Source description
About the role
Role Description We are seeking a highly experienced CyberArk L3 Engineer / Subject Matter Expert (SME) to lead the engineering, administration, and continuous improvement of enterprise Identity & Access Management (IAM), Identity Governance & Administration (IGA), and Privileged Access Management (PAM) platforms. The ideal candidate will possess deep expertise in CyberArk, Microsoft Entra ID (Azure AD), Active Directory, cloud identity, authentication technologies, and enterprise security architecture. This role requires providing L3 support, platform engineering, solution design, technical leadership, automation, and strategic guidance across large-scale global environments while ensuring the security, scalability, and availability of enterprise identity services. Key Responsibilities CyberArk Platform Engineering Design, deploy, configure, administer, and support the CyberArk Privileged Access Management platform.Manage CyberArk components including:Digital VaultPVWACPMPSMPSMPConjurEndpoint Privilege Manager (EPM)CyberArk IdentityPerform platform installation, upgrades, migrations, patching, disaster recovery testing, performance tuning, and health assessments.Configure privileged account onboarding, safes, password rotation, reconciliation accounts, and privileged session management.Integrate CyberArk with enterprise applications, databases, directories, cloud platforms, and authentication services.Troubleshoot complex production issues and provide L3 support. Identity & Access Management (IAM) Design and implement enterprise IAM solutions across hybrid and cloud environments.Configure and support:Single Sign-On (SSO)Multi-Factor Authentication (MFA)Passwordless AuthenticationAdaptive AuthenticationConditional Access PoliciesImplement secure Joiner-Mover-Leaver (JML) lifecycle processes.Design Zero Trust identity architectures following least privilege principles.Partner with application owners to implement secure authentication and authorization mechanisms. Microsoft Entra ID (Azure AD) Administer Microsoft Entra ID and hybrid identity environments.Configure and manage:Conditional AccessIdentity ProtectionAuthentication StrengthsLifecycle WorkflowsAdministrative UnitsCross-Tenant AccessAccess ReviewsImplement and administer Microsoft Entra Privileged Identity Management (PIM).Secure enterprise applications, service principals, managed identities, and application registrations. Identity Governance & Administration (IGA) Implement automated identity lifecycle management using platforms such as:SailPoint IdentityIQSailPoint IdentityNowSaviyntOmadaOne IdentityIBM Verify GovernanceDesign and implement:Role-Based Access Control (RBAC)Segregation of Duties (SoD)Birthright AccessAccess Request WorkflowsCertification CampaignsRole MiningIntegrate HR systems, enterprise applications, directories, and cloud services for automated provisioning and deprovisioning.Ensure compliance with governance policies and regulatory requirements. Privileged Access Management Provide Technical Expertise Across Enterprise PAM Technologies Including CyberArkDelinea (Thycotic)BeyondTrustHashiCorp VaultOne Identity SafeguardARCON PAMMicrosoft Entra PIMAWS IAMGoogle Cloud IAMAssess existing privileged environments and recommend security improvements.Design scalable and resilient privileged access architectures. Active Directory & Hybrid Identity Administer enterprise Active Directory environments across multiple forests and domains.Implement:Tier-0 SecurityPrivileged Access Workstations (PAW)Group Policy Security BaselinesLDAP & Kerberos AuthenticationHybrid Identity ServicesMonitor AD health, replication, and security. Cloud Identity & Security Implement identity security solutions across:Microsoft AzureAWSGoogle Cloud Platform (GCP)Integrate enterprise applications using:SAMLOAuth 2.0OpenID Connect (OIDC)LDAPSCIMKerberosRADIUSREST APIsSOAP Support Integrations With Enterprise Platforms Including SAPOracleSalesforceServiceNowWorkdayMicrosoft 365AzureAWSWindows ServersLinux/UnixDatabasesNetwork Infrastructure Automation & Platform Optimization Develop automation using:PowerShellPythonBashAzure CLIREST APIsCyberArk APIsImprove operational efficiency through scripting, orchestration, and automation.Drive continuous platform optimization and standardization. Security, Compliance & Governance Ensure compliance with:ISO 27001NISTCIS ControlsSOXGDPRPCI-DSSHIPAACyber EssentialsSupport internal and external audits.Perform privileged access reviews, vulnerability remediation, and compliance assessments.Participate in major incident management, change implementation, platform maintenance, and on-call support.Develop operational documentation, SOPs, knowledge articles, and technical runbooks. Leadership & Stakeholder Management Serve as the technical SME for CyberArk, IAM, IGA, and PAM technologies.Collaborate with security architects, infrastructure teams, application owners, auditors, project managers, and .
More at UST
Related open roles
Sr. Security Specialist (Vulnerability Management)
Chennai
Sr. Security Specialist (Vulnerability Management)
Hyderabad
Senior Security Assurance Analyst (GRC)
India
Sr. Security Specialist (Vulnerability Management)
India
Senior Security Assurance Analyst (GRC)
India
Sr. Security Specialist (Vulnerability Management) (Bengaluru)
Bangalore