CyberArk Architect

Bounteous
United Kingdom
Workplace: RemoteContractFunction: CybersecurityExperience: 10+ yearsSkills: ["Client-facing communication","Architecture leadership","Stakeholder presentation","Technical mentorship"]

Lead hands-on solution architecture for a large-scale, TSA-regulated Privileged Access Management (PAM) migration and merger consolidation. Own end-to-end CyberArk vault migration (v12.2 to v14.2), entity extraction/transformation, staged ingestion, and rollout runbooks. Architect CP/CCP and application onboarding sequencing across 250+ dependent apps, PVWA federation to Entra ID, and RSA SecurID to Entra MFA re-enrolment, while ensuring audit evidence, governance, and high/low side segregation.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Bounteous
Bounteous
1 hour ago

CyberArk Architect

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 1 hour agoStatus: Live

Job Summary

Lead hands-on solution architecture for a large-scale, TSA-regulated Privileged Access Management (PAM) migration and merger consolidation. Own end-to-end CyberArk vault migration (v12.2 to v14.2), entity extraction/transformation, staged ingestion, and rollout runbooks. Architect CP/CCP and application onboarding sequencing across 250+ dependent apps, PVWA federation to Entra ID, and RSA SecurID to Entra MFA re-enrolment, while ensuring audit evidence, governance, and high/low side segregation.
Location: United Kingdom
Workplace: Remote
Employment Type: Contract
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Design end-to-end CyberArk vault migration from v12.2 to v14.2, including extraction, transformation, reconciliation, and staged loading.
  • •Define staged-ingestion and cutover strategies (disabled import, CPM soft-verification, dual-run mirroring, forced rotation) to prevent credential exposure.
  • •Lead CP/CCP and application onboarding architecture: segment 250+ dependent applications by integration pattern and define re-onboarding, certificate/mTLS re-issuance, and phased cutover waves.
  • •Architect PVWA federation to Entra ID via SAML/OIDC with claims mapping, and design RSA SecurID to Entra MFA migration including Conditional Access policy and legacy/non-web bridging.
  • •Ensure governance and compliance: present architecture for sign-off, produce audit evidence for TSA compliance, define acceptance criteria/go-no-go gates, and mentor CyberArk engineers.

Key Requirements

  • •10+ years in Identity and Access Management, including 5+ years specifically in CyberArk PAM architecture and design.
  • •Deep hands-on knowledge of CyberArk EPV, PVWA, CPM, PSM, AAM/CCP, and Vault architecture for on-prem and Privilege Cloud deployments.
  • •Proven experience leading CyberArk version migrations at enterprise scale (v10/v11/v12 to v13/v14).
  • •Strong federation design experience with SAML 2.0 and OIDC, integrating CyberArk PVWA with an enterprise IdP (Entra ID, Okta, or equivalent).
  • •Experience in regulated environments with formal change control and audit evidence requirements, plus strong client-facing communication.
Experience:10+ yearsIdentity and Access ManagementPrivileged Access ManagementRegulated environments
Skills:Client-facing communicationArchitecture leadershipStakeholder presentationTechnical mentorship
Tech Stack:CyberArkEPVPVWACPMPSMAAMCCPVaultREST APIPACLISAML 2.0OIDCEntra IDOktaRSA SecurIDConditional AccessPrivateArkMTLSRADIUSHydden

Eligibility

Work Authorization:Sponsorship available.

Company Brief

Bounteous
Bounteous is a digital experience consultancy that designs, builds, and optimizes digital products, platforms, and customer experiences for enterprise brands across marketing, commerce, and analytics.
Industry: Consulting
Company Size: Enterprise (1,001+ employees)
Growth: Established Company
Headquarters: Chicago, United States
Founded: 2003
WebsiteLinkedIn