Bounteous
CyberArk Architect

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
CyberArk Architect
3+ months rolling contract
About the role
We are seeking a CyberArk Architect to lead solution design for a large-scale, TSA-regulated Privileged Access Management (PAM) migration and merger consolidation programme. This is a hands-on architecture role spanning vault migration design, identity federation, and application onboarding strategy for an estate spanning thousands of accounts and 250+ dependent applications, delivered against a fixed regulatory deadline.
Key responsibilities
Migration & vault architecture
- Design the end-to-end migration architecture from CyberArk v12.2 to v14.2, covering entity extraction (REST API primary, PACLI fallback), transformation, reconciliation, and staged loading into the target vault.
- Define the staged-ingestion model: disabled import → CPM soft-verification → dual-run mirroring → forced rotation at cutover — ensuring no credential is exposed to a script or human during migration.
- Own name-collision resolution, platform normalisation, and policy reconciliation rules between source and target environments.
- Produce migration runbooks, RAID logs, and effort-sizing models across Safes, Accounts, Platforms, and Policies.
Application & credential provider (CP/CCP) strategy
- Lead discovery to segment the 250+ dependent applications by integration pattern (CP agent, CCP centralised, Conjur, direct SSO) — the primary driver of onboarding sequencing and timeline risk.
- Design the CP/CCP re-onboarding approach, including AppID re-provisioning, certificate/mTLS re-issuance, and phased cutover waves.
- Define rollback and dual-run strategy per wave, including the read-only fallback window on the source vault.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Identity federation & MFA
- Design PVWA federation to Entra ID via SAML/OIDC, including claims mapping from Entra groups to CyberArk Vault Users and Safe membership.
- Architect the RSA SecurID → Entra MFA migration as a re-enrolment exercise, covering Conditional Access policy design and non-web/legacy client bridging (PrivateArk, PACLI, RADIUS-dependent flows).
- Ensure High Side / Low Side segregation is preserved across all federation and migration data flows, with no entitlement detail crossing the DMZ boundary.
Governance, compliance & stakeholder leadership
- Own architecture decisions and trade-offs; present designs to client security, compliance, and PAM leadership for sign-off.
- Ensure all migration and access-control designs produce audit evidence sufficient for TSA compliance reporting.
- Evaluate and position complementary tooling (e.g. Hydden for continuous identity discovery) against native CyberArk capability.
- Define acceptance criteria and go/no-go gates for pilot and production wave sign-off.
- Mentor and provide technical direction to CyberArk Senior Engineers delivering the build.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Required experience & skills
- 10+ years in Identity and Access Management, with 5+ years specifically in CyberArk PAM architecture and design.
- Deep hands-on knowledge of CyberArk EPV, PVWA, CPM, PSM, AAM/CCP, and Vault architecture across on-prem and Privilege Cloud deployments.
- Proven experience leading a CyberArk version migration (v10/v11/v12 → v13/v14) at enterprise scale.
- Strong working knowledge of SAML 2.0 and OIDC federation design, including experience integrating CyberArk PVWA with an enterprise IdP (Entra ID, Okta, or equivalent).
- Experience with credential provider architectures (CP, CCP) and application onboarding at scale (100+ application estates).
- Familiarity with MFA migration projects (e.g. RSA SecurID to a cloud MFA/Conditional Access model).
- Experience operating in regulated environments (financial services, telecom, or government) with formal change control and audit evidence requirements.
- Strong client-facing communication skills; able to present architecture to both technical and executive stakeholders.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location