Be Part Of A High-Performing Team
Join a cybersecurity organization supporting a global biopharmaceutical enterprise with a strong focus on securing privileged identities, infrastructure, applications, and cloud environments. The team is advancing an established CyberArk environment and needs a senior hands-on engineer who can assess its current maturity, identify technical and security gaps, and shape the next phase of its privileged-access strategy.
This is a combination of deep technical engineering, architecture assessment, implementation, and roadmap development. The successful candidate will work closely with cybersecurity, infrastructure, cloud, IAM, application, and operational teams to modernize privileged-access controls across the enterprise.
What's In Store For You
-
Engagement: W2 only (no C2C/1099)
-
Work model: Remote within the United States
- Full-time, long-term engagement
- Opportunity to influence both CyberArk architecture and hands-on implementation
- Broad exposure across PAM, EPM, SIA, JIT access, secrets management, cloud infrastructure, and enterprise application integrations
How You Will Make An Impact
- Assess the existing CyberArk environment, including architecture, configuration, integrations, policies, operational procedures, platform health, and adoption maturity.
- Identify security gaps, technical debt, unused capabilities, architectural weaknesses, and opportunities to strengthen privileged-access controls.
- Develop current-state and target-state CyberArk architectures along with a prioritized remediation and implementation roadmap.
- Design, implement, and optimize CyberArk Cloud/SaaS capabilities across privileged accounts, service accounts, applications, infrastructure, and cloud environments.
- Lead hands-on implementation and optimization of CyberArk Endpoint Privilege Manager, including policies, elevation rules, application control, agent deployment, exceptions, and ongoing tuning.
- Design and implement CyberArk Secure Infrastructure Access for secure access to Windows, Linux, cloud, and other infrastructure.
- Implement Just-in-Time privileged-access workflows that reduce standing privileges and enforce time-bound access.
- Configure and optimize CPM-based password rotation, verification, and reconciliation.
- Implement PSM-based privileged-session access, monitoring, recording, and secure administrative workflows.
- Lead onboarding of applications, databases, service accounts, APIs, machine identities, network devices, SaaS applications, and infrastructure.
- Strengthen enterprise secrets-management practices and application credential consumption.
- Build integrations between CyberArk and identity providers, cloud platforms, ITSM, SIEM, monitoring, ticketing, and enterprise applications.
- Develop automation using PowerShell, Python, REST APIs, and CyberArk capabilities to improve onboarding, discovery, reporting, and platform operations.
- Create architecture standards, onboarding guidelines, SOPs, operating procedures, use cases, and knowledge-transfer documentation.
Do You Have the Expertise to Lead CyberArk PAM & EPM Transformation?
- 5–8+ years of hands-on CyberArk PAM implementation and engineering experience.
- Strong recent experience with CyberArk Cloud/SaaS.
- Hands-on design, implementation, and operational expertise with CyberArk Endpoint Privilege Manager.
- Demonstrated CyberArk Secure Infrastructure Access implementation experience.
- Demonstrated Just-in-Time privileged-access implementation experience.
- Experience conducting CyberArk current-state assessments and architecture reviews.
- Ability to define target-state PAM architecture and develop a prioritized implementation roadmap.
- Strong working knowledge of CPM, PSM, password rotation, reconciliation, privileged-session management, and account lifecycle processes.
- Experience onboarding application accounts, service accounts, systems, databases, infrastructure, and other privileged identities.
- Hands-on secrets-management experience.
- Experience securing privileged access across Windows and Linux environments.
- Experience integrating CyberArk with enterprise identity/authentication platforms.
- Experience using PowerShell, Python, REST APIs, or comparable automation capabilities.
- Experience collaborating with application, infrastructure, cloud, IAM, security, and vendor teams.
- Relevant CyberArk Defender, Sentry, Cloud, or implementation/delivery credentials are preferred.
- CISSP is beneficial but not required.