Sobre esta vaga de CyberArk Architect na Bounteous
CyberArk Architect
3+ months rolling contract
Newbury, UK
About the role
We are seeking a CyberArk Architect to lead solution design for a large-scale, TSA-regulated Privileged Access Management (PAM) migration and merger consolidation programme. This is a hands-on architecture role spanning vault migration design, identity federation, and application onboarding strategy for an estate spanning thousands of accounts and 250+ dependent applications, delivered against a fixed regulatory deadline.
Key responsibilities
Migration & vault architecture
- Design the end-to-end migration architecture from CyberArk v12.2 to v14.2, covering entity extraction (REST API primary, PACLI fallback), transformation, reconciliation, and staged loading into the target vault.
- Define the staged-ingestion model: disabled import → CPM soft-verification → dual-run mirroring → forced rotation at cutover — ensuring no credential is exposed to a script or human during migration.
- Own name-collision resolution, platform normalisation, and policy reconciliation rules between source and target environments.
- Produce migration runbooks, RAID logs, and effort-sizing models across Safes, Accounts, Platforms, and Policies.
Application & credential provider (CP/CCP) strategy
- Lead discovery to segment the 250+ dependent applications by integration pattern (CP agent, CCP centralised, Conjur, direct SSO) — the primary driver of onboarding sequencing and timeline risk.
- Design the CP/CCP re-onboarding approach, including AppID re-provisioning, certificate/mTLS re-issuance, and phased cutover waves.
- Define rollback and dual-run strategy per wave, including the read-only fallback window on the source vault.
Identity federation & MFA
- Design PVWA federation to Entra ID via SAML/OIDC, including claims mapping from Entra groups to CyberArk Vault Users and Safe membership.
- Architect the RSA SecurID → Entra MFA migration as a re-enrolment exercise, covering Conditional Access policy design and non-web/legacy client bridging (PrivateArk, PACLI, RADIUS-dependent flows).
- Ensure High Side / Low Side segregation is preserved across all federation and migration data flows, with no entitlement detail crossing the DMZ boundary.
Governance, compliance & stakeholder leadership
- Own architecture decisions and trade-offs; present designs to client security, compliance, and PAM leadership for sign-off.
- Ensure all migration and access-control designs produce audit evidence sufficient for TSA compliance reporting.
- Evaluate and position complementary tooling (e.g. Hydden for continuous identity discovery) against native CyberArk capability.
- Define acceptance criteria and go/no-go gates for pilot and production wave sign-off.
- Mentor and provide technical direction to CyberArk Senior Engineers delivering the build.
Required experience & skills
- 10+ years in Identity and Access Management, with 5+ years specifically in CyberArk PAM architecture and design.
- Deep hands-on knowledge of CyberArk EPV, PVWA, CPM, PSM, AAM/CCP, and Vault architecture across on-prem and Privilege Cloud deployments.
- Proven experience leading a CyberArk version migration (v10/v11/v12 → v13/v14) at enterprise scale.
- Strong working knowledge of SAML 2.0 and OIDC federation design, including experience integrating CyberArk PVWA with an enterprise IdP (Entra ID, Okta, or equivalent).
- Experience with credential provider architectures (CP, CCP) and application onboarding at scale (100+ application estates).
- Familiarity with MFA migration projects (e.g. RSA SecurID to a cloud MFA/Conditional Access model).
- Experience operating in regulated environments (financial services, telecom, or government) with formal change control and audit evidence requirements.
- Strong client-facing communication skills; able to present architecture to both technical and executive stakeholders.