PAM Engineer/CyberArk Implementation SME
PAM Engineer, CyberArk implementation, Data Cleansing, Automation, Python or PowerShell, IDM, Active Directory, Linux, Azure, AWS, GCP
We are working with a leading investment banking client based in London to secure for them a PAM (privileged access management ) Engineer/CyberArk SME. We are looking for highly experienced CyberArk PAM Engineer to lead the design, implementation, and optimisation of CyberArk solutions across the banks infrastructure.
- Act as SME for CyberArk SaaS migration and metadata clean-up in major PAM transformation project.
- Administer and maintain CyberArk Vault, users, groups, policies, and security settings.
- Automate onboarding, rotation, and decommissioning of privileged credentials.
- Plan and deliver CyberArk upgrades, health checks, and post-upgrade assurance.
- Define Safes, RBAC, and master policies aligned to NIST and Zero Trust.
- Build automation scripts for privileged account onboarding.
- Develop and support custom CPM and PSM connectors.
- Provide SME support for incidents, troubleshooting, and operational issues.
- Maintain HLD, LLD, and knowledge base documentation.
- Support vaulting, Safe creation, and junior team members.
- Senior CyberArk PAM engineer with hands-on implementation experience, not only BAU support.
- Strong experience in CyberArk Vault, PVWA, CPM, PSM, PSMP, CCP/AAM and ideally CyberArk SaaS/Privilege Cloud.
- Proven delivery of CyberArk upgrades, migrations, onboarding, policy design, connector development, and automation.
- Solid infrastructure knowledge across Active Directory, Windows Server, Linux, RDP, SSH, service accounts, certificates, and cloud platforms.
- Experience in regulated enterprise environments, ideally financial services, where audit, compliance, change control, and secure operations are important.
- Strong automation capability using PowerShell, REST APIs, Python or Bash.
- CyberArk Vault (Both PAS On Prem or SaaS)
- PVWA
- CPM
- PSM
- PSMP
- PTA
- CCP/AAM/AIM
- Conjur/Secret Manager
- Password rotation
- Component troubleshooting
- PAS Reporter
- Discovery and onboarding
- PSM connection components
- Custom connection components
- Active Directory (Users, Groups, GPOs, LDAP, Kerberos)
- Windows Server administration
- Service account management
- RDP and Windows authentication troubleshooting
- Linux administration (RHEL)
- SSH key management
- Azure/AWS/GCP fundamentals
- Entra ID (Azure AD)
- Cloud privileged access
- Zero Trust concepts
- JIT/JEA/Zero Standing Privilege
- PowerShell
- REST API
- Python
- Bash