Identity Systems Engineer (CyberArk)

Identity Systems Engineer (CyberArk)

Full-Time 60000 - 80000 € / year (est.) Home office (partial)
Tokio Marine HCC International

At a Glance

  • Tasks: Lead the design and implementation of CyberArk solutions for secure access management.
  • Company: Join a leading global specialty insurer with a commitment to innovation.
  • Benefits: Enjoy a competitive salary, health benefits, and flexible hybrid work options.
  • Other info: Dynamic team environment with opportunities for professional growth.
  • Why this job: Make a real impact in cybersecurity while working with cutting-edge technologies.
  • Qualifications: Expertise in CyberArk and identity management is essential.

The predicted salary is between 60000 - 80000 € per year.

Reporting to: Manager, Identity and Access Management

Position Type: Permanent, 35 hours per week Hybrid

Overview

Standing still is not an option in the current world of Insurance. TMHCC are one of the world’s leading Specialty Insurers. With deep expertise in our chosen lines of business, our unparalleled track record and a solid balance sheet, TMHCC evaluates and manages risk like no one else in the industry. Looking beyond profit, empowering our people and delivering on our commitments are at the core of our customer values, and so is a desire to grow and provide creative and innovative solutions to our clients.

Job Purpose

The Infrastructure Collaboration Engineering team is seeking a highly experienced Senior Identity & Privileged Access Management (PAM) Engineer with expertise in enterprise Identity and Access Management, with primary specialization in CyberArk. This role will serve as the technical lead and subject matter expert for Privileged Access Management (PAM), responsible for designing, architecting, implementing, operating, and maintaining CyberArk solutions integrated across Entra ID, Active Directory, and Okta environments. The ideal candidate will possess deep end‑to‑end identity expertise while maintaining advanced hands‑on skills in CyberArk PAS, Privilege Cloud, EPM, Secrets Manager, and identity governance integration patterns.

Key Responsibilities

  • CyberArk (Primary Skillset – Privileged Access Management)
    • Proven expert knowledge of CyberArk Privilege Access Security (PAS) and/or Privilege Cloud architecture, deployment, and administration
    • Design, implement, and maintain CyberArk Vault, CPM (Central Policy Manager), PSM (Privileged Session Manager), and PTA (Privilege Threat Analytics)
    • Manage safes, platforms, account onboarding, credential rotation policies, and access controls
    • Implement Just‑in‑Time (JIT) privileged access models integrated with Entra PIM and AD tiering
    • Secure and rotate domain admin, enterprise admin, service accounts, application accounts, SSH keys, and cloud credentials
    • Integrate CyberArk with Entra ID, Active Directory, and Okta for authentication and authorization workflows
    • Deploy and manage CyberArk Endpoint Privilege Manager (EPM) for least privilege enforcement
    • Implement CyberArk Secrets Manager / Conjur for DevOps and Kubernetes environments
    • Develop automation using REST APIs, PowerShell, and CyberArk tools
    • Design CyberArk disaster recovery and vault backup strategies
    • Integrate CyberArk logs with SIEM platforms and support audit/compliance requirements
    • Maintain alignment with Zero Trust security architecture principles
    • Stay current on CyberArk roadmap, new features, and evolving PAM security threats
  • Entra
    • Proven expert knowledge of Azure Entra ID capabilities such as Conditional Access Policies, Privileged Identity Manager and Application Registrations, integrated with CyberArk privileged access controls
    • Strong understanding of PIM and the assignment of roles / IAM permissions on Management Groups, Subscriptions and Resources, aligned with Just‑in‑Time access principles
    • Azure Infrastructure Management to include user accounts, groups, conditional policies, Intune management, mobile device management, and endpoint security
    • Strong understanding of App registration, Enterprise Apps, SPN’s and managed identities with the understanding of least privileged administration when it comes to MS Graph API allocation of permissions and secure credential storage in CyberArk
    • Strong understanding of multifactor authentication, SSPR and WHfB, ensuring secure privileged authentication workflows
    • Strong PowerShell scripting Skills, automation, and scheduling skills when working with data in Azure and integrating with CyberArk APIs
    • Good understanding of Intune polices management and autopilot
    • An individual that stays abreast of the latest Entra ID features, best practices, and security trends, and make recommendations for continuous improvement
  • Active Directory
    • Strong background in Active Directory covering domains that span geo locations with numerous DCs and a user base of 5000+
    • Strong understanding of DNS and GPOs, user object and OU administration
    • Solid understanding of Microsoft Tiering, IAM, and PAM concepts with CyberArk vaulting integration for Tier 0 accounts
    • Strong knowledge of server operating systems from Windows 2016 to Windows 2025
    • Strong understanding of the FSMO roles when it comes to maintaining the security and the integrity of the domain
    • Strong understanding of the delegation of permissions across the domain OU structure aligned with least privilege principles
    • Strong PowerShell scripting skills, automation, and scheduling skills including AD account onboarding into CyberArk
    • Solid understanding of the recovery steps needed to recover a domain in the event of a disaster
  • OKTA
    • Able to demonstrate a strong understanding of IAM concepts, including identity federation, SSO, SAML, OAuth, OIDC, MFA, role‑based access control (RBAC), and least privilege principles, integrated with CyberArk privileged authentication workflows
    • Able to provide Okta subject matter expertise to a variety of program stakeholders on application integration, IAM functionality, and Okta’s feature roadmap
    • Capable of designing and implementing Okta platform configurations to align with overall solution architecture and customer requirements while integrating CyberArk for privileged user authentication
    • Willing to collaborate with Solution Architects, other solution component SMEs and stakeholders to develop and refine solution requirements, ensuring secure and efficient access for on‑premises and cloud‑based applications and resources
    • Able to drive and support customer application integrations into Okta-based IAM solutions and align privileged access controls through CyberArk
    • Troubleshoot and resolve technical issues before, during and after application integration

