12 Aug
|
Bounteous
|
Bengaluru
12 Aug
Bounteous
Bengaluru
Job Title: CyberArk Architect
Exp: 10 to 15 Yrs
Location: Bangalore, Hyderabad, Gurugram, Chennai, Mumbai and Pune
We are looking for freelance consultant to support for a critical engagement on an hourly basis. This is immediate need.
Please apply if you are a CyberArk Technical Architect, available immediately as a freelance consultant.
Engagement:
Client-facing, consulting / systems integration delivery
About the role
We are seeking a CyberArk Architect to lead solution design for a large-scale, TSA-regulated Privileged Access Management (PAM) migration and merger consolidation programme. This is a hands-on architecture role spanning vault migration design, identity federation, and application onboarding strategy for an estate spanning thousands of accounts and 250+ dependent applications, delivered against a fixed regulatory deadline.
Key responsibilities
Migration & vault architecture
- Design the end-to-end migration architecture from CyberArk v12.2 to v14.2, covering entity extraction (REST API primary, PACLI fallback), transformation, reconciliation, and staged loading into the target vault.
- Define the staged-ingestion model: disabled import → CPM soft-verification → dual-run mirroring → forced rotation at cutover — ensuring no credential is exposed to a script or human during migration.
- Own name-collision resolution, platform normalisation, and policy reconciliation rules between source and target environments.
- Produce migration runbooks, RAID logs, and effort-sizing models across Safes, Accounts, Platforms, and Policies.
Application & credential provider (CP/CCP) strategy
- Lead discovery to segment the 250+ dependent applications by integration pattern (CP agent, CCP centralised, Conjur, direct SSO)
— the primary driver of onboarding sequencing and timeline risk.
- Design the CP/CCP re-onboarding approach, including AppID re-provisioning, certificate/mTLS re-issuance, and phased cutover waves.
- Define rollback and dual-run strategy per wave, including the read-only fallback window on the source vault.
Identity federation & MFA
- Design PVWA federation to Entra ID via SAML/OIDC, including claims mapping from Entra groups to CyberArk Vault Users and Safe membership.
- Architect the RSA SecurID → Entra MFA migration as a re-enrolment exercise, covering Conditional Access policy design and non-web/legacy client bridging (PrivateArk, PACLI, RADIUS-dependent flows).
- Ensure High Side / Low Side segregation is preserved across all federation and migration data flows, with no entitlement detail crossing the DMZ boundary.
Governance, compliance & stakeholder leadership
- Own architecture decisions and trade-offs; present designs to client security, compliance, and PAM leadership for sign-off.
- Ensure all migration and access-control designs produce audit evidence sufficient for TSA compliance reporting.
- Evaluate and position complementary tooling (e.g. Hydden for continuous identity discovery) against native CyberArk capability.
- Define acceptance criteria and go/no-go gates for pilot and production wave sign-off.
- Mentor and provide technical direction to CyberArk Senior Engineers delivering the build.
Required experience & skills
- 10+ years in Identity and Access Management, with 5+ years specifically in CyberArk PAM architecture and design.
- Deep hands-on knowledge of CyberArk EPV, PVWA, CPM, PSM, AAM/CCP, and Vault architecture across on-prem and Privilege Cloud deployments.
- Proven experience leading a CyberArk version migration (v10/v11/v12 → v13/v14) at enterprise scale.
- Robust working knowledge of SAML 2.0 and OIDC federation design, including experience integrating CyberArk PVWA with an enterprise IdP (Entra ID, Okta, or equivalent).
- Experience with credential provider architectures (CP, CCP) and application onboarding at scale (100+ application estates).
- Familiarity with MFA migration projects (e.g. RSA SecurID to a cloud MFA/Conditional Access model).
- Experience operating in regulated environments (financial services, telecom, or government) with formal change control and audit evidence requirements.
- Strong client-facing communication skills; able to present architecture to both technical and executive stakeholders.
Preferred / nice to have
- CyberArk certification — CyberArk Defender, Sentry, or Guardian.
- Experience with SailPoint IdentityIQ or IdentityNow integration alongside CyberArk (joint IGA/PAM programmes).
- Exposure to identity data/discovery platforms (e.g. Hydden) for cross-platform reconciliation.
- Experience with M&A-driven; identity consolidation programmes (merging two organisations' identity estates).
- Familiarity with using AI-assisted delivery tooling (e.g. Claude Code, Copilot) to accelerate script and runbook development, distinct from runtime AI in the access path.
📌 Solutions Architect (Bengaluru)
🏢 Bounteous
📍 Bengaluru