Job Description
Galderma is the emerging pure-play dermatology category leader, present in approximately 90 countries. We deliver an innovative, science-based portfolio of premium flagship brands and services that span the full spectrum of the fast-growing dermatology market through Injectable Aesthetics, Dermatological Skincare and Therapeutic Dermatology. Since our foundation in 1981, we have dedicated our focus and passion to the human body's largest organ - the skin - meeting individual consumer and patient needs with superior outcomes in partnership with healthcare professionals. Because we understand that the skin, we are in shapes our lives, we are advancing dermatology for every skin story.
We look for people who focus on getting results, embrace learning and bring a positive energy. They must combine initiative with a sense of teamwork and collaboration. Above all, they must be passionate about doing something meaningful for consumers, patients, and the healthcare professionals we serve every day. We aim to empower each employee and promote their personal growth while ensuring business needs are met now and into the future. Across our company, we embrace diversity and respect the dignity, privacy, and personal rights of every employee.
At Galderma, we actively give our teams reasons to believe in our bold ambition to become the leading dermatology company in the world. With us, you have the ultimate opportunity to gain new and challenging work experiences and create an unparalleled, direct impact.
Job Title: Privileged Access Specialist (CyberArk) - JR020283
Location: Krakow/Poland – 3 days on-site
Department: IT – Cyber Security
About the role
As PAM Engineer, Privileged Access Specialist (CyberArk) you will be responsible for architecting, supporting, and continuously improving Galderma’s Privileged Access Management (PAM) framework. You will serve as the primary technical authority for the CyberArk platform, ensuring privileged credentials and session security are managed robustly across our global IT and OT environments. You will partner with IT, application, audit, and business stakeholders to deliver secure and compliant privileged access controls in a regulated setting.
Main Responsibilities
- Administer and operate Galderma’s CyberArk platform, including Vault, CPM, PSM, PVWA, HTML5 Gateway, PTA, PSMP, and Identity/SIA components.
- Lead platform lifecycle activities: upgrades, patching, disaster recovery testing, backup and restore, certificate management, and system hardening following industry standards.
- Configure and maintain privileged access, policies, including password rotation, reconciliation, session isolation and recording, exclusive access and dual control workflows
- Onboard privileged accounts across Windows, Unix/Linux, databases, network devices, cloud environments, SaaS applications, and OT/manufacturing systems
- Develop and maintain custom integrations with CPM plugins and PSM connectors for non-standard targets and business-critical platforms
- Support privileged session inspection, monitoring, and recording, integrating with SIEM to enhance detection of privileged misuse
- Manage secrets and machine identities, including Conjur/Secrets Hub, Credential Providers and API key lifecycles, with a focus on eliminating hard-coded credentials
- Contribute to PAM architecture and automation, including onboarding and compliance reporting through REST API, PowerShell and version control best practices
- Support audit and compliance requirements by providing evidence and documentation for privileged access controls, access reviews, session coverage, and remediation actions
- Maintain operational documentation and support incident response, forensic review and break-glass procedures with the IAM team
Key Requirements
- Higher education in Information Technology, Information Security or equivalent experience
- Minimum 5 years in privileged access management or IT security, including at least 3 years hands-on with CyberArk PAS/Privilege Cloud in production
- Strong practical experience with Vault, CPM, PSM and PVWA administration, privileged account onboarding, and policy configuration
- Demonstrated ability to create or maintain custom CPM plugins and PSM connectors for complex environments
- Robust knowledge of Windows Server, Active Directory (Kerberos, delegation, GPO tiering), Unix/Linux and networking concepts (TLS, firewalls, load balancing)
- Proficiency in PowerShell scripting, REST API integration; Python is an advantage
- Experience with secrets management (Conjur, Secrets Hub, CCP/CP, HashiCorp Vault) and integrating with CI/CD or Kubernetes pipelines
- Experience in regulated environments (SOX/ITGC; GxP is an advantage) and producing audit evidence/documentation
- Exposure to SIA/just-in-time access models, OT/manufacturing environments, or cloud privileged access controls is advantageous.
- CyberArk Defender certification required; Sentry preferred
- Fluent English
Skills & Competencies
- Deep expertise in privileged access management and CyberArk platform engineering
- Excellent understanding of privileged account lifecycle, session security, and access governance
- Strong analytic and troubleshooting skills for platform and integration issues
- Effective communication and stakeholder engagement across technical and business teams
- Strong organizational skills to manage platform operations and improvement programs
- Continuous improvement mindset with a focus on automation and operational excellence
What we offer in return:
- You will be working for an organization that embraces diversity & inclusion and believe we will deliver better outcomes by reflecting the perspectives of our diverse customer base.
- You will receive a competitive compensation package with bonus structure and extended benefit package.
- You will be able to work in an onsite work culture.
- You will participate in feedback loops, during which a personalized career path will be established.
- You will be joining a growing company that believes in ownership from day one where everyone is empowered to grow and to take on accountability.
Next Steps:
- If your profile is a match, we will invite you for a first virtual conversation with the recruiter.
- The next step is a virtual conversation with the hiring manager and the wider team.
- The final step is an in-person interview with the local HRBP
Our people make a difference
At Galderma, you’ll work with people who are like you. And people that are different. We value what every member of our team brings. Professionalism, collaboration, and a friendly, supportive ethos is the perfect environment for people to thrive and excel in what they do.
#LI-Hybrid