Cybersecurity Architect (Cyberark)
Summary
Designs and maintains the enterprise CyberArk privileged-access management (PAM) architecture for a bank, enforcing least-privilege policies and automating secret rotation across Windows, Linux, cloud platforms, and CI/CD pipelines.
Responsibilities:
- Define and own the enterprise‑wide CyberArk architecture (Vault, CPM, PSM, PVWA, Conjur, ) to support the banks technical accounts inventory.
- Design and enforce privileged‑access policies (least‑privilege, separation‑of‑duties, time‑bound access) across Windows, Linux, UNIX, databases, cloud platforms (AWS, Azure, GCP)
- 3. Provide high-availability support for the CyberArk, establishing robust monitoring, incident-response, and disaster-recovery processes that keep critical services up and running 24×7.
- Drive the secret‑management lifecycle – automatic password rotation, SSH key management, API‑credential vaulting, and on‑demand retrieval.
- Partner with engineering, application, and cloud teams to embed secure identity controls into every new service launch, migration, or platform upgrade.
- Automate PAM processes using PowerShell, Python, and CyberArk REST APIs (e.g., bulk onboarding/off‑boarding, credential rotation schedules).
- Evaluate emerging PAM technologies (e.g., CyberArk Conjur, Secret-Zero, Zero-Trust Privilege) and build business cases for adoption.
- Collaborate with DevSecOps, Cloud, and Application teams to embed privileged-access controls into CI/CD pipelines and cloud-native workload
Requirements:
- Requires a minimum of 8+ years of experience as security professional
- Bachelor’s degree in Computer Science, Information Security, or related field (Master’s ).
- Hands-on experience architecting, deploying, and operating CyberArk PAS (Vault, CPM, PSM, PVWA) at enterprise scale.
- Conjur (CyberArk) – L3 – policy-as-code (CPL/HCL), secret rotation, dynamic secrets, Kubernetes side-car injection, API/CLI integrations
- Deep expertise in CyberArk Core PAS components and CyberArk Privileged Threat Analytics.
- Strong knowledge of Windows/UNIX/Linux authentication mechanisms, Kerberos, LDAP/AD, SSH, database authentication.
- Experience integrating CyberArk with SSO/IdP solutions (SAML, OIDC, AD).
- Proficiency in PowerShell, Python, and CyberArk REST API for automation.
- Familiarity with cloud providers (AWS Secrets Manager, Azure Key Vault) and Hybrid‑IAM environments.
- Solid understanding of Zero‑Trust concepts for privileged access.
- Excellent interpersonal and communication skills; ability to influence and motivate
- Leverage PAM analytics (session recordings, anomaly scores) to drive risk-based decisions
- Ability to handle high pressure situations with key stakeholders to collaborate and communicate effectively and respectfully with both business-oriented executives and technology-oriented personnel in teams across the organization
Specific qualifications:
- CyberArk Certified Defender (CCD)
- Secrets Manager (Conjur) certified
•Work-life balance: Hybrid working mode and 18 days of Annual leave
•Health & insurance: Comprehensive coverage including General Practitioner, hospitalization, dental, and optical
•Performance incentives: Annual bonus based on individual performance
•Learning & development: Training programs, certification opportunities, and training incentives to support career growth
•Team culture: Regular team-building activities and social events