Job Description
CyberArk Architect (PAM Consultant)
Location: Amsterdam, Netherlands (Hybrid)
Contract Duration: 6 Months
Start Date: October 2026
Experience Required: 6–8 Years
We are seeking an experienced CyberArk Architect to design, implement, and support enterprise-wide Privileged Access Management (PAM) solutions. The ideal candidate will have strong expertise in CyberArk architecture, privileged account governance, identity security, secrets management, and integration with enterprise systems.
Key Responsibilities
- Design and develop secure, scalable, and highly available CyberArk PAM architectures.
- Define PAM strategy, architecture standards, best practices, and implementation roadmap.
- Lead the deployment, configuration, and upgrade of CyberArk components.
- Configure and manage Safes, Platforms, Account Groups, access controls, and privileged credentials.
- Implement password rotation and privileged credential lifecycle management.
- Integrate CyberArk with enterprise identity, cloud, ITSM, and security platforms.
- Develop automation using REST APIs, PowerShell, Python, and Ansible.
- Implement application credential and secrets management solutions.
- Conduct security assessments and recommend PAM improvements.
- Support governance, compliance, and privileged access audits.
- Provide Level 3 support, troubleshooting, and root cause analysis for CyberArk environments.
- Create technical documentation, operational procedures, and mentor junior PAM engineers.
Required Skills & Experience
- 6–8 years of experience in CyberArk Privileged Access Management.
- Strong hands-on experience designing and implementing enterprise CyberArk solutions.
- Expertise with:
- Digital Vault
- Privileged Session Manager (PSM)
- Central Policy Manager (CPM)
- Password Vault Web Access (PVWA)
- Privileged Threat Analytics (PTA)
- CyberArk Identity
- Conjur Secrets Management
- Experience integrating CyberArk with:
- Active Directory
- Microsoft Entra ID (Azure AD)
- LDAP
- SIEM platforms
- IT Service Management tools
- Cloud platforms (AWS, Azure, or GCP)
- Strong scripting and automation skills using PowerShell, Python, REST APIs, or Ansible.
- Experience implementing secrets management and privileged credential governance.
- Strong understanding of Zero Trust and least-privilege security principles.
- Experience supporting compliance frameworks such as ISO 27001, NIST, SOC 2, PCI-DSS, or CIS Controls.
- Excellent analytical, troubleshooting, communication, and documentation skills.
Preferred Qualifications
- CyberArk certifications are an advantage.
- Experience with enterprise identity security and cloud-native PAM environments.
- Ability to lead technical discussions and mentor security engineering teams.