Back to search
Signify Technology Linkedin · Posted 12d ago

PAM Architect

Sofia City

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

PAM Architect with CyberArk


The PAM Architect will lead the design, deployment, and optimization of Privileged Access Management (PAM) infrastructure utilizing CyberArk. Key responsibilities include defining PAM strategies, securing privileged accounts across enterprise networks, and ensuring seamless integration with existing identity and security frameworks.


Your responsibilities:

• Design, implement, and own enterprise Privileged Access Management (PAM) architecture and operations centered on CyberArk, delivering secure, scalable controls for human and non-human privileged identities across cloud, hybrid, and on-prem environments.

• Advise Security Architecture, IAM, Platform Engineering, and Infrastructure teams on privileged access design patterns, onboarding strategy, and risk reduction—translating policy and compliance requirements into enforceable technical controls.

• Lead hands-on deployment and configuration of core CyberArk capabilities (e.g., vaulting, session management, credential rotation, onboarding/offboarding workflows, and privileged access governance), ensuring high availability, resilience, and operational readiness.

• Engineer automated onboarding and lifecycle management for privileged accounts, safes, platforms, and policies using PowerShell, Python, and Bash—building reusable modules and pipelines that standardize provisioning, reduce manual effort, and improve control consistency.

• Integrate CyberArk with identity providers and enterprise access systems (SSO/MFA/conditional access, directory services), and design robust authentication, authorization, and approval workflows for privileged sessions and credential retrieval.

• Enable secure machine-to-machine access by implementing patterns for application identities, service accounts, APIs, keys, certificates, and secrets, including rotation, least privilege, and auditability across Windows and Linux workloads.

• Drive adoption of privileged session controls and monitoring—implementing session recording, command/control policies (where applicable), and evidence retention to support incident response, forensics, and regulatory audits.

• Partner with cloud and Azure engineering teams to extend PAM controls into Azure (subscriptions, resources, automation accounts, DevOps pipelines, and cloud-native identities), ensuring privileged access is governed consistently across cloud and on-prem.

• Define and maintain PAM standards, reference architectures, hardening baselines, and operational runbooks—covering safe design, platform configurations, credential types, rotation schedules, break-glass procedures, and emergency access.

• Troubleshoot complex integration and operational issues across CyberArk components, directories, endpoints, and network dependencies—providing deep technical support and root-cause analysis to maintain service reliability and performance.

• Establish metrics and continuous improvement practices for PAM effectiveness (onboarding coverage, rotation compliance, session governance, access review outcomes), driving measurable reduction in privileged risk and improved audit posture.

• Provide technical leadership to engineers and stakeholders through workshops, enablement sessions, and hands-on guidance—accelerating onboarding of new systems, improving operational maturity, and ensuring secure-by-design delivery.


What you bring in:

• Bachelor’s or Master’s degree in computer science, Cybersecurity, Information Systems, Engineering, or a related technical field.

• CyberArk certifications strongly preferred:

o CyberArk Defender (PAM)

o CyberArk Sentry

o CyberArk Guardian

• Additional IAM or security certifications beneficial:

o CISSP, CISM, CCSP

o Microsoft Entra ID / Azure security certifications

o TOGAF or equivalent architecture certification (advantage)

• 8–12+ years of experience in identity security, PAM engineering, IAM, or security architecture roles.

• Proven experience designing and implementing CyberArk PAM solutions in enterprise or highly regulated environments.

• Hands-on experience with privileged access across Windows, Linux/Unix, databases, network devices, cloud platforms, and applications.

• Experience integrating PAM with cloud (AWS, Azure, GCP), DevOps, and CI/CD environments.

• Demonstrated ability to advise senior stakeholders on privileged access risks, architectural trade-offs, and remediation strategies.

• Experience supporting audits, compliance initiatives, and security risk assessments related to privileged access.


12 month Contract

€ 250 per day

Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search