We are seeking a highly experienced CyberArk L3 Engineer / Subject Matter Expert (SME) to lead the engineering, administration, and continuous improvement of enterprise Identity & Access Management (IAM), Identity Governance & Administration (IGA), and Privileged Access Management (PAM) platforms.
The ideal candidate will possess deep expertise in CyberArk , Microsoft Entra ID (Azure AD) , Active Directory , cloud identity , authentication technologies, and enterprise security architecture. This role requires providing L3 support, platform engineering, solution design, technical leadership, automation, and strategic guidance across large-scale global environments while ensuring the security, scalability, and availability of enterprise identity services.
Key Responsibilities CyberArk Platform Engineering
- Design, deploy, configure, administer, and support the CyberArk Privileged Access Management platform.
- Digital Vault
- PVWA
- CPM
- PSM
- PSMP
- Conjur
- Endpoint Privilege Manager (EPM)
- CyberArk Identity
- Perform platform installation, upgrades, migrations, patching, disaster recovery testing, performance tuning, and health assessments.
- Configure privileged account onboarding, safes, password rotation, reconciliation accounts, and privileged session management.
- Integrate CyberArk with enterprise applications, databases, directories, cloud platforms, and authentication services.
- Troubleshoot complex production issues and provide L3 support.
Identity & Access Management (IAM)
- Design and implement enterprise IAM solutions across hybrid and cloud environments.
- Single Sign-On (SSO)
- Multi-Factor Authentication (MFA)
- Passwordless Authentication
- Adaptive Authentication
- Conditional Access Policies
- Implement secure Joiner-Mover-Leaver (JML) lifecycle processes.
- Design Zero Trust identity architectures following least privilege principles.
- Partner with application owners to implement secure authentication and authorization mechanisms.
Microsoft Entra ID (Azure AD)
- Administer Microsoft Entra ID and hybrid identity environments.
- Conditional Access
- Identity Protection
- Authentication Strengths
- Lifecycle Workflows
- Administrative Units
- Cross-Tenant Access
- Access Reviews
- Implement and administer Microsoft Entra Privileged Identity Management (PIM).
- Secure enterprise applications, service principals, managed identities, and application registrations.
Identity Governance & Administration (IGA)
- SailPoint IdentityIQ
- SailPoint IdentityNow
- Saviynt
- Omada
- One Identity
- IBM Verify Governance
- Role-Based Access Control (RBAC)
- Segregation of Duties (SoD)
- Birthright Access