Service Account & Application Credential Management
- Discover and onboard service accounts.
- Implement credential rotation and reconciliation.
- Manage application secrets using:
- CyberArk AAM
- CyberArk Conjur
- Secure DevOps and CI/CD privileged credentials.
Session Management & Monitoring
- Configure privileged session monitoring and recording.
- Review session recordings during investigations.
- Define alerting and anomaly detection rules.
- Support incident response and forensic investigations.
Cloud & Hybrid PAM
- Integrate CyberArk with:
- Microsoft Entra ID
- Active Directory
- Azure
- AWS
- GCP
- Kubernetes
- Implement cloud privilege governance.
- Secure privileged access for SaaS platforms.
Architecture & Governance
- Define CyberArk standards and best practices.
- Develop PAM roadmaps and implementation strategies.
- Support audits and compliance initiatives.
- Create technical documentation and operational procedures.
Experience Requirements
- 15+ years in Cybersecurity or IAM.
- 12+ years administering and engineering CyberArk PAM.
- Experience with large-scale CyberArk deployments.
- Experience with service account governance and secrets management.
- Experience supporting enterprise environments with strict compliance requirements.
For both roles, the resource should be capable of:
- Leading technical design workshops.
- Acting as an escalation point for L1/L2 teams.
- Creating architecture standards and governance frameworks.
- Driving remediation of security findings.
- Leading IAM/PAM projects independently.
- Mentoring junior engineers and operations teams.
- Engaging with auditors, security architects, and senior stakeholders.
Required Qualifications (Must Have)
- Extensive experience in Active Directory engineering within enterprise environments
- Proven, hands-on expertise in:
- Active Directory Tiering model (Tier 0 / Tier 1 / Tier 2) mandatory
- Microsoft Entra ID (Azure AD)
- Conditional Access (design & enforcement)
- Privileged Identity Management (PIM)
- Group Policy (GPO)
- Hybrid identity (AD Connect / Entra ID sync)
- Strong experience with:
- Access governance and access reviews
- Identity security and privileged access controls
- Advanced troubleshooting (AD, authentication, identity sync)
- Proven ability to operate as a expert engineer / SME / technical lead
- Mandatory Microsoft Certifications
- Microsoft Certified: Identity and Access Administrator Associate (SC-300)
- Microsoft Certified: Windows Server Hybrid Administrator Associate (AZ-800 & AZ-801)
Preferred / Nice to Have
- Experience with PKI / Certificate Services
- Knowledge of Identity Protection and Zero Trust models
- Exposure to ISO 27001 / audit / compliance frameworks
- Microsoft Certified: Cybersecurity Architect Expert (SC-100)
Key Competencies
- Robust security-first mindset
- Deep understanding of privileged access risks and AD Tiering enforcement
- Ability to drive and influence identity architecture decisions
- Strong ownership and accountability in critical environments
- Excellent problem-solving and advanced troubleshooting skills
- Ability to collaborate across security, cloud, and infrastructure teams
Ideal Candidate
- A senior identity expert who owns Active Directory Tiering end-to-end, has strong command of Microsoft Entra ID, Conditional Access, and PIM, and can drive identity security maturity across hybrid environments.
Become an Atid!
Disclaimer : This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 CyberArk PAM Architect (India)
🏢 Atidan Technologies
📍 India
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.