13 days ago
Hartford, CT, USA +2 moreSenior
Base Salary
$127k - $209k/yr
Responsibilities
- Own the architecture, deployment, configuration, and lifecycle of self-hosted CyberArk components, including PVWA, CPM, PSM, and PSMP.
- Maintain CyberArk platform policies, safe structures, access controls, and master policy settings according to least-privilege and separation-of-duties principles.
- Onboard privileged accounts and secrets across Windows, Linux/Unix, databases, network devices, and cloud platforms.
- Develop custom CPM plugins and connection components for platforms lacking out-of-the-box support.
- Lead disaster recovery, high availability, backup validation, version upgrades, migrations, and resilience improvements.
- Build automation for onboarding, reconciliation, reporting, and health monitoring using the CyberArk REST API and PowerShell.
- Troubleshoot complex CyberArk PAM issues involving connection components, PSM recordings, CPM rotation, and vault performance.
- Document standards and runbooks and provide guidance and coaching to team members.
- Advance privileged access toward passwordless, certificate-based, ephemeral, and just-in-time access models.
- Integrate PAM with identity, IT service management, security monitoring, and secrets-consumer ecosystems.
Requirements
- Hands-on experience operating self-hosted, on-premises CyberArk PAM in a production enterprise environment.
- Strong knowledge of CyberArk Vault, PVWA, CPM, PSM/PSMP, with familiarity with PTA, Conjur, or CyberArk SaaS offerings.
- Experience developing custom connection components and CPM plugins for non-standard platforms.
- Proficiency with the CyberArk REST API and PowerShell; Python is a plus.
- Strong knowledge of Windows Server and Active Directory, plus working knowledge of Linux/Unix privileged access models.
- Practical understanding of LDAP, SAML, Kerberos, certificates, authentication protocols, and PKI concepts as they relate to PAM.
- Understanding of just-in-time, zero-standing-privilege, passwordless, certificate-based, and ephemeral access models.
- Experience integrating PAM with Entra ID, Okta, ServiceNow, SIEM platforms, and secrets consumers through APIs.
- Experience evaluating, piloting, or integrating new PAM capabilities and planning phased rollouts.
- Track record leading upgrades, migrations, or resilience improvements in self-hosted deployments.
- CyberArk Defender, Sentry, or Guardian certification is preferred.
- Exposure to hybrid and cloud privileged access patterns using AWS and Azure.
- Experience supporting privileged access in a regulated industry.
- Bachelor’s degree in Computer Science or a similar field, or equivalent work experience.
- At least four years of experience in information technology security engineering or software engineering.
Benefits
- Health insurance coverage for eligible employees and family members begins on the first day of employment.
- Travelers matches 401(k) contributions dollar-for-dollar up to the first 5% of eligible pay, subject to an annual maximum.
- The Paying it Forward Savings Program provides annual 401(k) contributions for eligible employees making student loan payments.
- Employees are eligible for a Travelers-funded pension plan.
- The role provides at least 20 days of paid time off annually plus nine paid company holidays.
- Wellness, mental health, caregiving, counseling, health coaching, and related support resources are available.
- Travelers offers matching gift and volunteer rewards programs.
- The posting states that Travelers may fill the position at a level above or below the level listed.
