CyberArk Engineer -OT / Critical Infrastructure (Contract)
As a CyberArk Engineer, you will be part of our Delivery Services Team, supporting the design, implementation, administration, and optimization of Privileged Access Management (PAM) solutions for clients in operational technology (OT) and regulated utility environments. You will play a critical role in securing privileged accounts, credentials, and access to critical systems while ensuring the resilience, integrity, and availability of the CyberArk platform across on-premises, segmented, and air-gapped infrastructure.
Location: USA, Remote
Employment Type: Contract, Immediate Start through March 2027
What You'll Do:
Deploy, configure, and support CyberArk PAM components, including Digital Vault, PVWA, CPM, PSM, and Disaster Recovery Vaults.
Configure Safes, platform onboarding, credential rotation, and reconciliation accounts across OT and enterprise environments.
Plan and execute failover, backup/restore, and disaster recovery testing to meet resilience requirements for critical systems.
Onboard and manage privileged accounts across Windows Server, RHEL/Linux, service accounts, SSH keys, scheduled tasks, application pools, and database platforms.
Implement secure privileged access controls that align with NERC CIP requirements and client change management processes.
Work in air-gapped and segmented networks, adapting deployment, patching, and support approaches to restricted connectivity.
Collaborate with OT, infrastructure, security, and compliance teams to gather requirements and translate them into PAM designs.
Perform upgrades, troubleshooting, and health checks, and maintain platform availability and security compliance.
Create technical documentation, SOPs, operational runbooks, and compliance evidence, and conduct knowledge transfer sessions.
Who We're Looking For:
5+ years of hands-on experience with CyberArk engineering and Privileged Access Management solutions.
Strong experience deploying and configuring Digital Vault, CPM, PVWA, and Disaster Recovery Vaults, including failover and restore testing.
Experience working in OT, regulated utility, or air-gapped environments.
Familiarity with NERC CIP controls, change management, and resilience requirements for critical infrastructure.
Hands-on experience onboarding privileged accounts across Windows Server, RHEL/Linux, SSH keys, service accounts, scheduled tasks, application pools, and databases.
Solid knowledge of Active Directory, LDAP, network segmentation, and enterprise infrastructure.
Strong troubleshooting, analytical, and problem-solving abilities.
Ability to work in a team environment as well as independently.
Strong verbal and written communication skills, with the ability to explain technical concepts to OT, IT, and compliance stakeholders.
Nice-to-Have Skills:
CyberArk certifications such as CDE – PAM, Sentry PAM, or Defender PAM.
OT security certifications such as GICSP, or experience with ISA/IEC 62443.
Experience with PSM/PSMP for secure remote access into OT environments.
Experience integrating CyberArk with MFA, SIEM, and ITSM tools.
Scripting and automation experience using PowerShell, Python, or REST APIs.
Previous consulting or client-facing implementation experience. #LI-RR1