Define and own the enterprise‑wide CyberArk architecture (Vault, CPM, PSM, PVWA, Conjur, ) to support the banks technical accounts inventory.
Design and enforce privileged‑access policies (least‑privilege, separation‑of‑duties, time‑bound access) across Windows, Linux, UNIX, databases, cloud platforms (AWS, Azure, GCP)
3. Provide high-availability support for the CyberArk, establishing robust monitoring, incident-response, and disaster-recovery processes that keep critical services up and running 24×7.
Drive the secret‑management lifecycle – automatic password rotation, SSH key management, API‑credential vaulting, and on‑demand retrieval.
Partner with engineering, application, and cloud teams to embed secure identity controls into every new service launch, migration, or platform upgrade.
Automate PAM processes using PowerShell, Python, and CyberArk REST APIs (e.g., bulk onboarding/off‑boarding, credential rotation schedules).
Evaluate emerging PAM technologies (e.g., CyberArk Conjur, Secret-Zero, Zero-Trust Privilege) and build business cases for adoption.
Collaborate with DevSecOps, Cloud, and Application teams to embed privileged-access controls into CI/CD pipelines and cloud-native workload