- Company Name
- Allegis Group
- Job Title
- CyberArk Engineer
- Job Description
-
**Job Title:** CyberArk Engineer
**Role Summary:**
Lead the design, deployment, and continuous improvement of Enterprise CyberArk Privileged Access Management (PAM) solutions across a multi‑region on‑prem environment. Ensure secure credential handling, regulatory compliance, and seamless integration with DevOps tools while driving future migration to CyberArk SaaS.
**Expectations:**
- Deliver robust PAM architecture that meets NIST 800‑53 and Zero‑Trust security standards.
- Own the full lifecycle of privileged account management, from onboarding and rotation to decommissioning.
- Maintain high platform availability, performance, and compliance through proactive upgrades and incident resolution.
- Provide subject‑matter expertise and training to internal stakeholders.
**Key Responsibilities:**
- Design and administer CyberArk multi‑region deployments (Digital Vault, CPM, PSM, PSMP, CCP, PTA, AIM).
- Automate credential onboarding, rotation, and decommissioning, including service accounts, certificates, and SSH keys.
- Plan and execute major CyberArk version upgrades: assess environments, migrate, validate security, and document outcomes.
- Define and enforce Safe structures, RBAC policies, and master policies aligned to NIST 800‑53.
- Develop scripts to automate privileged account onboarding into Safes.
- Configure and develop non‑out‑of‑the‑box connectors (e.g., Oracle Cloud, other business apps).
- Act as SME for troubleshooting incidents; collaborate with infrastructure and application teams to resolve PAM issues and optimize performance.
- Integrate AIM/AAM/Conjur with CI/CD pipelines for secret management.
- Create and maintain SOPs, onboarding guides, platform diagrams, and deliver training sessions to internal teams and stakeholders.
**Required Skills:**
- Deep expertise with CyberArk components (CPM, PSM, PSMP, CCP, PTA, AIM, PTA).
- Strong scripting abilities (Python, PowerShell, Bash) for automation and connector development.
- Experience managing on‑prem PAM deployments at scale, including multi‑region and cloud transition plans.
- Knowledge of NIST 800‑53, Zero‑Trust principles, and regulatory compliance related to privileged access.
- Familiarity with DevOps tools (Jenkins, GitLab, Concourse) and secret management solutions (Conjur, AAM).
- Excellent troubleshooting, incident response, and performance tuning skills.
- Effective communication and training capabilities for technical and non‑technical audiences.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field.
- CyberArk Certified PAM Engineer (CPAM) or equivalent PAM certification.
- Relevant certifications in security (CISSP, CISM, or CompTIA Security+) are a plus.