Cybersecurity Architect (CyberArk)
Contract Summary Box:
Location: on-site
Contract Length: 2 weeks
Day Rate / Pay: 0.0
Working Environment: hybrid
Start Date: 31/07/2026
The Cybersecurity Architect (CyberArk) contract supports the APAC Production Security teams responsible for IT Security activities within the organisation’s Asia Pacific region. This role involves leading the design, implementation, and ongoing improvement of CyberArk vault and PAM solutions to enhance privileged access security across all APAC operations. The architect will ensure high-availability, resilience, and automation of privileged credentials management in collaboration with engineering and cloud teams.
Key Skills & Experience
- Expert knowledge of CyberArk (Vault, PSM, CPM), and PAM solutions
- Demonstrated L3-level expertise in Conjur (design, policy-as-code, secret lifecycle automation, and Kubernetes integration) and CyberArk Privileged Access Management
- Proven track record of building high-availability, resilient identity platforms with monitoring, automated remediation, and documented DR procedures
- Ability to define and enforce privileged-access policies across Windows, Linux, UNIX, databases, and cloud platforms (AWS, Azure, GCP)
- Experience automating PAM processes using PowerShell, Python, and CyberArk REST APIs
- Knowledge of integrating CyberArk with SSO/IdP solutions (SAML, OIDC, AD)
- Familiarity with cloud providers (AWS Secrets Manager, Azure Key Vault) and Hybrid-IAM environments
- Solid understanding of Zero-Trust concepts for privileged access
Nice to Have
- CyberArk Certified Defender (CCD)
- Secrets Manager (Conjur) certification
Role Overview
This role involves defining and owning the enterprise-wide CyberArk architecture, including vault and PSM components, to support the organisation’s technical accounts inventory. The architect will design privilege management policies, support high-availability monitoring, and automate processes to improve security posture and operational efficiency. Collaboration with DevSecOps, cloud, and application teams is essential to embed secure identity controls in all platform lifecycle stages.
Key Responsibilities
- Define and own the enterprise‑wide CyberArk architecture to support the organisation’s technical accounts.
- Design and enforce privileged‑access policies across various operating systems and cloud platforms.
- Provide high-availability support for CyberArk systems, establishing monitoring, incident response, and disaster recovery processes.
- Drive the secret‑management lifecycle, including password rotation, SSH key management, and credential vaulting.
- Partner with engineering, application, and cloud teams to embed privileged access controls into new services.
- Automate PAM processes using PowerShell, Python, and CyberArk REST APIs.
- Evaluate emerging PAM technologies and build business cases for adoption.
- Collaborate with DevSecOps and cloud teams to embed privileged-access controls into CI/CD pipelines and cloud-native workloads.
Requirements
- A minimum of 8+ years of experience as a security professional
- Bachelor’s degree in Computer Science, Information Security, or related field (Master’s preferred)
- Hands-on experience architecting, deploying, and operating CyberArk PAS (Vault, PSM, CPM, PVWA) at enterprise scale
- Deep expertise in CyberArk Core PAS components and CyberArk Privileged Threat Analytics
- Strong knowledge of Windows/UNIX/Linux authentication mechanisms, Kerberos, LDAP/AD, SSH, database authentication
- Experience integrating CyberArk with SSO/IdP solutions (SAML, OIDC, AD)
- Proficiency in PowerShell, Python, and CyberArk REST API for automation
- Familiarity with cloud providers (AWS Secrets Manager, Azure Key Vault) and Hybrid-IAM environments
- Solid understanding of Zero‑Trust concepts for privileged access
If you have the required skills and availability, please apply with an updated CV.
