CyberArk Security Engineer
CyberArk Security Engineer
Location: Hybrid 1-2 days Warwick
Job Summary
We are looking for an experienced CyberArk Security Engineer to help secure and manage privileged accounts across the organization. The candidate will work with the CyberArk PAM platform to protect administrator accounts, manage passwords, control privileged access, and monitor privileged sessions.
The ideal candidate should have strong hands-on experience with CyberArk PAM/PAS, PVWA, CPM, PSM, and CyberArk Vault.
Responsibilities
- Manage and support the organization's CyberArk PAM/PAS environment.
- Onboard administrator and other privileged accounts into CyberArk.
- Create and manage CyberArk Safes and permissions.
- Configure password policies, password rotation, and reconciliation.
- Manage CyberArk components including PVWA, CPM, PSM, and Vault.
- Configure and monitor privileged user sessions through PSM.
- Manage user access using RBAC and least-privilege principles.
- Integrate CyberArk with Active Directory, LDAP, SSO, and MFA.
- Troubleshoot CyberArk authentication, access, password, and connectivity issues.
- Support integration of CyberArk with SIEM and security monitoring tools.
- Help identify and resolve privileged-access security issues.
- Support CyberArk upgrades, patches, and configuration changes.
- Automate CyberArk tasks using PowerShell, Python, or REST APIs.
- Work with IAM, cybersecurity, infrastructure, application, and cloud teams.
- Create and maintain CyberArk security documentation and procedures.
- Support security audits and compliance requirements related to privileged access.
Required Skills
- 8+ years of hands-on CyberArk experience.
- Strong experience with CyberArk PAM/PAS.
- Hands-on experience with:
- PVWA
- CPM
- PSM
- CyberArk Vault
- Experience onboarding privileged accounts.
- Experience with Safes, permissions, and access policies.
- Experience with password rotation and reconciliation.
- Experience with privileged session management.
- Good understanding of IAM, RBAC, PAM, and least privilege.
- Experience with Active Directory.
- Knowledge of Windows and Linux environments.
- Understanding of MFA, SSO, and authentication.
- Strong troubleshooting and problem-solving skills.
Preferred Skills
- CyberArk Defender or Sentry certification.
- Experience with CyberArk Conjur / Secrets Management.
- Experience with Azure or AWS.
- Experience with Splunk, Microsoft Sentinel, or other SIEM tools.
- Experience with PowerShell, Python, or REST APIs.
- Experience with CyberArk upgrades and migrations.
- Knowledge of security standards and compliance requirements.