Haystack
← Back to Jobs
Other

Senior CyberArk and Identity Governance & Administration Engineer

Stellent IT LLCUnited States🇺🇸United StatesPosted 21 Jul 2026

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Hello


We have an urgent need for CyberArk Principal Engineer to lead the strategy for client but also lead a small team. Must be able to consult on IAM/PAM/IGA strategy and support director, greenfield PAM environment so leaning on this resource to support efforts. Strong Presentation skills is a must and must be a leader and a contributor. Seeking stronger consultative but hands on engineer background with some leadership/management experience to lead small PAM/IAM/IGA team under director. Must be hands on, consulting new PAM team, new implementation and driving the strategy in place. Strong CyberArk administrator/hands on experience, and strong PAM/IAM experience needed to support director/team.

Position Title: Senior CyberArk and Identity Governance & Administration Engineer

Location Information

Remote

Position Responsibilities:

As a Senior CyberArk and Identity Governance & Administration Engineer, you will play a pivotal role in managing, securing, and maturing enterprise privileged access management (PAM) and identity governance platforms. This position involves active oversight of CyberArk operations, providing technical leadership, and driving security initiatives to strengthen privileged access controls while supporting the evolution of identity governance strategy.

Key responsibilities include:

  • Manage the lifecycle and administration of privileged account vaults, including Safe creation, naming conventions, and ownership standards.
  • Onboard privileged accounts across domains (e.g., domain administrators, service accounts, local administrators, and cloud identities).
  • Audit Safe memberships, remediate excessive or orphaned access, and enforce best access hygiene practices.
  • Monitor, tune, and manage credential management platform operations including password rotation, verification jobs, complexity policies, reconcile settings, and heartbeat intervals.
  • Onboard new and non-standard platforms, manage reconcile accounts, and support privileged session monitoring and validation of session management health for both remote and web access.
  • Retrieve and provide session recordings for audit and investigation purposes in response to alerts and policy violations.
  • Process time-bound and dual-control access requests and review standing privileged access to enforce the principle of least privilege.
  • Maintain account configurations aligned to ongoing changes within environments.
  • Perform discovery of privileged accounts across Windows, Linux, and cloud environments; identify and coordinate the onboarding of unmanaged and shadow accounts.
  • Advise on the evaluation, selection, and future integration of Identity Governance platforms, supporting design and planning for future lifecycle management and integration with CyberArk.
  • Monitor the health of core CyberArk components, validate integrations with security monitoring and SIEM tools, and ensure audit log flow integrity.
  • Support API-based workflow automation and troubleshoot integration issues between CyberArk, identity governance, and IT service management platforms.
  • Assist in platform patching, upgrade activities, and handle incident response tasks such as emergency credential rotation, access revocation, and evidence collection for investigations.
  • Deliver metrics and reporting on onboarding progress, access requests, session records, and rotation success rates; manage compliance reporting and prepare audit evidence packages as needed.

Essential Skills, Experience

  • Extensive hands-on experience with CyberArk, including Vault, Credential Management, session management, and web access components within enterprise environments.
  • Experience leading and managing teams within Privileged Access Management (PAM) and Identity Access Management (IAM) domains, alongside hands-on operational support.
  • Expertise with onboarding privileged accounts and platforms, managing reconcile accounts, monitoring session health, and conducting privilege audits and access remediation.
  • Proficiency in API-based automation and integration for CyberArk and related platforms.
  • Working knowledge of at least one Identity Governance and Administration (IGA) platform, such as SailPoint, Saviynt, or comparable tools, and experience supporting platform evaluation and selection.
  • Strong technical background in Active Directory, Entra ID, LDAP, and authentication protocols including SAML, OAuth, OIDC, and Kerberos.
  • Experience integrating and supporting multi-factor authentication and cloud-based identity and access management in AWS, Azure, or Google Cloud Platform environments.
  • Understanding of security monitoring tools (such as Splunk, Microsoft Sentinel) and emerging credential-based attack patterns.
  • Experience with IT service management and workflow automation, using scripting languages such as PowerShell or Python, and utilizing REST APIs and tools like ServiceNow.
  • Deep understanding of account provisioning standards (e.g., SCIM) and familiarity with compliance frameworks (SOC, PCI, NIST, ISO).
  • Demonstrated experience supporting security audits, access reviews, producing compliance evidence, and managing audit response processes.
  • Ability to deliver operational, technical and compliance metrics, and manage compliance reporting requirements.
  • Excellent problem-solving skills, organizational abilities, and a collaborative, solution-oriented approach.

Qualifications:

  • Bachelor's degree in Computer Science, Information Security, or related technical field preferred (or equivalent related professional experience).
  • Relevant technical certifications such as CyberArk Defender or Sentry, or Identity Governance certifications, are highly desirable.
  • Minimum of 5+ years of experience in privileged access management and/or identity governance.
  • Strong communication skills with the ability to interface with stakeholders at all levels.
  • Demonstrated track record of supporting large-scale enterprise security platforms and driving process improvements.




Gopal Gupta
Technical Recruiter

E:
D:
A: 505 Knolle Court, Saint Augustine| FL 32092

Skills

AWS
OAuth
SAML
Splunk
Active Directory
Azure
Compliance
Google Cloud
LDAP
Onboarding
PowerShell
Python
REST
SAFe
ServiceNow
Vault

Similar jobs