Sysgroup logo

CyberArk Engineer (contract)

Sysgroup
Posted 6 hours ago
United KingdomRemoteEngineering & Development
Is this job info correct?

Job Description

This is a remote position.

The Role

SysGroup is hiring a Cyber Security Engineer specialising in privileged access management, with CyberArk as the core platform. You will report to the Cyber Operations Lead and work closely with the SOC engineers.


UK - Remote
Day Rate: negotiable/ open to discussion
Start: ASAP

Requirements

The Engagement

A contract CyberArk Engineer to support privileged access management across SysGroup's managed client estates. Service delivery focus, with no pre-sales or leadership scope. You own the CyberArk ticket queue from L2 to L4 and are the deep escalation point for the platform. Based anywhere with remote delivery, subject to UK-hours coverage and security screening.

In one line: keep CyberArk healthy across multiple client estates and be the person the hard tickets escalate to.

Responsibilities

  • Own CyberArk incidents and requests L2–L4: triage, diagnose, fix, close within SLA.
  • Troubleshoot the full stack — vault, CPM rotation failures, PSM session issues, PVWA faults, integration breaks (Entra ID, MFA, SIEM) — including root-cause analysis and CyberArk vendor escalations.
  • Handle account onboarding/offboarding, safe and policy changes, and access reviews from the queue.
  • Patch, upgrade, renew certificates and run DR checks (Self-Hosted and Privilege Cloud).
  • Keep runbooks and known-error records current; work cleanly within ITSM change control.

Requirements

Competency
Identity & Access Management


ITSM & Service Management


Incident Management


Security Tooling & EDR

Supporting competencies (cloud, networking, network security, monitoring, scripting, vulnerability management, documentation) at Practitioner.

  • 3+ years hands-on CyberArk administration and troubleshooting in production (CPM, PSM, PVWA, vault).
  • Proven L3/L4 fault resolution under SLA pressure; ticket-queue and change-control discipline in a managed service.
  • PowerShell scripting for diagnosis and repair.
  • Desirable: Defender/Sentry certification (experience outweighs paper); Entra ID, EDR, SIEM or Zscaler exposure; MSP background


Similar jobs