566,730open jobs
22,876companies
77,553added this week
Browse all
Salary
$18k – $40k per year (Estimated)
Location
In office (Hyderabad)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Bristol Myers Squibb is an American pharmaceutical company whose predecessors date to 1858 and 1887 and which took its present form in a 1989 merger. Its portfolio is concentrated in oncology, haematology, immunology and cardiovascular disease, including the checkpoint inhibitor Opdivo, the blood thinner Eliquis co-marketed with Pfizer, the cell therapies acquired with Celgene, and newer products such as the schizophrenia treatment Cobenfy. Headquartered in Princeton, New Jersey and listed on the New York Stock Exchange, it faces a heavy sequence of patent expiries and has been buying and licensing assets to replace them.

At Bristol Myers Squibb, our employees often ask, “Who are you working for?”-a question that fuels collaboration, accountability, and urgency in our work. Our purpose-driven culture inspires us to discover, develop, and deliver innovative medicines to prevail over serious diseases. We offer uniquely interesting and meaningful work, opportunities for growth, and a supportive environment that values inclusion, wellbeing, flexibility, and comprehensive benefits. This is work that transforms the lives of patients, and the careers of those who do it.

Overview:

We are seeking an experienced Senior CyberArk Operations Engineer to take ownership of our CyberArk privileged access management infrastructure and the integrations that support password management and retrieval across the enterprise. Our privileged access estate is moving to the CyberArk SaaS model, and the successful candidate must bring hands-on experience of operating CyberArk in a SaaS deployment together with a working understanding of the migration path from self-hosted to SaaS - whether to complete remaining migration waves or to stabilise, optimise, and run the platform once the transition is complete. The role also holds design and delivery ownership for the introduction of secrets management for application and DevOps teams and the redesign of the PMUL and ADB scope and control model. Beyond day-to-day responsibility for platform health, upgrades, and third-party integration, the successful candidate will act as the accountable owner for privileged access control decisions, progressively convert routine operational work into automation and self-service, and build PAM capability across the wider team.

Responsibilities:

  • Own the installation, configuration, and maintenance of CyberArk vault server infrastructure, ensuring compatibility and seamless integration with third-party systems for password management and retrieval.

  • Own the operation and optimisation of the CyberArk SaaS environment - tenant and connector architecture, connector capacity and resilience, integration health, vendor release and feature adoption, and validation that privileged access controls operate as designed in the SaaS model.

  • Lead any remaining migration or onboarding waves to the SaaS platform, including integration re-establishment, cutover sequencing, rollback planning, and post-migration control validation, and drive the decommissioning and clean-up of legacy self-hosted components.

  • Design and deliver the introduction of secrets management for application and DevOps teams, including the onboarding pattern, integration of secrets retrieval into build and deployment pipelines, and the retirement of hardcoded and embedded credentials.

  • Define the target scope and control model for PMUL and ADB and own the operational transition to it.

  • Collaborate with cross-functional teams to identify integration requirements and design solutions that meet business needs while adhering to security and operational standards.

  • Configure and maintain integrations between CyberArk and other password management products, such as Active Directory, LDAP, SSO solutions, and cloud-based identity providers.

  • Monitor the health and performance of integrated systems, troubleshooting issues and optimizing configurations to ensure smooth operation, and act as the final escalation point for complex CyberArk and BeyondTrust faults.

  • Develop custom scripts, automation workflows, and API-based integrations to streamline password management processes and enhance system interoperability, with a standing mandate to reduce recurring privileged access ticket volume through self-service and automation.

  • Plan and execute software upgrades, patches, and maintenance activities for CyberArk and integrated systems, including impact assessment and control validation, ensuring minimal disruption to operations.

  • Act as the accountable owner for privileged access control decisions - approval judgement on elevated and non-standard requests, break-glass authorisation, exception handling, and the technical response to internal and external audit.

  • Own the platform, safe, policy, and permission model for the privileged access estate and approve changes to it.

  • Support and enhance endpoint privilege management and just-in-time administrator access through BeyondTrust, including policy design and troubleshooting across Windows, Linux, and macOS.

  • Collaborate with IT Security teams to implement and enforce security policies and best practices for password management across integrated systems.

  • Provide technical support, direction, and review to end-users, IT teams, and operations engineers on privileged access processes and integrations.

  • Develop and maintain documentation, runbooks, and standards, and deliver structured cross-training so that privileged access coverage is held by multiple engineers rather than a single individual.

  • Stay informed about industry trends and emerging technologies in password management and privileged access management, proactively identifying opportunities for integration improvement and optimization.

Qualifications:

  • Bachelor's degree in Computer Science, Information Technology, or related field (or equivalent work experience).

  • 5 or more years of experience working with CyberArk privileged access management solutions, including at least 3 years in a design or engineering capacity rather than administration alone, with a focus on integrations with other password management products.

  • Hands-on experience operating CyberArk in a SaaS deployment (Privilege Cloud or equivalent), including tenant and connector administration, integration management, and adoption of vendor-driven releases.

  • Direct involvement in a migration from self-hosted CyberArk to the SaaS model - or an equivalent major version or architecture migration - with a clear working understanding of the migration approach, cutover and rollback planning, integration re-establishment, and post-migration control validation.

  • Strong working knowledge of CyberArk components such as EPV, CPM, PSM, PVWA, PTA, and CCP/AAM, including installation, configuration, troubleshooting, and high availability and disaster recovery design.

