Source description
About the role
We are seeking a highly experienced CyberArk L3 Engineer / Subject Matter Expert (SME) to lead the engineering, administration, and continuous improvement of enterprise Identity & Access Management (IAM), Identity Governance & Administration (IGA), and Privileged Access Management (PAM) platforms. The ideal candidate will possess deep expertise in CyberArk , Microsoft Entra ID (Azure AD) , Active Directory , cloud identity , authentication technologies, and enterprise security architecture. This role requires providing L3 support, platform engineering, solution design, technical leadership, automation, and strategic guidance across large-scale global environments while ensuring the security, scalability, and availability of enterprise identity services. Key Responsibilities CyberArk Platform Engineering
Design, deploy, configure, administer, and support the CyberArk Privileged Access Management platform. Manage CyberArk components including:
Digital Vault PVWA CPM PSM PSMP Conjur Endpoint Privilege Manager (EPM) CyberArk Identity
Perform platform installation, upgrades, migrations, patching, disaster recovery testing, performance tuning, and health assessments. Configure privileged account onboarding, safes, password rotation, reconciliation accounts, and privileged session management. Integrate CyberArk with enterprise applications, databases, directories, cloud platforms, and authentication services. Troubleshoot complex production issues and provide L3 support.
Identity & Access Management (IAM)
Design and implement enterprise IAM solutions across hybrid and cloud environments. Configure and support:
Single Sign-On (SSO) Multi-Factor Authentication (MFA) Passwordless Authentication Adaptive Authentication Conditional Access Policies
Implement secure Joiner-Mover-Leaver (JML) lifecycle processes. Design Zero Trust identity architectures following least privilege principles. Partner with application owners to implement secure authentication and authorization mechanisms.
Microsoft Entra ID (Azure AD)
Administer Microsoft Entra ID and hybrid identity environments. Configure and manage:
Conditional Access Identity Protection Authentication Strengths Lifecycle Workflows Administrative Units Cross-Tenant Access Access Reviews
Implement and administer Microsoft Entra Privileged Identity Management (PIM). Secure enterprise applications, service principals, managed identities, and application registrations.
Identity Governance & Administration (IGA)
Implement automated identity lifecycle management using platforms such as:
SailPoint IdentityIQ SailPoint IdentityNow Saviynt Omada One Identity IBM Verify Governance
Design and implement:
Role-Based Access Control (RBAC)
Segregation of Duties (SoD) Birthright Access Access Request Workflows Certification Campaigns Role Mining
Integrate HR systems, enterprise applications, directories, and cloud services for automated provisioning and deprovisioning. Ensure compliance with governance policies and regulatory requirements.
Privileged Access Management Provide technical expertise across enterprise PAM technologies including:
CyberArk Delinea (Thycotic) BeyondTrust HashiCorp Vault One Identity Safeguard ARCON PAM Microsoft Entra PIM AWS IAM Google Cloud IAM Assess existing privileged environments and recommend security improvements. Design scalable and resilient privileged access architectures.
Active Directory & Hybrid Identity
Administer enterprise Active Directory environments across multiple forests and domains. Implement:
Tier-0 Security Privileged Access Workstations (PAW) Group Policy Security Baselines LDAP & Kerberos Authentication Hybrid Identity Services
Monitor AD health, replication, and security.
Cloud Identity & Security
Implement identity security solutions across:
Microsoft Azure AWS Google Cloud Platform (GCP)
Integrate enterprise applications using:
SAML OAuth 2.0 OpenID Connect (OIDC) LDAP SCIM Kerberos RADIUS REST APIs SOAP
Support integrations with enterprise platforms including:
SAP Oracle Salesforce ServiceNow Workday Microsoft 365 Azure AWS Windows Servers Linux/Unix Databases Network Infrastructure
Automation & Platform Optimization
Develop automation using:
PowerShell Python Bash Azure CLI REST APIs CyberArk APIs
Improve operational efficiency through scripting, orchestration, and automation. Drive continuous platform optimization and standardization.
Security, Compliance & Governance
Ensure compliance with:
ISO 27001 NIST CIS Controls SOX GDPR PCI-DSS HIPAA Cyber Essentials
Support internal and external audits. Perform privileged access reviews, vulnerability remediation, and compliance assessments. Participate in major incident management, change implementation, platform maintenance, and on-call support. Develop operational documentation, SOPs, knowledge articles, and technical runbooks.
Leadership & Stakeholder Management
Serve as the technical SME for CyberArk, IAM, IGA, and PAM technologies. Collaborate with security architects, infrastructure teams, application owners, auditors, project managers, and vendors. Provide technical leadership, mentoring, and best practice guidance. Identify opportunities to improve security posture through automation, modernization, and platform enhancements.
Required Skills & Experience Experience
10+ years of overall IT experience. 7+ years of hands-on experience in Identity & Access Management (IAM). 5+ years of enterprise CyberArk engineering and administration experience. Experience supporting large-scale global enterprise environments. Proven experience in L3 production support, platform engineering, upgrades, migrations, disaster recovery, and cloud transformation initiatives.
Mandatory Technical Skills
CyberArk PAM Suite (Vault, PVWA, CPM, PSM, PSMP, Conjur, EPM, Identity) Microsoft Entra ID (Azure AD) Active Directory & Hybrid Identity Microsoft Entra PIM Identity Governance platforms (SailPoint, Saviynt, Omada, One Identity, IBM Verify Governance) IAM & PAM Architecture SSO, MFA, Conditional Access, Passwordless Authentication RBAC & Segregation of Duties (SoD) Active Directory Security & Tier-0 Administration Azure, AWS, and GCP Identity Services Authentication & Federation (SAML, OAuth 2.0, OIDC, LDAP, SCIM, Kerberos) PowerShell, Python, Bash, REST APIs, Azure CLI
High Availability and Disaster Recovery, Privileged Access Management, PowerShell, Identity Governance
More at UST
Related open roles
Lead Ii Data Engineering Python, Aws, Sql Kerala
India
Lead Ii Devops Engineering Chennai
Chennai
Nodejs Developer(Javascript, Nodejs with Express JS, SQL, ReactJS)
Hyderabad
Lead I / Lead II - Fullstack Dev (React, Node JS, Typescript, JavaScript)
India
Developer II - Software Engineering
Chennai
Lead II - Software Engineering
Chennai