CyberSecurity Architect
Job Description
Role Scope: This role is accountable for securing, monitoring, and governing all privileged credentials and sessions, thereby reducing the risk of credential-theft, insider abuse, and lateral movement in the enterprise environment. Candidate Success Factors: Candidates will be measured on the following four performance drivers that will dictate how individual impact is considered on the platform: · Expert knowledge of CyberArk (Vault, PSM, CPM),and PAM solutions. · Demonstrated L3-level expertise in Conjur (design, policy-as-code, secret lifecycle automation, and Kubernetes integration) combined with deep, hands-on experience in CyberArk Privileged Access Management, enabling the architect to drive end-to-end secret-management and privileged-account implementation. · Proven track record of building high-availability, resilient identity platforms with robust monitoring, automated remediation, and documented DR procedures. · Client, Customer and Stakeholder Focus · Compliance Culture and Conduct Responsibilities
- Define and own the enterprise‑wide CyberArk architecture (Vault, CPM, PSM, PVWA, Conjur)to support the banks technical accounts inventory.
- Design and enforce privileged‑access policies (least‑privilege, separation‑of‑duties, time‑bound access) across Windows, Linux, UNIX, databases, cloud platforms (AWS, Azure, GCP).
- Provide high-availability support for the CyberArk, establishing robust monitoring, incident-response, and disaster-recovery processes that keep critical services up and running 24×7.
- Drive the secret‑management lifecycle – automatic password rotation, SSH key management, API‑credential vaulting, and on‑demand retrieval.
- Partner with engineering, application, and cloud teams to embed secure identity controls into every new service launch, migration, or platform upgrade.
- Automate PAM processes using PowerShell, Python, and CyberArk REST APIs (e.g., bulk onboarding/off‑boarding, credential rotation schedules).
- Evaluate emerging PAM technologies (e.g., CyberArk Conjur, Secret-Zero, Zero-Trust Privilege) and build business cases for adoption. 8.Collaborate with DevSecOps, Cloud, and Application teams to embed privileged-access controls into CI/CD pipelines and cloud-native workloads.
Technical& Behavioral Competencies Technical ▪ Requires a minimum of 7+ years of experience as security professional ▪ Bachelor’s degree in Computer Science, Information Security, or related field (Master’s preferred). ▪ Hands-on experience architecting, deploying, and operating CyberArk PAS (Vault, CPM,PSM, PVWA) at enterprise scale. ▪ Conjur (CyberArk) – L3 – policy-as-code (CPL/HCL), secret rotation, dynamic secrets, Kubernetes side-car injection, API/CLI integrations ▪ Deep expertise in CyberArk Core PAS components and CyberArk Privileged Threat Analytics. ▪ Strong knowledge of Windows/UNIX/Linux authentication mechanisms, Kerberos, LDAP/AD,SSH, database authentication. ▪ Experience integrating CyberArk with SSO/IdP solutions (SAML, OIDC, AD). ▪ Proficiency in PowerShell, Python, and CyberArk REST API for automation. ▪ Familiarity with cloud providers (AWS Secrets Manager, Azure Key Vault) and Hybrid‑IAM environments. ▪ Solid understanding of Zero‑Trust concepts for privileged access.
If interested, you can click on “Apply here” or write an e-mail to [email protected] with your updated resume. NOTE: - Only shortlisted candidates will be contacted back. Thanks & Regards Deeksha Agarwal EA Licence No.91C2918 Personnel Registration No. R26161520