Live bench: 42 verified engineers  //  48-hour sourcing SLA  //  0% placement fee  //  14-day risk-free trial
CyberTowers, HITEC City, Hyderabad ISO/IEC 27001:2022 & SOC 2 Type II +91 9704443164
REQUISITION // PAM PRACTICE

Senior CyberArk PAM Architecture Specialist

Lead privileged access architecture for a Fortune 500 banking estate — vault topology, onboarding waves at scale, break-glass design and audit-defensible documentation.

8-12 yrs
Experience
Hyderabad
Base location
Full time
Engagement
7-10 days
Decision loop

About the role

You will act as the design authority for a multi-year privileged access programme inside a regulated banking estate, working directly with the client's security architecture team. The role combines hands-on CyberArk engineering with architecture ownership: you will define the vault topology, set the account tiering model, sequence onboarding waves and make sure break-glass procedures survive a regulator's questions.

This is a deployment role with oneid365, not a bench position. You will be embedded with the client team from Day 1, with a named oneid365 delivery manager handling everything contractual so you can stay on the engineering.

What you will own

check_circleVault, CPM, PSM and PVWA architecture including high availability and disaster recovery design
check_circleSafe structure, platform configuration and account tiering model across the enterprise estate
check_circleOnboarding wave planning with dependency mapping and rotation validation before enablement
check_circleBreak-glass design, documented drills and independent verification of emergency access
check_circleIntegration with directory services, SIEM, ITSM and the client's identity governance platform
check_circleMentoring two to three engineers in the client pod and reviewing their configuration work

What we are looking for

check_circleEight to twelve years in infrastructure or security engineering, with at least five on CyberArk PAS
check_circleCyberArk Sentry required; Certified Delivery Engineer strongly preferred
check_circleDemonstrated experience onboarding several thousand privileged accounts across mixed platforms
check_circleComfort presenting design decisions to security architects and audit stakeholders
check_circleWorking knowledge of Active Directory tiering, Windows and Linux privilege models
check_circleExposure to EPM, HashiCorp Vault or cloud secret managers is an advantage

Interview process

Recruiter conversation, then a ninety-minute technical interview with our PAM practice head, then a recorded range lab on a live vault instance, then a client architecture discussion. You will be told the client name before the client stage. Typical end-to-end time is seven to ten days.

Call to ask a question
ROLE SUMMARY
PracticePAM
LocationHyderabad, India
EngagementFull time
Experience8-12 years
Client sectorBanking
ShiftIST with US overlap
WHY ONEID365
check_circleSponsored CyberArk certification renewals with paid study time
check_circleNamed delivery manager handling all contractual matters
check_circleClient name disclosed before you interview — never a blind submission
check_circleZero candidate fees at any stage
Life at oneid365
RAPID TALENT MOBILISATION

Not quite your profile?

Browse every live requisition, or join the depository and we will match you as new roles open.