Posted On: Sep 08, 2026
Job Type
Experience
5 - 25 Years
Salary
$45 - $50 Per Hour
Work Arrangement
Travel Requirement
0%
Required Skills
We are seeking a highly experienced CyberArk EPM Architect to lead the design, implementation, governance, and optimization of CyberArk Endpoint Privilege Manager (EPM) solutions across enterprise environments. The ideal candidate should possess deep expertise in Endpoint Privilege Management, Windows security, application control, least privilege enforcement, and endpoint hardening.
The architect will work closely with security, infrastructure, application, and business teams to define enterprise-level privilege management strategies and ensure compliance with security policies and regulatory requirements.
Mandatory Experience
· 5+ Years of CyberArk EPM Implementation Experience.
· Experience designing enterprise-level privilege management solutions.
· Strong understanding of Windows internals and application whitelisting.
· Experience leading global deployment and migration projects.
Responsibilities
Architecture & Design
· Design and architect CyberArk EPM solutions for global enterprise environments.
· Define least privilege security models and endpoint privilege elevation strategies.
· Develop scalable EPM policies, application control frameworks, and endpoint security standards.
· Design integrations with Active Directory, Microsoft Entra ID, SIEM, ITSM, and other security tools.
· Review existing endpoint security controls and recommend improvements.
Implementation & Deployment
· Lead end-to-end CyberArk EPM implementation and migration projects.
· Configure and manage:
o Privilege Elevation Policies
o Application Control Policies
o Threat Protection Policies
o Credential Theft Protection
o Adaptive Application Controls
· Deploy EPM agents across Windows and macOS endpoints.
· Support large-scale onboarding and policy rollout activities.
Operations & Governance
· Establish governance processes for endpoint privilege management.
· Conduct security reviews and privilege access assessments.
· Define operational procedures, SOPs, and support models.
· Review exceptions and risk acceptance requests.
· Ensure compliance with internal security standards.
Security & Compliance
· Support audits and compliance requirements including:
o ISO 27001
o SOX
o PCI-DSS
o NIST
o CIS Benchmarks
· Generate security reports and risk assessments.
· Work with SOC teams for monitoring and incident response activities.
Stakeholder Management
· Engage with Security Architects, Infrastructure Teams, SOC Teams, Application Owners, and Business Leaders.
· Provide technical leadership and mentoring to engineering and operations teams.
· Present solution architecture and implementation strategies to senior management and clients.
Required Technical Skills
CyberArk Expertise
· Strong hands-on experience with:
o CyberArk Endpoint Privilege Manager (EPM)
o Privilege Elevation & Delegation
o Application Control
o Endpoint Threat Protection
o Credential Theft Protection
o Least Privilege Enforcement
· Experience with CyberArk Identity Security Platform.
Endpoint Security
· Windows Security Architecture
· Windows Administration
· Active Directory & Group Policies
· Microsoft Entra ID (Azure AD)
· Windows Defender / Microsoft Defender for Endpoint
· Endpoint Hardening
Scripting & Automation
· PowerShell
· Windows Batch Scripting
· REST API Integrations
· Automation using CyberArk APIs
Security Technologies
· SIEM (Splunk, Sentinel, QRadar)
· ITSM (ServiceNow)
· EDR/XDR Platforms
· Vulnerability Management Tools
Additional Skills:
· 10 Years in Information Security, Identity Access Management IAM, Privileged Access Management PAM, and Endpoint Security.
· Mandatory Experience: 5 Years of CyberArk EPM Implementation Experience.
· Experience designing enterprise level privilege management solutions.
· Strong understanding of Windows internals and application whitelisting.
· Experience leading global deployment and migration projects.
Job ID: LFT122264
Posted By
Chandramani Prakash