- Company Name
- Sobeys
- Job Title
- Senior Identity Access Management IAM Specialist - CyberArk
- Job Description
-
**Job Title**: Senior Identity Access Management (IAM) Specialist – CyberArk
**Role Summary**
Lead the design, deployment, and ongoing management of CyberArk Privileged Access Management (PAM) solutions across on‑premise and SaaS environments. Drive secure, credential‑less access for Linux, Windows, and databases, enforce zero‑trust principles, and automate identity governance workflows.
**Expectations**
* 7+ years of hands‑on CyberArk PAM experience.
* Deep expertise in CyberArk SaaS Spaces: Identity Administration, PVWA, Flows, Secure Access, Remote Access (Vendor PAM/Alero).
* Strong grasp of least privilege, zero‑trust architecture, Active Directory, Entra, and single‑sign‑on concepts.
* Proven ability to support Tier 3 escalations, conduct audits, and integrate with ITSM, SIEM, directories, and cloud platforms.
* Self‑driven learner of emerging CyberArk technologies (SRS, Identity Protection, Incident & Response).
**Key Responsibilities**
1. Act as CyberArk SME for on‑premise and SaaS deployments.
2. Design, deploy, and manage CyberArk Secure Infrastructure Access (SIA) for credential‑less access.
3. Implement and maintain Identity Security Intelligence (ISI) for behavioral analytics and policy enforcement.
4. Configure CyberArk Remote Access for secure, agentless vendor connections.
5. Build and optimize Flows to automate access requests, approvals, and governance processes.
6. Integrate CyberArk solutions with Azure, AWS, GCP, directories, ITSM, and SIEM tools.
7. Develop architectural diagrams, technical documentation, and operational playbooks.
8. Troubleshoot advanced issues and provide Tier 3 support.
9. Collaborate with cybersecurity, infrastructure, and compliance teams for audits and policy enforcement.
10. Upgrade and maintain CyberArk connectors (PSM, CPM, SIA).
11. Securely manage cloud administrator access via CyberArk.
**Required Skills**
* Advanced CyberArk PAM expertise (SIA, ISI, Remote Access, Flows).
* Experience with CyberArk SaaS Spaces and services.
* Strong knowledge of least privilege and zero‑trust frameworks.
* Proficiency in Active Directory, Microsoft Entra, SSO, and cloud identity services.
* Ability to integrate with Azure, AWS, GCP, ITSM, and SIEM.
* Documentation, troubleshooting, and Tier 3 support skills.
* Excellent communication and collaboration with cross‑functional teams.
**Required Education & Certifications**
* Bachelor’s degree in Computer Science, Information Systems, or related field, or equivalent experience.
* CyberArk Certified Professional (or equivalent CyberArk certification).
* Relevant security certifications such as CISSP, CISM, CompTIA Security+ preferred.