- Company Name
- Allegis Group
- Job Title
- Cyberark IAM Engineer
- Job Description
-
**Job title**: CyberArk IAM Engineer
**Role Summary**: Lead the design, implementation, and ongoing optimization of CyberArk Privileged Access Management (PAM) solutions across enterprise infrastructure to ensure secure privileged access in compliance with regulatory and security policies.
**Expactations**:
- Deliver end‑to‑end CyberArk deployments that meet security, compliance, and operational requirements.
- Establish and enforce privileged access controls, policies, and audit procedures.
- Provide mentorship and guidance to technical teams on PAM best practices.
**Key Responsibilities**:
- Architect and implement CyberArk components (PAM, Privilege Cloud, Advanced Threat Analytics, Access Manager) in hybrid/cloud environments.
- Configure and maintain Enterprise Password Vault, Password Protection, Privileged Session Manager, Central Policy Manager, and relevant integrations.
- Design and enforce privileged account life‑cycle policies, password rotation, and session monitoring.
- Develop automation scripts (PowerShell, Python, Bash) for provisioning, deprovisioning, and reporting.
- Conduct vulnerability assessments, penetration tests, and remediate findings related to privileged access.
- Produce compliance reports (PCI‑DSS, SOX, ISO 27001, GDPR) and support audit engagements.
- Monitor and analyze logs, alerts, and dashboards; respond to incidents and reduce mean time to recovery.
- Collaborate with network, identity, and security teams to integrate CyberArk with SSO, MFA, and SIEM solutions.
- Evaluate new CyberArk features, roadmap, and emerging PAM technologies; recommend enhancements.
**Required Skills**:
- In‑depth knowledge of CyberArk PAM suite (PAM, Privilege Cloud, Active Directory/LDAP, Azure AD, IAM).
- Experience with on‑prem, Azure, AWS, and VMware environments.
- Strong scripting/automation skills (PowerShell, Python, Bash).
- Familiarity with security frameworks (NIST CSF, ISO 27001) and regulatory standards (PCI‑DSS, SOX, GDPR).
- Proficiency in incident response, audit, and log analysis using SIEM tools (Splunk, QRadar, ArcSight).
- Excellent problem‑solving, communication, and stakeholder engagement abilities.
**Required Education & Certifications**:
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent professional experience).
- CyberArk Certified Engineer (CCE) or CyberArk Certified Privileged Access Administrator (CCPA).
- Relevant security certifications (CISSP, CISM, CompTIA Security+, or equivalent).