Skills And Experience Specification

  • Planning
    • Follow work plans, established timelines, and predefined goals for assigned work. Meet commitments on deadlines.
  • Communication
    • Communicate activities, results, and observations with employees and management as appropriate.
  • Cost Management
    • Identify areas for improvement in existing business practices. Perform work thoroughly in a cost‑efficient manner and at a high productivity level.
  • Business Controls and Policies
    • Comply with all corporate policies and procedures. Report any breakdowns in controls to management. Conduct all activities in a safe manner.
  • Other
    • Excellent troubleshooting, architectural, and documentation skills
    • Knowledge and experience with Rubrik advantageous.
    • Microsoft, Azure or Okta certification are highly beneficial.

    The Tokio Marine HCC Group of companies is an equal opportunity employer. Please visit www.tmhcc.com for more information about our companies.

Identity Systems Engineer (CyberArk) employer: Tokio Marine HCC International

At Tokio Marine HCC, we pride ourselves on being a forward-thinking employer that values innovation and employee empowerment. Our hybrid work culture fosters collaboration while providing flexibility, and we are committed to the professional growth of our team members through continuous learning opportunities and support for certifications. Join us in a dynamic environment where your expertise in Identity Systems can make a meaningful impact in the insurance industry.

Tokio Marine HCC International

Contact Detail:

Tokio Marine HCC International Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Identity Systems Engineer (CyberArk)

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for interviews by practising common questions and scenarios related to CyberArk and identity management. We recommend doing mock interviews with friends or using online platforms to get comfortable with your responses.

Tip Number 3

Show off your skills! Create a portfolio or GitHub repository showcasing your projects related to CyberArk and identity systems. This gives potential employers a tangible look at what you can do.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who take that extra step to engage with us directly.

We think you need these skills to ace Identity Systems Engineer (CyberArk)

CyberArk Privileged Access Security (PAS)
CyberArk Privilege Cloud
CyberArk Vault management
Central Policy Manager (CPM)
Privileged Session Manager (PSM)
Privilege Threat Analytics (PTA)
Just-in-Time (JIT) access models

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Identity Systems Engineer role. Highlight your experience with CyberArk and any relevant projects you've worked on. We want to see how your skills align with what we're looking for!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about this role and how your background makes you a perfect fit. Don't forget to mention your understanding of PAM and identity management.

Showcase Your Technical Skills:In your application, be sure to showcase your technical skills, especially around CyberArk, Azure Entra ID, and Active Directory. We love seeing specific examples of how you've used these technologies in past roles.

Apply Through Our Website:We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and you'll be able to keep track of your application status directly!

How to prepare for a job interview at Tokio Marine HCC International

Know Your CyberArk Inside Out

Make sure you brush up on your CyberArk knowledge before the interview. Be prepared to discuss your experience with Privileged Access Management, including specific projects where you've implemented CyberArk solutions. Highlight your understanding of CyberArk Vault, CPM, and PSM, as well as any integration work you've done with Entra ID or Active Directory.

Showcase Your Scripting Skills

Since PowerShell scripting is crucial for this role, be ready to demonstrate your skills. Prepare examples of how you've used PowerShell for automation in previous roles, especially in relation to CyberArk or Azure environments. If possible, bring along a script you've written to showcase your technical abilities.

Understand the Bigger Picture

This role isn't just about technical skills; it's also about understanding how identity management fits into the broader security landscape. Be prepared to discuss Zero Trust principles and how they relate to PAM. Show that you can think strategically about identity and access management within an organisation.

Prepare Questions for Them

Interviews are a two-way street, so come armed with thoughtful questions. Ask about their current challenges with identity management, how they see the role evolving, or what tools they plan to implement next. This shows your genuine interest in the position and helps you assess if it's the right fit for you.