CyberArk Architect

Ampcus Inc.•Chicago, IL
•Remote

About The Position

Ampcus Inc. is a certified global provider of a broad range of Technology and Business consulting services. We are in search of a highly motivated candidate to join our talented Team. Job Title: CyberArk Architect Location(s): Chicago, IL (Remote) Job Summary We are seeking an experienced Senior CyberArk PAM Implementation Engineer to assess, optimize, and enhance our existing CyberArk Privileged Access Management environment. The ideal candidate will have strong hands-on experience with CyberArk Cloud/SaaS and the ability to perform a comprehensive assessment of the existing PAM implementation, identify security and operational gaps, and develop a strategic roadmap for utilizing CyberArk capabilities to their fullest extent. This role requires deep expertise in CyberArk PAM and Endpoint Privilege Manager (EPM), Secure Infrastructure Access (SIA), Just-in-Time (JIT) privileged access, application onboarding, password rotation, privileged session access, secrets management, and cloud integrations. The successful candidate will define the current-state architecture, recommend a target-state design based on CyberArk and industry best practices, and lead or support execution of the resulting roadmap.

Requirements

  • Minimum of 5–8 years of hands-on CyberArk PAM implementation and engineering experience.
  • Demonstrated experience assessing an existing CyberArk environment and developing a remediation or enhancement roadmap.
  • Strong hands-on experience with CyberArk Cloud/SaaS.
  • Demonstrated implementation experience with CyberArk SIA.
  • Demonstrated implementation experience with Just-in-Time (JIT) privileged access.
  • Experience onboarding complex applications and systems for password rotation, password reconciliation, session access, privileged session management, and secrets management.
  • Experience integrating CyberArk with enterprise applications and cloud platforms.
  • Experience migrating or transforming legacy privileged access processes into CyberArk-based workflows.
  • Strong understanding of privileged account lifecycle management.
  • Experience working with application owners, infrastructure teams, cloud teams, IAM teams, and vendors.
  • CyberArk PAM implementation experience
  • CyberArk Cloud/SaaS experience
  • CyberArk SIA implementation
  • JIT privileged access implementation
  • CyberArk assessment and architecture review experience
  • CPM password rotation and reconciliation
  • PSM privileged session access
  • Application and service account onboarding
  • Secrets management
  • Windows and Linux privileged access
  • PowerShell, Python, and/or API automation
  • Ability to develop a PAM roadmap and target-state architecture
  • CyberArk Defender certification
  • CyberArk Sentry certification
  • CyberArk Cloud-related training or certifications
  • CyberArk PAM implementation or delivery credentials
  • CISSP is beneficial but not mandatory

Nice To Haves

  • CyberArk Endpoint Privilege Manager (EPM) design, implementation, policy development, deployment, and operational support
  • Privileged Threat Analytics (PTA), where applicable to the environment
  • CyberArk application access and secrets capabilities
  • AWS, Microsoft Azure, and/or Google Cloud integration
  • Kubernetes or container environments
  • DevOps and CI/CD integrations
  • ITSM and SIEM integrations
  • Hands-on experience designing, deploying, configuring, and supporting CyberArk Endpoint Privilege Manager (EPM), including policy development, application control, privilege elevation, agent rollout, and operational optimization.
  • EPM operational and exception-management procedures
  • EPM application control and privilege elevation use-case catalogue
  • EPM agent deployment and phased rollout plan
  • EPM policy and baseline design
  • EPM target-state architecture and deployment strategy
  • EPM current-state assessment and maturity review

Responsibilities

  • Perform a comprehensive assessment of the existing CyberArk PAM environment, including architecture, configuration, integrations, policies, account onboarding processes, and operational procedures.
  • Identify security gaps, implementation deficiencies, unused capabilities, technical debt, and opportunities for optimization.
  • Evaluate the effectiveness of privileged account onboarding, password rotation, session management, access controls, and privileged access workflows.
  • Assess CyberArk platform health, scalability, resilience, availability, and operational maturity.
  • Review the existing use of CyberArk Cloud capabilities and recommend improvements.
  • Develop a current-state assessment report, including findings, risks, recommendations, and remediation priorities.
  • Develop a strategic PAM roadmap aligned with business requirements, cybersecurity objectives, and CyberArk best practices.
  • Define a target-state CyberArk architecture and implementation plan.
  • Develop a prioritized plan to maximize adoption and utilization of CyberArk capabilities.
  • Create implementation phases, dependencies, milestones, and technical requirements.
  • Define PAM use cases and prioritize systems, accounts, applications, and user populations for onboarding.
  • Develop a PAM maturity improvement plan.
  • Implement and optimize CyberArk Cloud/SaaS capabilities, including privileged account management, account discovery, password rotation, privileged session management, application credential management, secrets management, and privileged access request workflows.
  • Design, implement, and optimize CyberArk Secure Infrastructure Access (SIA) to enable secure, centralized access to infrastructure.
  • Implement secure access workflows for Windows, Linux, cloud infrastructure, and other supported platforms.
  • Integrate SIA with enterprise identity providers and authentication mechanisms.
  • Implement role-based access controls for infrastructure access.
  • Develop standards and procedures for onboarding infrastructure to SIA.
  • Design and implement Just-in-Time (JIT) privileged access capabilities, including time-bound and controlled privileged access.
  • Integrate JIT workflows with identity, ITSM, cloud, and authentication platforms.
  • Define access request, approval, elevation, expiration, and revocation workflows for JIT access.
  • Lead onboarding of applications, systems, databases, platforms, and privileged accounts into CyberArk.
  • Assess applications for password rotation, credential management, and secure access requirements.
  • Configure and implement password rotation, verification, and reconciliation.
  • Onboard service accounts and application accounts into CyberArk.
  • Work with application owners to implement credential retrieval and secure secrets consumption.
  • Enable users to securely access systems and administrative portals through CyberArk.
  • Implement session management and recording for supported systems.
  • Develop reusable onboarding patterns for various platforms and identity types.
  • Design, implement, and optimize CyberArk Endpoint Privilege Manager (EPM) to enforce least privilege and reduce local administrator rights.
  • Develop EPM application control and privilege elevation policies.
  • Perform EPM discovery and assessment to identify excessive local administrator privileges.
  • Plan and execute EPM agent deployment, phased rollout, and onboarding.
  • Implement application elevation, application control, credential protection, and least-privilege policies.
  • Define and maintain EPM policy baselines and exception management processes.
  • Integrate EPM with enterprise identity, security monitoring, and IT operational processes.
  • Monitor EPM policy effectiveness, troubleshoot agent and policy issues, and continuously optimize configurations.
  • Integrate CyberArk with enterprise identity and authentication platforms, cloud platforms, and infrastructure services.
  • Work with application teams to integrate applications with CyberArk secrets management capabilities.
  • Integrate CyberArk with ITSM, SIEM, monitoring, and ticketing platforms.
  • Develop automation for privileged account discovery, onboarding, reporting, and operational processes using PowerShell, Python, REST APIs, and CyberArk automation capabilities.
  • Develop CyberArk architecture standards and implementation guidelines.
  • Define PAM onboarding standards and security requirements.
  • Develop SOPs and operational runbooks for CyberArk administration.
  • Define privileged account ownership and lifecycle processes.
  • Establish policies for password rotation, reconciliation, session recording, privileged access, and emergency access.
  • Develop privileged account inventory and classification standards.
  • Ensure implementation aligns with CyberArk best practices and organizational security requirements.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service