About the role

  • CyberArk EPM Engineer responsible for least-privilege access controls on endpoints. Focuses on application control, endpoint hardening, and regulatory compliance in hybrid environments.

Responsibilities

  • Design, implement, and manage least-privilege access controls on endpoints.
  • Manage EPM policies, application groups, sets, and rules.
  • Handle application onboarding (browsers, Office apps, etc.).
  • Configure CrowdStrike Admin platform.
  • Design JIT and time-bound elevation policies.
  • Implement command-line restrictions and file reputation–based rules.
  • Integrate CyberArk EPM with Microsoft Entra ID for policy enforcement.
  • Support SSO-based elevation workflows.
  • Analyze elevation events, blocked executions, and anomaly patterns.
  • Generate reports on policy usage and security posture.

Requirements

  • Strong hands-on experience with CyberArk Endpoint Privilege Manager (EPM).
  • In-depth understanding of:
  • Windows process execution & parent-child relationships
  • PowerShell, CMD, MSI/EXE installers
  • File reputation, hash, certificate, and path-based controls.
  • Experience with Microsoft Entra ID (Azure AD) integration.
  • Working knowledge of Windows OS internals and endpoint security controls.
  • Familiarity with SIEM tools (Microsoft Sentinel, Splunk, etc.).
  • Experience with Defender for Endpoint is a plus.
  • Understanding of least privilege, endpoint hardening, and zero-trust principles.

Job title

CyberArk Engineer III

Job type

Experience level

Mid levelSenior

Salary

Not specified

Degree requirement

No Education Requirement

Tech skills

Location requirements

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job