CyberArk Architect
AI Summary
CyberArk Architect leading a large-scale PAM migration and merger consolidation, designing vault migration, identity federation, and application onboarding for thousands of accounts and 250+ dependent applications under TSA regulatory requirements.
About this role
CyberArk Architect
3+ months rolling contract
Newbury, UK
About the role
We are seeking a CyberArk Architect to lead solution design for a large-scale, TSA-regulated Privileged Access Management (PAM) migration and merger consolidation programme. This is a hands-on architecture role spanning vault migration design, identity federation, and application onboarding strategy for an estate spanning thousands of accounts and 250+ dependent applications, delivered against a fixed regulatory deadline.
Key responsibilities
Migration & vault architecture
- Design the end-to-end migration architecture from CyberArk v12.2 to v14.2, covering entity extraction (REST API primary, PACLI fallback), transformation, reconciliation, and staged loading into the target vault.
- Define the staged-ingestion model: disabled import → CPM soft-verification → dual-run mirroring → forced rotation at cutover — ensuring no credential is exposed to a script or human during migration.
- Own name-collision resolution, platform normalisation, and policy reconciliation rules between source and target environments.
- Produce migration runbooks, RAID logs, and effort-sizing models across Safes, Accounts, Platforms, and Policies.
Application & credential provider (CP/CCP) strategy
- Lead discovery to segment the 250+ dependent applications by integration pattern (CP agent, CCP centralised, Conjur, direct SSO) — the primary driver of onboarding sequencing and timeline risk.
- Design the CP/CCP re-onboarding approach, including AppID re-provisioning, certificate/mTLS re-issuance, and phased cutover waves.
- Define rollback and dual-run strategy per wave, including the read-only fallback window on the source vault.
Identity federation & MFA
- Design PVWA federation to Entra ID via SAML/OIDC, including claims mapping from Entra groups to CyberArk Vault Users and Safe membership.
- Architect the RSA SecurID → Entra MFA migration as a re-enrolment exercise, covering Conditional Access policy design and non-web/legacy client bridging (PrivateArk, PACLI, RADIUS-dependent flows).
- Ensure High Side / Low Side segregation is preserved across all federation and migration data flows, with no entitlement detail crossing the DMZ boundary.
Governance, compliance & stakeholder leadership
- Own architecture decisions and trade-offs; present designs to client security, compliance, and PAM leadership for sign-off.
- Ensure all migration and access-control designs produce audit evidence sufficient for TSA compliance reporting.
- Evaluate and position complementary tooling (e.g. Hydden for continuous identity discovery) against native CyberArk capability.
- Define acceptance criteria and go/no-go gates for pilot and production wave sign-off.
- Mentor and provide technical direction to CyberArk Senior Engineers delivering the build.
Required experience & skills
- 10+ years in Identity and Access Management, with 5+ years specifically in CyberArk PAM architecture and design.
- Deep hands-on knowledge of CyberArk EPV, PVWA, CPM, PSM, AAM/CCP, and Vault architecture across on-prem and Privilege Cloud deployments.
- Proven experience leading a CyberArk version migration (v10/v11/v12 → v13/v14) at enterprise scale.
- Strong working knowledge of SAML 2.0 and OIDC federation design, including experience integrating CyberArk PVWA with an enterprise IdP (Entra ID, Okta, or equivalent).
- Experience with credential provider architectures (CP, CCP) and application onboarding at scale (100+ application estates).
- Familiarity with MFA migration projects (e.g. RSA SecurID to a cloud MFA/Conditional Access model).
- Experience operating in regulated environments (financial services, telecom, or government) with formal change control and audit evidence requirements.
- Strong client-facing communication skills; able to present architecture to both technical and executive stakeholders.
Information Security Responsibilities
Skills
Explore related jobs
More jobs at bounteous
Jobs in London
Senior AdministratorIngleton Wood · London, London- Assistant Manager(09759) - 1082-1084 Eagleton Blvd.Domino's · London, OH
Client Services ManagerFertifa · London, United Kingdom
Early Years Educator ApprenticeshipLMP Group · London, Greater London- FP&A and Strategic Finance LeadWindracers · London, United Kingdom
Senior Art Director - LondonAkcelo · London, London
Browse these categories
Market data for this role
All reports →- SeriesRole reportsOne role family at a time: how many openings, what changed this week, who is hiring, what it pays.
- SeriesSalary reportsWhat employers publish in job postings, by level and workplace. Not self-reported pay.
- Market overviewState of tech hiring, September 2026: up 4.8%Tech hiring rose 4.8% month over month in September 2026, with 411,122 new listings. Customer support and account executive roles led the growth.
