Mediabistro logo
job logo

CyberArk EPM Architect

Veriipro · Richardson, TX, USA ·

Job type:
Full Time

We are seeking a highly experienced CyberArk EPM Architect to lead the design, implementation, governance, and optimization of CyberArk Endpoint Privilege Manager (EPM) solutions across enterprise environments. The ideal candidate should possess deep expertise in Endpoint Privilege Management, Windows security, application control, least privilege enforcement, and endpoint hardening.

The architect will work closely with security, infrastructure, application, and business teams to define enterprise-level privilege management strategies and ensure compliance with security policies and regulatory requirements.

Mandatory Experience

5+ Years of CyberArk EPM Implementation Experience.

Experience designing enterprise-level privilege management solutions.

Strong understanding of Windows internals and application whitelisting.

Experience leading global deployment and migration projects.

Responsibilities
Architecture & Design

Design and architect CyberArk EPM solutions for global enterprise environments.

Define least privilege security models and endpoint privilege elevation strategies.

Develop scalable EPM policies, application control frameworks, and endpoint security standards.

Design integrations with Active Directory, Microsoft Entra ID, SIEM, ITSM, and other security tools.

Review existing endpoint security controls and recommend improvements.

Implementation & Deployment

Lead end-to-end CyberArk EPM implementation and migration projects.

Configure and manage:

Privilege Elevation Policies

Application Control Policies

Threat Protection Policies

Credential Theft Protection

Adaptive Application Controls

Deploy EPM agents across Windows and macOS endpoints.

Support large-scale onboarding and policy rollout activities.

Operations & Governance

Establish governance processes for endpoint privilege management.

Conduct security reviews and privilege access assessments.

Define operational procedures, SOPs, and support models.

Review exceptions and risk acceptance requests.

Ensure compliance with internal security standards.

Security & Compliance

Support audits and compliance requirements including:

ISO 27001

SOX

PCI-DSS

NIST

CIS Benchmarks

Generate security reports and risk assessments.

Work with SOC teams for monitoring and incident response activities.

Stakeholder Management

Engage with Security Architects, Infrastructure Teams, SOC Teams, Application Owners, and Business Leaders.

Provide technical leadership and mentoring to engineering and operations teams.

Present solution architecture and implementation strategies to senior management and clients.

Required Technical Skills
CyberArk Expertise

Strong hands-on experience with:

CyberArk Endpoint Privilege Manager (EPM)

Privilege Elevation & Delegation

Application Control

Endpoint Threat Protection

Credential Theft Protection

Least Privilege Enforcement

Experience with CyberArk Identity Security Platform.

Endpoint Security

Windows Security Architecture

Windows Administration

Active Directory & Group Policies

Microsoft Entra ID (Azure AD)

Windows Defender / Microsoft Defender for Endpoint

Endpoint Hardening

Scripting & Automation

PowerShell

Windows Batch Scripting

REST API Integrations

Automation using CyberArk APIs

Security Technologies

SIEM (Splunk, Sentinel, QRadar)

ITSM (ServiceNow)

EDR/XDR Platforms

Vulnerability Management Tools

Additional Skills:

10 Years in Information Security, Identity Access Management IAM, Privileged Access Management PAM, and Endpoint Security.

Mandatory Experience: 5 Years of CyberArk EPM Implementation Experience.

Experience designing enterprise level privilege management solutions.

Strong understanding of Windows internals and application whitelisting.

Experience leading global deployment and migration projects.

#J-18808-Ljbffr