- Company Name
- Whitehall Resources Ltd
- Job Title
- Cyberark PAM Engineer
- Job Description
-
**Job Title:** CyberArk PAM Engineer
**Role Summary:**
Design, implement, and operate CyberArk Privileged Access Management solutions for a large, multi‑region enterprise. Lead upgrades, automation, and integration initiatives while ensuring alignment with Zero‑Trust and NIST standards and supporting a future shift to CyberArk Privileged Cloud (SaaS).
**Expectations:**
- Remote engagement on a 6‑month contract (outside IR35).
- Eligible to work in the required jurisdiction.
- Proven ability to operate in complex, large‑scale enterprise environments.
- Strong communication skills for SME support, documentation, and internal training.
**Key Responsibilities:**
- Manage and maintain CyberArk components (Digital Vault, CPM, PSM, PSMP, CCP, AIM) across multiple regions.
- Automate onboarding, rotation, and decommissioning of privileged accounts, certificates, and SSH keys.
- Plan and execute major CyberArk version upgrades.
- Design CyberArk Safes, RBAC structures, and policies in line with Zero‑Trust and NIST guidelines.
- Develop automation scripts and integrate non‑standard platforms (e.g., Oracle Cloud).
- Provide expert troubleshooting and incident response for CyberArk‑related issues.
- Support DevOps/CI‑CD secret management using AIM, AAM, and Conjur.
- Maintain comprehensive documentation and deliver internal training sessions.
**Required Skills:**
- Extensive hands‑on experience with CyberArk PAM (Digital Vault, CPM, PSM, PSMP, CCP, AIM).
- Strong scripting/automation abilities (PowerShell, Python, Bash, or similar).
- Experience with large, complex enterprise infrastructures and multi‑region deployments.
- Familiarity with cloud/PaaS environments and SaaS PAM models (Azure, AWS, Oracle Cloud).
- Knowledge of Zero‑Trust principles and NIST security frameworks.
- Ability to design RBAC, policy structures, and safe configurations.
- Excellent troubleshooting, incident management, and stakeholder communication skills.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field (or equivalent practical experience).
- CyberArk certification preferred (e.g., CyberArk Certified Trustee, CyberArk Certified Sentry, or CyberArk Privileged Access Security Specialist).
- Additional relevant certifications (CISSP, CISM, or cloud security credentials) are a plus.