Work Location: Reading or Newbury (hybrid 2 to 3 days a week)
This is an immediate and urgent requirement hence immediate joiners preferred.
Required experience & skills
- 15+ years in Identity and Access Management, specifically in CyberArk PAM architecture and design.
- Deep hands-on knowledge of CyberArk EPV, PVWA, CPM, PSM, AAM/CCP, and Vault architecture across on-prem and Privilege Cloud deployments.
- Proven experience leading a CyberArk version migration (v10/v11/v12 β v13/v14) at enterprise scale.
- Strong working knowledge of SAML 2.0 and OIDC federation design, including experience integrating CyberArk PVWA with an enterprise IdP (Entra ID, Okta, or equivalent).
- Experience with credential provider architectures (CP, CCP) and application onboarding at scale (100+ application estates).
- Familiarity with MFA migration projects (e.g. RSA SecurID to a cloud MFA/Conditional Access model).
- Experience operating in regulated environments (financial services, telecom, or government) with formal change control and audit evidence requirements.
- Strong client-facing communication skills; able to present architecture to both technical and executive stakeholders.
Migration & vault architecture
- Design the end-to-end migration architecture from CyberArk , covering entity extraction (REST API primary, PACLI fallback), transformation, reconciliation, and staged loading into the target vault.
- Define the staged-ingestion model: disabled import β CPM soft-verification β dual-run mirroring β forced rotation at cutover β ensuring no credential is exposed to a script or human during migration.
- Produce migration runbooks, RAID logs, and effort-sizing models across Safes, Accounts, Platforms, and Policies.
- Lead discovery to segment the dependent applications by integration pattern (CP agent, CCP centralized, Conjur, direct SSO) β the primary driver of onboarding sequencing and timeline risk.
- Design the CP/CCP re-onboarding approach, including AppID re-provisioning, certificate/mTLS re-issuance, and phased cutover waves.
- Define rollback and dual-run strategy per wave, including the read-only fallback window on the source vault.
Identity federation & MFA
- Design PVWA federation to Entra ID via SAML/OIDC, including claims mapping from Entra groups to CyberArk Vault Users and Safe membership.
- Architect the RSA SecurID β Entra MFA migration as a re-enrolment exercise, covering Conditional Access policy design and non-web/legacy client bridging (PrivateArk, PACLI, RADIUS-dependent flows).
- Ensure High Side / Low Side segregation is preserved across all federation and migration data flows, with no entitlement detail crossing the DMZ boundary.
Governance, compliance & stakeholder leadership
- Own architecture decisions and trade-offs; present designs to client security, compliance, and PAM leadership for sign-off.
- Ensure all migration and access-control designs produce audit evidence sufficient for TSA compliance reporting.
- Evaluate and position complementary tooling (e.g. Hydden for continuous identity discovery) against native CyberArk capability.
- Define acceptance criteria and go/no-go gates for pilot and production wave sign-off.
- Mentor and provide technical direction to CyberArk Senior Engineers delivering the build.
Required Skills
cyberark identity and access management pam architecture vault migration saml oidc enterprise security
#J-18808-Ljbffr
CyberArk Architect in Reading employer: Consult
At Consult, we pride ourselves on being an exceptional employer that fosters a dynamic and inclusive work culture. Our North America team is dedicated to professional growth, offering robust training and development opportunities while working in a fast-paced, innovative environment. Join us to be part of a collaborative team that values your contributions and supports your career aspirations in the exciting MedTech sector.