Job Description & Details
This is a heavy-duty infrastructure security role focused entirely on locking down secrets, machine identities, and privileged access using CyberArk and Conjur. If you enjoy untangling complex RBAC models, wrangling certificates, and automating credential management in high-availability enterprise environments, this gig will keep you on your toes.
What You'll Actually Be Doing
You will spend your days knee-deep in CyberArk PAM, Vault administration, and Conjur integrations, figuring out how to securely manage secrets across cloud, IoT, and standard enterprise IT. Expect to configure CPM password rotations, manage Safes, and ensure that High Availability and Disaster Recovery setups don't fall apart when things go sideways. You'll also be dealing with TLS certificates and making sure audit logging and compliance controls pass muster without breaking developer workflows.
The Core Tech Stack
You need absolute fluency in CyberArk Privileged Access Management, Conjur, and CyberArk Secrets Manager. Beyond the core tooling, a solid grasp of directory services like Active Directory, identity federation protocols like SAML and OAuth, and scripting capabilities to automate provisioning and migration are non-negotiable. They are building a tight ship here, so if you haven't deployed and integrated these solutions in a production environment before, you'll struggle.
Interview Expectations
Be ready for the hiring manager to ask you to troubleshoot a broken Conjur follower integration where application workloads can't fetch secrets due to a TLS handshake failure or policy mismatch. They want to see how you systematically trace authentication from the application identity through the authenticator to the Conjur master. Another classic you'll face is explaining how you would design a zero-downtime credential rotation strategy using CPM across a sprawling multi-region architecture without causing unexpected application outages.
Application Advice
Make sure your resume doesn't just list 'CyberArk' as a bullet point—spell out your specific experience with Safes, CPM, Vault administration, and Conjur policy management. Explicitly drop keywords like 'Role-Based Access Control', 'TLS/certificate implementation', and 'credential lifecycle management' into your experience section so you can easily clear the ATS filters. Highlight any automation scripts you've written for identity provisioning or migration, as the team values candidates who can code their way out of repetitive operational toil.