- Company Name
- Initialize
- Job Title
- PAM (CyberArk) Architect
- Job Description
-
**Job Title:** PAM (CyberArk) Architect
**Role Summary:**
Design and deliver end‑to‑end privileged access management solutions using CyberArk. Lead architectural planning, integration, and operational model definition for a large‑scale PAM implementation, ensuring compliance with security frameworks and regulatory requirements.
**Expectations:**
- 3+ years of hands‑on experience as a CyberArk Architect.
- Proven track record designing and deploying CyberArk Vault, PSM/PSMP, CPM, and PVWA.
- Experience onboarding Windows/Linux servers, databases, network devices, and cloud services (AWS/Azure).
- Ability to integrate CyberArk with ServiceNow, SIEM/SOAR, SSO, AD/Entra ID, and enterprise directories.
- Strong understanding of privileged account classification, credential rotation, session monitoring, JIT access, and Zero Trust principles.
**Key Responsibilities:**
- Create and maintain high‑level and low‑level design artefacts (HLD, LLD, data‑flow diagrams, topology).
- Define privileged account onboarding, classification, vaulting, and rotation standards.
- Design and implement session monitoring, audit, and break‑glass processes.
- Architect integrations with AD/Entra ID, servers, databases, network devices, cloud platforms, ServiceNow, and SIEM/SOAR.
- Align PAM architecture with NIST 800‑53/800‑63, CIS Controls, SOX, ISO 27001, and Zero Trust models.
- Provide technical leadership to PAM engineering teams, validate configurations, and develop reusable design patterns.
**Required Skills:**
- CyberArk Vault, PSM, CPM, PVWA implementation.
- Privileged account discovery, classification, and JIT/least‑privilege models.
- Integration experience (ServiceNow, SIEM/SOAR, SSO, AD/Entra ID, cloud APIs).
- Knowledge of IAM/IGA concepts and tools (e.g., Saviynt, Workday).
- Understanding of security frameworks (NIST, CIS, ISO 27001, SOX).
- Strong analytical, documentation, and communication skills.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- CyberArk certifications such as CDE, CPE, or CIM highly desirable.
- Additional certifications (CISSP, CISA, AWS/Azure security) are a plus.