Please Accept our Privacy Policy
Overview
CTG is seeking to fill an IAM Security Consultant/CyberArk Engineer position for our client.
Location: Dallas, TX
Duration: 5 months
Duties:
Deploy, configure, and maintain CyberArk components, including Digital Vault, Central Policy Manager (CPM), Password Vault Web Access (PVWA), and disaster recovery vaults.
Configure and manage CyberArk safes, platform onboarding, credential rotation, reconciliation accounts, and privileged access policies.
Perform failover, backup, restore, and disaster recovery testing to ensure the availability and resilience of privileged access infrastructure.
Onboard, manage, and secure privileged accounts across Windows Server, RHEL/Linux, service accounts, SSH keys, scheduled tasks, application pools, and database platforms.
Support Identity and Access Management (IAM) initiatives, including identity lifecycle management, provisioning, deprovisioning, and identity migration across enterprise IT, cloud, OT, and IoT environments.
Implement and support IAM solutions, including Single Sign-On (SSO), directory services, and identity federation.
Develop scripts to automate identity provisioning, migration, credential management, and other IAM processes.
Support privileged access security within operational technology (OT), regulated utility, and air-gapped environments.
Ensure IAM and privileged access solutions align with applicable security controls, regulatory requirements, change management processes, and operational resilience standards.
Collaborate with security, infrastructure, and application teams to troubleshoot issues and improve identity security.
Skills:
Hands-on expertise deploying and configuring CyberArk components, including Digital Vault, CPM, PVWA, disaster recovery vaults, safes, and platform integrations.
Strong knowledge of privileged access management (PAM), privileged account onboarding, credential rotation, reconciliation, and access controls.
Experience managing privileged accounts across Windows Server, RHEL/Linux, service accounts, SSH keys, scheduled tasks, application pools, and databases.
Knowledge of IAM solutions such as IBM ISIM/ISAM, Okta, SailPoint, Microsoft Entra ID, and cloud identity platforms.
Proficiency with directory services, including Active Directory (AD) and Tivoli Directory Integrator (TDI).
Familiarity with SAML, OAuth, Single Sign-On (SSO), and identity federation.
Scripting and automation skills for identity provisioning, migration, and security administration.
Understanding of OT/IoT security, air-gapped infrastructure, and secure access management in critical environments.
Familiarity with NERC CIP controls, change management, disaster recovery, and infrastructure resilience requirements.
Strong troubleshooting, analytical, documentation, and communication skills.
Experience:
Demonstrated experience implementing, configuring, and supporting CyberArk Privileged Access Management solutions in enterprise environments.
Hands-on experience managing privileged identities and credentials across Windows, Linux, application, and database platforms.
Experience supporting IAM solutions, including identity lifecycle management, SSO, directory integration, and automated provisioning.
Experience working in operational technology (OT), regulated utility environments, or air-gapped infrastructure, with an understanding of critical system security requirements.
Experience supporting disaster recovery, failover, backup, and restoration procedures for security infrastructure.
Experience developing scripts to automate IAM and privileged access management processes.
Ability to collaborate with cross-functional teams and support security initiatives in complex enterprise environments.
Education:
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent practical experience.
Relevant certifications in CyberArk, Identity and Access Management, or cybersecurity are preferred.
Excellent verbal and written English communication skills and the ability to interact professionally with a diverse group are required.
CTG does not accept unsolicited resumes from headhunters, recruitment agencies, or fee based recruitment services for this role.
To Apply: To be considered, please apply directly to this requisition using the link provided. Kindly forward this to any other interested parties. Thank you!