Padmi

CyberArk SME L3 Engineer IAM, IGA & PAM

Bangalore · Hyderabad · Chennai · HybridPosted 1 month ago
Software engineeringSenior
Apply at UST

Opens the source posting on usource.ripplehire.com

Source description

About the role

View original

We are seeking a highly experienced CyberArk L3 Engineer / Subject Matter Expert (SME) to lead the engineering, administration, and continuous improvement of enterprise Identity & Access Management (IAM), Identity Governance & Administration (IGA), and Privileged Access Management (PAM) platforms. The ideal candidate will possess deep expertise in CyberArk , Microsoft Entra ID (Azure AD) , Active Directory , cloud identity , authentication technologies, and enterprise security architecture. This role requires providing L3 support, platform engineering, solution design, technical leadership, automation, and strategic guidance across large-scale global environments while ensuring the security, scalability, and availability of enterprise identity services. Key Responsibilities CyberArk Platform Engineering

Design, deploy, configure, administer, and support the CyberArk Privileged Access Management platform. Manage CyberArk components including:

Digital Vault PVWA CPM PSM PSMP Conjur Endpoint Privilege Manager (EPM) CyberArk Identity

Perform platform installation, upgrades, migrations, patching, disaster recovery testing, performance tuning, and health assessments. Configure privileged account onboarding, safes, password rotation, reconciliation accounts, and privileged session management. Integrate CyberArk with enterprise applications, databases, directories, cloud platforms, and authentication services. Troubleshoot complex production issues and provide L3 support.

Identity & Access Management (IAM)

Design and implement enterprise IAM solutions across hybrid and cloud environments. Configure and support:

Single Sign-On (SSO) Multi-Factor Authentication (MFA) Passwordless Authentication Adaptive Authentication Conditional Access Policies

Implement secure Joiner-Mover-Leaver (JML) lifecycle processes. Design Zero Trust identity architectures following least privilege principles. Partner with application owners to implement secure authentication and authorization mechanisms.

Microsoft Entra ID (Azure AD)

Administer Microsoft Entra ID and hybrid identity environments. Configure and manage:

Conditional Access Identity Protection Authentication Strengths Lifecycle Workflows Administrative Units Cross-Tenant Access Access Reviews

Implement and administer Microsoft Entra Privileged Identity Management (PIM). Secure enterprise applications, service principals, managed identities, and application registrations.

Identity Governance & Administration (IGA)

Implement automated identity lifecycle management using platforms such as:

SailPoint IdentityIQ SailPoint IdentityNow Saviynt Omada One Identity IBM Verify Governance

Design and implement:

Role-Based Access Control (RBAC)

Segregation of Duties (SoD) Birthright Access Access Request Workflows Certification Campaigns Role Mining

Integrate HR systems, enterprise applications, directories, and cloud services for automated provisioning and deprovisioning. Ensure compliance with governance policies and regulatory requirements.

Privileged Access Management Provide technical expertise across enterprise PAM technologies including:

CyberArk Delinea (Thycotic) BeyondTrust HashiCorp Vault One Identity Safeguard ARCON PAM Microsoft Entra PIM AWS IAM Google Cloud IAM Assess existing privileged environments and recommend security improvements. Design scalable and resilient privileged access architectures.

Active Directory & Hybrid Identity

Administer enterprise Active Directory environments across multiple forests and domains. Implement:

Tier-0 Security Privileged Access Workstations (PAW) Group Policy Security Baselines LDAP & Kerberos Authentication Hybrid Identity Services

Monitor AD health, replication, and security.

Cloud Identity & Security

Implement identity security solutions across:

Microsoft Azure AWS Google Cloud Platform (GCP)

Integrate enterprise applications using:

SAML OAuth 2.0 OpenID Connect (OIDC) LDAP SCIM Kerberos RADIUS REST APIs SOAP

Support integrations with enterprise platforms including:

SAP Oracle Salesforce ServiceNow Workday Microsoft 365 Azure AWS Windows Servers Linux/Unix Databases Network Infrastructure

Automation & Platform Optimization

Develop automation using:

PowerShell Python Bash Azure CLI REST APIs CyberArk APIs

Improve operational efficiency through scripting, orchestration, and automation. Drive continuous platform optimization and standardization.

Security, Compliance & Governance

Ensure compliance with:

ISO 27001 NIST CIS Controls SOX GDPR PCI-DSS HIPAA Cyber Essentials

Support internal and external audits. Perform privileged access reviews, vulnerability remediation, and compliance assessments. Participate in major incident management, change implementation, platform maintenance, and on-call support. Develop operational documentation, SOPs, knowledge articles, and technical runbooks.

Leadership & Stakeholder Management

Serve as the technical SME for CyberArk, IAM, IGA, and PAM technologies. Collaborate with security architects, infrastructure teams, application owners, auditors, project managers, and vendors. Provide technical leadership, mentoring, and best practice guidance. Identify opportunities to improve security posture through automation, modernization, and platform enhancements.

Required Skills & Experience Experience

10+ years of overall IT experience. 7+ years of hands-on experience in Identity & Access Management (IAM). 5+ years of enterprise CyberArk engineering and administration experience. Experience supporting large-scale global enterprise environments. Proven experience in L3 production support, platform engineering, upgrades, migrations, disaster recovery, and cloud transformation initiatives.

Mandatory Technical Skills

CyberArk PAM Suite (Vault, PVWA, CPM, PSM, PSMP, Conjur, EPM, Identity) Microsoft Entra ID (Azure AD) Active Directory & Hybrid Identity Microsoft Entra PIM Identity Governance platforms (SailPoint, Saviynt, Omada, One Identity, IBM Verify Governance) IAM & PAM Architecture SSO, MFA, Conditional Access, Passwordless Authentication RBAC & Segregation of Duties (SoD) Active Directory Security & Tier-0 Administration Azure, AWS, and GCP Identity Services Authentication & Federation (SAML, OAuth 2.0, OIDC, LDAP, SCIM, Kerberos) PowerShell, Python, Bash, REST APIs, Azure CLI

High Availability and Disaster Recovery, Privileged Access Management, PowerShell, Identity Governance

One address, no account. We’ll tell you when matching roles go live.

More at UST

Related open roles

View all roles