Job Description & Details
This is a heavy-duty engineering role focused on locking down enterprise Microsoft cloud environments using the CyberArk stack. You won't just be drawing architecture diagrams; you'll be knee-deep in configuration-as-code, debugging ephemeral access workflows, and fixing broken RDP/SMB dependencies in Azure. If you like architecting secure identity perimeters and actually building them yourself, this one's worth a look.
What You'll Actually Be Doing
You'll spend your days designing and configuring CyberArk capabilities like SIA, Privilege Cloud, PSM, EPM, and CPM alongside Microsoft Entra ID and Windows 365 environments. Expect to build out Zero Standing Privilege patterns, wrestle with API integrations for your ITSM platforms, and figure out why a credential rotation workflow is failing across a massive Azure footprint. You will constantly balance security controls with developer and admin productivity so people can actually get their work done without bypassing your guardrails.
The Core Tech Stack
You need deep, battle-tested expertise with CyberArk—specifically Privilege Cloud, PSM, EPM, CPM, and SIA. Pair that with strong hands-on Azure and Microsoft security knowledge, including Entra ID, PIM, Conditional Access, Windows LAPS, and Intune. If you don't know your way around PowerShell and API-driven automation for configuration-as-code, you're going to have a hard time keeping up with the operational runbooks and health checks required here.
Interview Expectations
The hiring manager is going to test whether you've actually managed enterprise-scale cluster failures or if you've only read the documentation. They'll likely ask you to explain how you troubleshoot a scenario where a CyberArk connector drops mid-session on an Azure-hosted Windows 365 environment while enforcing strict Zero Standing Privilege. They want to see how you think through network dependencies, firewall rules, and ephemeral account cleanup without dropping the entire administrative perimeter. They'll also probe your experience managing overlap and conflicts between Windows LAPS, Intune, EPM, and CyberArk local group controls to ensure you understand how these tools step on each other's toes.
Application Advice
Make sure your resume doesn't read like a high-level security consultant who only talks strategy. The ATS and the hiring team are looking for concrete keywords like CyberArk Privilege Cloud, EPM, CPM, SIA, Entra PIM, Windows LAPS, and PowerShell automation. Explicitly highlight large-scale enterprise migrations or troubleshooting stories involving Azure networking, service principals, and API integrations to prove you can handle the scale of this environment.