Role description
We are seeking a highly experienced CyberArk L3 Engineer / Subject Matter Expert (SME) to lead the engineering, administration, and continuous improvement of enterprise Identity & Access Management (IAM), Identity Governance & Administration (IGA), and Privileged Access Management (PAM) platforms.
The ideal candidate will possess deep expertise in CyberArk, Microsoft Entra ID (Azure AD), Active Directory, cloud identity, authentication technologies, and enterprise security architecture. This role requires providing L3 support, platform engineering, solution design, technical leadership, automation, and strategic guidance across large-scale global environments while ensuring the security, scalability, and availability of enterprise identity services.
Key Responsibilities CyberArk Platform Engineering
- Design, deploy, configure, administer, and support the CyberArk Privileged Access Management platform.
- Manage CyberArk components including:
- Digital Vault
- PVWA
- CPM
- PSM
- PSMP
- Conjur
- Endpoint Privilege Manager (EPM)
- CyberArk Identity
- Perform platform installation, upgrades, migrations, patching, disaster recovery testing, performance tuning, and health assessments.
- Configure privileged account onboarding, safes, password rotation, reconciliation accounts, and privileged session management.
- Integrate CyberArk with enterprise applications, databases, directories, cloud platforms, and authentication services.
- Troubleshoot complex production issues and provide L3 support.
Identity & Access Management (IAM)
- Design and implement enterprise IAM solutions across hybrid and cloud environments.
- Configure and support:
- Single Sign-On (SSO)
- Multi-Factor Authentication (MFA)
- Passwordless Authentication
- Adaptive Authentication
- Conditional Access Policies
- Implement secure Joiner-Mover-Leaver (JML) lifecycle processes.
- Design Zero Trust identity architectures following least privilege principles.
- Partner with application owners to implement secure authentication and authorization mechanisms.
Microsoft Entra ID (Azure AD)
- Administer Microsoft Entra ID and hybrid identity environments.
- Configure and manage:
- Conditional Access
- Identity Protection
- Authentication Strengths
- Lifecycle Workflows
- Administrative Units
- Cross-Tenant Access
- Access Reviews
- Implement and administer Microsoft Entra Privileged Identity Management (PIM).
- Secure enterprise applications, service principals, managed identities, and application registrations.
Identity Governance & Administration (IGA)
- Implement automated identity lifecycle management using platforms such as:
- SailPoint IdentityIQ
- SailPoint IdentityNow
- Saviynt
- Omada
- One Identity
- IBM Verify Governance
- Design and implement:
- Role-Based Access Control (RBAC)
- Segregation of Duties (SoD)
- Birthright Access
- Access Request Workflows
- Certification Campaigns
- Role Mining
- Integrate HR systems, enterprise applications, directories, and cloud services for automated provisioning and deprovisioning.
- Ensure compliance with governance policies and regulatory requirements.
Privileged Access Management
Provide technical expertise across enterprise PAM technologies including:
- CyberArk
- Delinea (Thycotic)
- BeyondTrust
- HashiCorp Vault
- One Identity Safeguard
- ARCON PAM
- Microsoft Entra PIM
- AWS IAM
- Google Cloud IAM
- Assess existing privileged environments and recommend security improvements.
- Design scalable and resilient privileged access architectures.
Active Directory & Hybrid Identity
- Administer enterprise Active Directory environments across multiple forests and domains.
- Implement:
- Tier-0 Security
- Privileged Access Workstations (PAW)
- Group Policy Security Baselines
- LDAP & Kerberos Authentication
- Hybrid Identity Services
- Monitor AD health, replication, and security.
Cloud Identity & Security
- Implement identity security solutions across:
- Microsoft Azure
- AWS
- Google Cloud Platform (GCP)
- Integrate enterprise applications using:
- SAML
- OAuth 2.0
- OpenID Connect (OIDC)
- LDAP
- SCIM
- Kerberos
- RADIUS
- REST APIs
- SOAP
Support integrations with enterprise platforms including:
- SAP
- Oracle
- Salesforce
- ServiceNow
- Workday
- Microsoft 365
- Azure
- AWS
- Windows Servers
- Linux/Unix
- Databases
- Network Infrastructure
Automation & Platform Optimization
- Develop automation using:
- PowerShell
- Python
- Bash
- Azure CLI
- REST APIs
- CyberArk APIs
- Improve operational efficiency through scripting, orchestration, and automation.
- Drive continuous platform optimization and standardization.
Security, Compliance & Governance
- Ensure compliance with:
- ISO 27001
- NIST
- CIS Controls
- SOX
- GDPR
- PCI-DSS
- HIPAA
- Cyber Essentials
- Support internal and external audits.
- Perform privileged access reviews, vulnerability remediation, and compliance assessments.
- Participate in major incident management, change implementation, platform maintenance, and on-call support.
- Develop operational documentation, SOPs, knowledge articles, and technical runbooks.
Leadership & Stakeholder Management
- Serve as the technical SME for CyberArk, IAM, IGA, and PAM technologies.
- Collaborate with security architects, infrastructure teams, application owners, auditors, project managers, and vendors.
- Provide technical leadership, mentoring, and best practice guidance.
- Identify opportunities to improve security posture through automation, modernization, and platform enhancements.
Required Skills & Experience
- 10+ years of overall IT experience.
- 7+ years of hands-on experience in Identity & Access Management (IAM).
- 5+ years of enterprise CyberArk engineering and administration experience.
- Experience supporting large-scale global enterprise environments.
- Proven experience in L3 production support, platform engineering, upgrades, migrations, disaster recovery, and cloud transformation initiatives.
- CyberArk PAM Suite (Vault, PVWA, CPM, PSM, PSMP, Conjur, EPM, Identity)
- Microsoft Entra ID (Azure AD)
- Active Directory & Hybrid Identity
- Microsoft Entra PIM
- Identity Governance platforms (SailPoint, Saviynt, Omada, One Identity, IBM Verify Governance)
- IAM & PAM Architecture
- SSO, MFA, Conditional Access, Passwordless Authentication
- RBAC & Segregation of Duties (SoD)
- Active Directory Security & Tier-0 Administration
- Azure, AWS, and GCP Identity Services
- Authentication & Federation (SAML, OAuth 2.0, OIDC, LDAP, SCIM, Kerberos)
- PowerShell, Python, Bash, REST APIs, Azure CLI
Skills
High Availability and Disaster Recovery, Privileged Access Management, PowerShell, Identity Governance
About UST
UST is a global digital transformation solutions provider. For more than 20 years, UST has worked side by side with the world’s best companies to make a real impact through transformation. Powered by technology, inspired by people and led by purpose, UST partners with their clients from design to operation. With deep domain expertise and a future-proof philosophy, UST embeds innovation and agility into their clients’ organizations. With over 30,000 employees in 30 countries, UST builds for boundless impact—touching billions of lives in the process.