components, as required.\n, • Hands-on experience or knowledge in configuring CyberArk PTA, Endpoint Privilege Management (EPM) and privileged access monitoring capabilities.\n, • Integrating various platforms with CyberArk, including Windows, UNIX/Linux, databases, network devices, SSH keys, cloud platforms, SAP, and enterprise applications.\n, • Creating and managing Safes, platforms, owners, vault policies, asset groups, account management policies, and access controls within CyberArk environments.\n, • Should be familiar with CyberArk Password Upload Utility, PACLI, REST APIs, and corresponding administration, onboarding, and integration utilities/tools.\n, • Experience in integrating CyberArk solutions with LDAP/Active Directory, SIEM, SNMP, MFA, and other identity and access management systems.\n, • Strong scripting skills using PowerShell, Python, Shell scripting, or APIs to automate tasks, develop integrations, and customize CyberArk solutions.\n, • Knowledge of regulatory requirements and industry standards related to privileged access management, including NIST, CIS, SOX, PCI-DSS, HIPAA, and GDPR.\n, • Experience with security monitoring tools and integrating CyberArk with Security Information and Event Management (SIEM) platforms; ability to support client workshops, design discussions, and solution reviews in an onsite US-facing environment.\n\n \n Soft Skills \n\n • Excellent Verbal and written communication skills in English.\n, • Ability to present solutions to clients in person and remotely if needed.\n, • Good documentation skills that will enable creation of design documents for the technical solutions proposed.\n, • Excellent problem-solving skills.\n, • Good collaboration skills in working with virtual and distributed teams. \n\n Certifications \n\n • Good to have relevant PAM certifications such as:\n, • CyberArk Certified Delivery Engineer (CDE)\n, • CyberArk Certified Defender (CCD)\n, • CyberArk Certified Sentry (CCS)\n, • CyberArk Certified Guardian (CCG)\n, • CISSP (Certified Information Systems Security Professional)\n\n \n Educational Qualifications \n\n • University degree in IT or/and IT Security\n