UST logo

CyberArk SME L3 Engineer IAM, IGA & PAM

UST

RemoteFull timeMid levelPosted today
Apply with JobAssist

About the role

Role Description We are seeking a highly experienced CyberArk L3 Engineer / Subject Matter Expert (SME) to lead the engineering, administration, and continuous improvement of enterprise Identity & Access Management (IAM), Identity Governance & Administration (IGA), and Privileged Access Management (PAM) platforms.

The ideal candidate will possess deep expertise in CyberArk , Microsoft Entra ID (Azure AD) , Active Directory , cloud identity , authentication technologies, and enterprise security architecture. This role requires providing L3 support, platform engineering, solution design, technical leadership, automation, and strategic guidance across large-scale global environments while ensuring the security, scalability, and availability of enterprise identity services.

Key Responsibilities CyberArk Platform Engineering

  • Design, deploy, configure, administer, and support the CyberArk Privileged Access Management platform.

  • Manage CyberArk components including:

  • Digital Vault

  • PVWA

  • CPM

  • PSM

  • PSMP

  • Conjur

  • Endpoint Privilege Manager (EPM)

  • CyberArk Identity

  • Perform platform installation, upgrades, migrations, patching, disaster recovery testing, performance tuning, and health assessments.

  • Configure privileged account onboarding, safes, password rotation, reconciliation accounts, and privileged session management.

  • Integrate CyberArk with enterprise applications, databases, directories, cloud platforms, and authentication services.

  • Troubleshoot complex production issues and provide L3 support.

Identity & Access Management (IAM)

  • Design and implement enterprise IAM solutions across hybrid and cloud environments.

  • Configure and support:

  • Single Sign-On (SSO)

  • Multi-Factor Authentication (MFA)

  • Passwordless Authentication

  • Adaptive Authentication

  • Conditional Access Policies

  • Implement secure Joiner-Mover-Leaver (JML) lifecycle processes.

  • Design Zero Trust identity architectures following least privilege principles.

  • Partner with application owners to implement secure authentication and authorization mechanisms.

Microsoft Entra ID (Azure AD)

  • Administer Microsoft Entra ID and hybrid identity environments.

  • Configure and manage:

  • Conditional Access

  • Identity Protection

  • Authentication Strengths

  • Lifecycle Workflows

  • Administrative Units

  • Cross-Tenant Access

  • Access Reviews

  • Implement and administer Microsoft Entra Privileged Identity Management (PIM).

  • Secure enterprise applications, service principals, managed identities, and application registrations.

Identity Governance & Administration (IGA)

  • Implement automated identity lifecycle management using platforms such as:

  • SailPoint IdentityIQ

  • SailPoint IdentityNow

  • Saviynt

  • Omada

  • One Identity

  • IBM Verify Governance

  • Design and implement:

  • Role-Based Access Control (RBAC)

  • Segregation of Duties (SoD)

  • Birthright Access

  • Access Request Workflows

  • Certification Campaigns

  • Role Mining

  • Integrate HR systems, enterprise applications, directories, and cloud services for automated provisioning and deprovisioning.

  • Ensure compliance with governance policies and regulatory requirements.

Privileged Access Management

Provide Technical Expertise Across Enterprise PAM Technologies Including

  • CyberArk
  • Delinea (Thycotic)
  • BeyondTrust
  • HashiCorp Vault
  • One Identity Safeguard
  • ARCON PAM
  • Microsoft Entra PIM
  • AWS IAM
  • Google Cloud IAM
  • Assess existing privileged environments and recommend security improvements.
  • Design scalable and resilient privileged access architectures.

Active Directory & Hybrid Identity

  • Administer enterprise Active Directory environments across multiple forests and domains.

  • Implement:

  • Tier-0 Security

  • Privileged Access Workstations (PAW)

  • Group Policy Security Baselines

  • LDAP & Kerberos Authentication

  • Hybrid Identity Services

  • Monitor AD health, replication, and security.

Cloud Identity & Security

  • Implement identity security solutions across:

  • Microsoft Azure

  • AWS

  • Google Cloud Platform (GCP)

  • Integrate enterprise applications using:

  • SAML

  • OAuth 2.0

  • OpenID Connect (OIDC)

  • LDAP

  • SCIM

  • Kerberos

  • RADIUS

  • REST APIs

  • SOAP

Support Integrations With Enterprise Platforms Including

  • SAP
  • Oracle
  • Salesforce
  • ServiceNow
  • Workday
  • Microsoft 365
  • Azure
  • AWS
  • Windows Servers
  • Linux/Unix
  • Databases
  • Network Infrastructure

Automation & Platform Optimization

  • Develop automation using:

  • PowerShell

  • Python

  • Bash

  • Azure CLI

  • REST APIs

  • CyberArk APIs

  • Improve operational efficiency through scripting, orchestration, and automation.

  • Drive continuous platform optimization and standardization.

Security, Compliance & Governance

  • Ensure compliance with:

  • ISO 27001

  • NIST

  • CIS Controls

  • SOX

  • GDPR

  • PCI-DSS

  • HIPAA

  • Cyber Essentials

  • Support internal and external audits.

  • Perform privileged access reviews, vulnerability remediation, and compliance assessments.

  • Participate in major incident management, change implementation, platform maintenance, and on-call support.

  • Develop operational documentation, SOPs, knowledge articles, and technical runbooks.

Leadership & Stakeholder Management

  • Serve as the technical SME for CyberArk, IAM, IGA, and PAM technologies.
  • Collaborate with security architects, infrastructure teams, application owners, auditors, project managers, and vendors.
  • Provide technical leadership, mentoring, and best practice guidance.
  • Identify opportunities to improve security posture through automation, modernization, and platform enhancements.

Experience Required Skills & Experience

  • 10+ years of overall IT experience.
  • 7+ years of hands-on experience in Identity & Access Management (IAM).
  • 5+ years of enterprise CyberArk engineering and administration experience.
  • Experience supporting large-scale global enterprise environments.
  • Proven experience in L3 production support, platform engineering, upgrades, migrations, disaster recovery, and cloud transformation initiatives.

Mandatory Technical Skills

  • CyberArk PAM Suite (Vault, PVWA, CPM, PSM, PSMP, Conjur, EPM, Identity)
  • Microsoft Entra ID (Azure AD)
  • Active Directory & Hybrid Identity
  • Microsoft Entra PIM
  • Identity Governance platforms (SailPoint, Saviynt, Omada, One Identity, IBM Verify Governance)
  • IAM & PAM Architecture
  • SSO, MFA, Conditional Access, Passwordless Authentication
  • RBAC & Segregation of Duties (SoD)
  • Active Directory Security & Tier-0 Administration
  • Azure, AWS, and GCP Identity Services
  • Authentication & Federation (SAML, OAuth 2.0, OIDC, LDAP, SCIM, Kerberos)
  • PowerShell, Python, Bash, REST APIs, Azure CLI

Skills High Availability and Disaster Recovery, Privileged Access Management, PowerShell, Identity Governance

Millions of jobs, with real people getting hired every day

20,000+
New jobs added daily
7,000,000+
Verified job listings
500,000+
Tailored applications submitted
FAQ

Questions, answered

Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.

Yes. This role at UST was screened before publishing – we confirmed the employer before listing it.

The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.

This position can be done from anywhere, with no in-office requirement.

Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.