
CyberArk Architect
Posted Sep 11

Posted Sep 11
This is a fully remote position, open to applicants in United Kingdom.
• Lead the design of solutions for a large-scale, TSA-regulated Privileged Access Management migration and merger consolidation initiative.
• Create end-to-end migration architecture transitioning from CyberArk v12.2 to v14.2.
• Define staged ingestion processes, credential protection measures, name-collision resolutions, platform normalization, and policy reconciliation.
• Develop migration runbooks, RAID logs, and models for effort sizing.
• Segment over 250 dependent applications by integration pattern and oversee CP/CCP re-onboarding.
• Design AppID re-provisioning strategies, certificate/mTLS re-issuance, phased cutover waves, rollback plans, and dual-run methodologies.
• Architect PVWA federation to Entra ID using SAML/OIDC and map Entra groups to CyberArk Vault Users and Safe memberships.
• Plan the migration of RSA SecurID to Entra MFA, including Conditional Access and bridging legacy clients.
• Ensure High Side / Low Side segregation throughout federation and migration data flows.
• Take ownership of architecture decisions, trade-offs, audit documentation, tooling assessments, acceptance criteria, and go/no-go milestones.
• Present architectural designs to client security, compliance teams, and PAM leadership.
• Provide mentorship and technical guidance to CyberArk Senior Engineers.
• Over 10 years of experience in Identity and Access Management.
• More than 5 years specifically focused on CyberArk PAM architecture and design.
• Extensive hands-on expertise with CyberArk EPV, PVWA, CPM, PSM, AAM/CCP, and Vault architecture in both on-prem and Privilege Cloud environments.
• Demonstrated experience leading CyberArk version migrations (v10/v11/v12 → v13/v14) at an enterprise scale.
• Strong understanding of SAML 2.0 and OIDC federation design principles.
• Experience integrating CyberArk PVWA with an enterprise Identity Provider (Entra ID, Okta, or similar).
• Proficient in credential provider architectures (CP, CCP) and onboarding applications at scale (100+ application estates).
• Familiarity with MFA migration projects, such as transitioning from RSA SecurID to a cloud-based MFA/Conditional Access model.
• Experience working in regulated environments with established change control and audit evidence requirements.
• Excellent client-facing communication skills, capable of presenting architecture to both technical and executive stakeholders.
• Eligible candidates may receive sponsorship for employment visas.
• Remote work arrangement is available.
Hightouch
Cisco
Gainwell Technologies
Get handpicked remote jobs straight to your inbox weekly.