What are the responsibilities and job description for the CyberArk Architect position at Prophecy Technologies?
Job Tittle : CyberArk Architect -PAM
Location : Manhattan, NY
Role Summary
We are hiring a Senior CyberArk Architect who has responsibly owned and delivered large-scale PAM implementations in financial services — not observed them, not advised on them, but owned them end-to-end. You've designed on-prem, p-Cloud & Hybrid vault topologies that serve tens of thousands of accounts across segmented network zones, defined safe hierarchies that scale across business units, and stood in front of infrastructure, security, and risk stakeholders to defend your architecture decisions.
You'll define the target-state architecture, establish design standards, drive requirements across platform teams, and ensure what we build is production-grade, scalable, and audit-ready from day one. You won't just draw — you'll own the outcome.
What You'll Do
Architecture & Design
• End-to-end CyberArk architecture — Hybrid Vault topology b/w an on-prem and cloud vault (primary, DR, satellite), HA strategy, replication design, and component placement across data centers and cloud regions
• Safe hierarchy design — RBAC model, and platform structure that scales to 20,000 managed accounts across hundreds of platform types
• PSM/PSMP proxy layer architecture — Connection component strategy, and session routing across network zones with strict segmentation
• Privilege Cloud integration model — Connector placement, secure tunnel architecture, and hybrid coexistence with on-prem Vault
• SIA architecture — Deployment model for dynamic/just-in-time access use cases across cloud and on-prem targets
• SRS/CPM platform design patterns — Rotation policies, reconciliation strategies, plugin selection, and failure handling
Stakeholder Engagement & Requirements
• Lead requirements elicitation with platform teams (Windows, Linux, Unix, Database, Network, Cloud, Middleware) to define account types, access patterns, rotation constraints, and onboarding sequencing
• Partner with Network/Firewall teams to define proxy architecture, port matrices, firewall rule sets, and connector communication paths
• Engage with Identity and Security Architecture teams on integration points — IdP federation, SIEM forwarding, ticketing workflows, and governance reporting
• Present architecture decisions to Security Leadership, Risk, and Audit stakeholders; defend design choices against regulatory and compliance requirements (SOX, OCC, FFIEC, NIST)
Standards & Governance
• Author platform design standards, safe naming conventions, onboarding patterns, and exception-handling procedures
• Define operational model — monitoring, alerting, patching cadence, upgrade strategy, and capacity planning
• Establish credential lifecycle policies — rotation frequency, reconciliation windows, break-glass procedures, and dual-control workflows
Technical Oversight
• Provide technical leadership to implementation engineers; review configurations, platform definitions, and deployment decisions
• Own escalation for complex design problems — multi-domain rotation dependencies, cross-zone session brokering, edge-case platform behaviors
• Drive vendor engagement with CyberArk and support escalation for architectural issues
What You Bring
Must-Have
• 7 years of hands-on CyberArk architecture and engineering experience
• Proven ownership of at least one large-scale CyberArk deployment (10,000 managed accounts) in a financial institution (banking, capital markets, insurance, asset management)
• Deep expertise in Digital Vault architecture — installation, hardening, replication, DR failover/failback, and performance tuning
• Expert-level Safe design — RBAC modeling, member permissioning, CPM assignment strategies, and platform-to-safe binding at scale
• Expert-level SIA architecture (Secure Infrastructure Access) — architecture, connector deployment, and policy configuration
• Expert-level PSM/PSMP architecture — proxy deployment models, connection component design, HTML5 Gateway, session recording storage, and load balancing
• Strong CPM platform design expertise — built-in and custom platforms, plugin development/customization, rotation and reconciliation logic, and failure triage
• Production experience with Privilege Cloud — connector architecture, secure tunnel, component deployment, and hybrid integration with on-prem Vault
• Demonstrated ability to drive network/proxy requirements — firewall rules, port matrices, DMZ placement, and segmented zone traversal
• Experience navigating regulatory and audit requirements in financial services (SOX controls, access certification, session recording retention)
• Strong stakeholder communication — can translate technical architecture into risk/business language for senior leadership
Nice-to-Have
• CyberArk Sentry (or Guardian) certification
• Experience with CyberArk Secrets Manager / Conjur for application identity
• Secrets Hub or Cloud Entitlements Manager exposure
• Familiarity with EPM and Identity Security (Workforce SSO/MFA)
• Background in infrastructure architecture (Active Directory, PKI, network segmentation)
• Experience with IaC-driven deployment (Terraform, Ansible) for CyberArk components
What Success Looks Like (First 6–12 Months)
• Target-state architecture documented, approved by Security Architecture Review, and baselined for implementation
• Vault topology deployed and hardened (Primary DR), replication validated, and DR failover tested
• Safe hierarchy, RBAC model, and platform standards defined and adopted by implementation team
• First 3–5 platform types fully designed, tested, and onboarded to production (e.g., Domain Admin, Enterprise Admin, Network equipment, Linux Root, Service Accounts)
• Network architecture for PSM proxy layers and Privilege Cloud connectors implemented across all required zones
• Operational runbooks, monitoring, and alerting in place for steady-state