Remote job
CyberArk Architect
Job details
About this role
Role overview Serve as the lead CyberArk Architect on a large, regulator-driven Privileged Access Management migration and merger consolidation programme. This hands-on architecture role spans vault migration design, identity federation, and application onboarding strategy for an estate of thousands of accounts and more than 250 dependent applications, delivered against a fixed regulatory deadline.
Responsibilities - Design end-to-end migration architecture from CyberArk v12.2 to v14.2, covering entity extraction, transformation, reconciliation, staged loading, and staged ingestion with dual-run mirroring. - Lead discovery to segment 250+ dependent applications by integration pattern and design the credential provider re-onboarding approach, including phased cutover waves and rollback strategy. - Design PVWA federation to Entra ID via SAML/OIDC and architect the RSA SecurID to Entra MFA migration, including Conditional Access policy and legacy client bridging. - Ensure High Side and Low Side segregation is preserved across all federation and migration data flows. - Produce migration runbooks, RAID logs, and effort sizing models, and present designs to client security, compliance, and PAM leadership. - Mentor and provide technical direction to CyberArk Senior Engineers delivering the build.
Requirements - 10+ years in Identity and Access Management with 5+ years specifically in CyberArk PAM architecture and design. - Deep hands-on knowledge of CyberArk EPV, PVWA, CPM, PSM, AAM/CCP, and Vault architecture across on-prem and Privilege Cloud deployments. - Proven experience leading an enterprise-scale CyberArk version migration (v10/v11/v12 to v13/v14). - Strong working knowledge of SAML 2.0 and OIDC federation design, including integrating PVWA with an enterprise IdP such as Entra ID or Okta. - Experience with credential provider architectures and onboarding at scale across 100+ application estates, plus familiarity with MFA migration projects such as RSA SecurID to a cloud MFA model. - Experience operating in regulated environments such as financial services, telecom, or government, with strong client-facing communication skills.
Benefits and work setup - Initial 3+ month rolling contract based in Newbury, UK, on a programme with a fixed regulatory deadline.