CyberArk Architect

Posted Sep 11

This is a fully remote position, open to applicants in United Kingdom.

📋 Description

• Lead the design of solutions for a large-scale, TSA-regulated Privileged Access Management migration and merger consolidation initiative.

• Create end-to-end migration architecture transitioning from CyberArk v12.2 to v14.2.

• Define staged ingestion processes, credential protection measures, name-collision resolutions, platform normalization, and policy reconciliation.

• Develop migration runbooks, RAID logs, and models for effort sizing.

• Segment over 250 dependent applications by integration pattern and oversee CP/CCP re-onboarding.

• Design AppID re-provisioning strategies, certificate/mTLS re-issuance, phased cutover waves, rollback plans, and dual-run methodologies.

• Architect PVWA federation to Entra ID using SAML/OIDC and map Entra groups to CyberArk Vault Users and Safe memberships.

• Plan the migration of RSA SecurID to Entra MFA, including Conditional Access and bridging legacy clients.

• Ensure High Side / Low Side segregation throughout federation and migration data flows.

• Take ownership of architecture decisions, trade-offs, audit documentation, tooling assessments, acceptance criteria, and go/no-go milestones.

• Present architectural designs to client security, compliance teams, and PAM leadership.

• Provide mentorship and technical guidance to CyberArk Senior Engineers.


⛳️ Requirements

• Over 10 years of experience in Identity and Access Management.

• More than 5 years specifically focused on CyberArk PAM architecture and design.

• Extensive hands-on expertise with CyberArk EPV, PVWA, CPM, PSM, AAM/CCP, and Vault architecture in both on-prem and Privilege Cloud environments.

• Demonstrated experience leading CyberArk version migrations (v10/v11/v12 → v13/v14) at an enterprise scale.

• Strong understanding of SAML 2.0 and OIDC federation design principles.

• Experience integrating CyberArk PVWA with an enterprise Identity Provider (Entra ID, Okta, or similar).

• Proficient in credential provider architectures (CP, CCP) and onboarding applications at scale (100+ application estates).

• Familiarity with MFA migration projects, such as transitioning from RSA SecurID to a cloud-based MFA/Conditional Access model.

• Experience working in regulated environments with established change control and audit evidence requirements.

• Excellent client-facing communication skills, capable of presenting architecture to both technical and executive stakeholders.


🏝️ Benefits

• Eligible candidates may receive sponsorship for employment visas.

• Remote work arrangement is available.

People also viewed

Hightouch15 hours ago

Forward Deployed Architect

US flagUnited States OnlyFull-timeArchitect$175k – $225k/year
ApplyView job
Cisco15 hours ago

Customer Delivery Architect

US flagNorth Carolina OnlyFull-timeArchitect$169.3k – $237.2k/year
ApplyView job
Gainwell Technologies19 hours ago

Principal Application Architect

US flagFlorida, +1 more stateFull-timeArchitect$118.8k – $169.7k/year
ApplyView job
Brillio20 hours ago

Architect

US flagNew York OnlyFull-timeArchitect$160k – $165k/year
ApplyView job
Akamai Technologies20 hours ago

Architect

US flagMassachusetts OnlyFull-timeArchitect$146.4k – $263.6k/year
ApplyView job
Workiy Inc.20 hours ago

Digital Architect

CA flagCanada OnlyFreelanceArchitect
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers