CyberArk PAM Engineer
We are looking for a hands-on CyberArk PAM engineer to build, upgrade, and support enterprise Privileged Access Management environments, and to onboard and integrate privileged accounts across a mixed Windows, Linux, database, and network estate.
Key Responsibilities
- Install, configure, troubleshoot, and maintain the CyberArk PAM implementation.
- Create, maintain, and monitor CyberArk PAM policy configurations for password and session management.
- Integrate various target platforms (such as LDAP, Windows, Unix, Databases, Network devices, etc.) with CyberArk PAM for credential rotation (CPM).
- Configure CPM connectors and related policies.
- Perform privileged account onboarding and connector management.
- Troubleshoot issues with account onboarding, password management, session management, and proxy session connections through deep-dive investigations.
- Perform CyberArk PAS integrations with supporting systems for Authentication, Authorization, Notifications, IT Service Management, etc.
- Provide support for planned maintenance activities such as patching, DR/failover testing, and environment health checks.
- Build and deploy new CyberArk PAM environments end to end (Vault, PVWA, CPM, PSM, PSMP), including hardening, HA/DR configuration, and post-build validation.
- Plan and execute CyberArk version upgrades, both in-place and side-by-side, including pre-upgrade compatibility assessment, component sequencing, rollback planning, and post-upgrade regression testing.
- Lead CyberArk migrations legacy vault to new hardware/OS, data centre relocation, on-premises to Privilege Cloud, and safe/account migration between environments — with data integrity checks and cutover validation.
- Develop clear and concise documentation and liaise with the PAM support team to facilitate day-to-day operations.
Required Candidate Profile
- Minimum 5 years of hands-on CyberArk PAM experience.
Experience with other PAM vendor products (BeyondTrust,
Delinea, HashiCorp Vault) is an additional asset.
- Hands-on experience with day-to-day CyberArk administration and operational support, including protected and platform management, account onboarding, and access request handling.
- Demonstrated experience building CyberArk PAM environments from the ground up, including Vault, PVWA, CPM, PSM and PSMP installation, hardening, and integration with existing infrastructure.
- Proven experience planning and executing CyberArk version upgrades across all components, including pre-upgrade assessment, sequencing, rollback planning, and post-upgrade validation.
- Experience migrating CyberArk environments — hardware/OS refresh, data centre or cloud relocation, on-premises to Privilege Cloud, and safe/account migration between vaults.
- Experience in deploying and/or maintaining HA/DR PAM environments.
- Strong understanding of IAM/PAM environments and exposure to IT infrastructure components such as Active Directory, Windows and Linux server operating systems, network devices, virtualization, etc.
- PAM architecture and design experience is an asset.
- Good understanding of business, audit, and regulatory drivers is an asset.
- Good understanding of data centre networking concepts.
- Positive understanding of the main operating systems (Windows/Linux/AIX).
- Good understanding of information security concepts (Confidentiality, Integrity, Availability).
- General knowledge of security and technology standards (e.g., infrastructure, architecture, processes, applications).
- Good communication in both written and verbal areas.
- Proactive team player with effective time management skills; ability to work independently, manage multiple deadlines/projects and keep key players informed.
Education and Accreditations
- University or college degree (BE/BTech/ME/MTech), or equivalent experience with suitable security designation.
- PAM vendor certifications such as CyberArk PAM Certified Delivery Engineer (CDE-PAM) would be an asset.
📌 Cyberark Engineer (Noida)
🏢 SDG
📍 Noida