  • Experience integrating CyberArk with other products for password management and retrieval, such as Active Directory, LDAP, SSO solutions, and cloud-based identity providers.

  • Strong scripting skills in languages such as PowerShell or Python, with hands-on use of CyberArk REST APIs to develop custom scripts, automation workflows, and self-service capability.

  • Excellent analytical and problem-solving skills, with the ability to troubleshoot complex technical issues related to integrations and interoperability.

  • Effective communication skills, both written and verbal, with the ability to collaborate with technical and non-technical stakeholders to understand requirements and deliver solutions, and to present design decisions and control rationale to security leadership and audit.

  • CyberArk Certified Defender (CCD) required; CyberArk Sentry or Guardian, or equivalent senior privileged access certification, strongly preferred.

  • Ability to work independently with minimal direction, with a strong sense of ownership and accountability, and the capability to mentor and cross-train other engineers.

  • Willingness to learn and adapt to new technologies and methodologies in the field of privileged access management and password management integrations.

Additional Skills for Upcoming Initiatives:

  • Experience running a hybrid privileged access estate during and after a SaaS transition, including coexistence of self-hosted and SaaS components and legacy decommissioning.

  • Practical experience with secrets management platforms such as CyberArk Conjur, HashiCorp Vault, or a cloud-native equivalent, and with removing hardcoded credentials from application code and CI/CD pipelines.

  • Familiarity with DevOps tooling and pipeline integration (Jenkins, GitLab, Azure DevOps, Ansible, Terraform) sufficient to design and support secrets retrieval patterns for application teams.

  • Experience with cloud privileged access in AWS, Azure, or GCP, including onboarding of cloud accounts, roles, and workload identities.

  • Experience with endpoint privilege management and just-in-time administrator access, ideally BeyondTrust Privilege Management.

  • Understanding of Unix and Linux privilege delegation models such as PMUL and sudo policy design, and of privileged database access controls.

  • Experience integrating privileged access telemetry with SIEM platforms such as Splunk or Microsoft Sentinel for monitoring and detection use cases.

  • Experience operating as a control owner in a regulated or audited environment, including direct engagement with auditors and remediation of control findings.

If you are passionate about operational excellence, want ownership of an enterprise privileged access estate, and enjoy working with cutting-edge technologies to secure and manage privileged access across integrated systems, we encourage you to apply for this exciting opportunity to join our CyberArk operations team.

We hire for skills and capabilities, not just credentials - if this role excites you, but doesn’t perfectly match your resume, we encourage you to apply anyway.

How We Work

Where you work matters - because collaboration, innovation and patient impact happen in many settings. Our roles are structured across four work models: site-essential, site-by-design, field-based and remote-by-design. The model assigned to this role is based on its core responsibilities. Learn more at https://careers.bms.com/ways-of-working.

Supporting People with Disabilities

BMS is dedicated to ensuring that people with disabilities can excel through a transparent recruitment process, reasonable workplace accommodations/adjustments and ongoing support in their roles. Applicants can request a reasonable workplace accommodation/adjustment prior to accepting a job offer. If you require reasonable accommodations/adjustments in completing this application, or in any part of the recruitment process, direct your inquiries to [email protected]. Visit careers.bms.com/eeo-accessibility to access our complete Equal Employment Opportunity statement.

Candidate Rights

BMS will consider qualified applicants with arrest and conviction records, pursuant to applicable laws in your area.

For roles based in Los Angeles County only: If you live in or expect to work from Los Angeles County if hired for this position, please visit this page for important additional information: https://careers.bms.com/california-residents/

Data Protection

We will never request payments, financial information, or social security numbers during our application or recruitment process. Learn more about protecting yourself at https://careers.bms.com/fraud-protection.

Any data processed in connection with role applications will be treated in accordance with applicable data privacy policies and regulations.

If this posting is missing required information required by local law or incorrect, contact BMS at [email protected] with the Job Title and Requisition number. Do not send application-related inquiries to this email. To check your application status, please login to your Candidate Home Account.

R1606194 : Senior CyberArk Operations Engineer
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
566,730 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Hyderabad
$80k – $100k per year • Equity • Remote/Hybrid • Full-Time • Bachelor's Degree • Pittsburgh
Python
SQL
AI/ML
Claude
Prompt Engineering
AI Agents
OpenAI
Anthropic
DevOps
Rest API
GCP
Azure
Git
AWS
Analytics
Power BI
Apply
In office
Python
SQL
Databases
MySQL
PostgreSQL
MS SQL
Amazon Aurora
DevOps
Terraform
CloudFormation
Prometheus
CI/CD
AWS
Grafana
Amazon EC2
Amazon S3
Amazon CloudWatch
Apply
Data Engineer 1 hour ago
Remote/Hybrid
Python
SQL
Python
pySpark
Databases
Snowflake
Databricks
MS SQL
Google BigQuery
BigQuery
AI/ML
Spark
Pandas
DevOps
Terraform
GCP
GitHub Actions
CI/CD
Jenkins
Git
Analytics
SSIS
Dimensional Modeling
Apply
$17k – $41k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Hyderabad • Bengaluru
Python
C#
DevOps
Git
Apply
$19k – $42k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Bengaluru
Python
AI/ML
Copilot
Claude Code
Scikit-learn
SciPy
TensorFlow
Pandas
NumPy
PyTorch
Streamlit
Time Series Forecasting
Interpretability
DevOps
CI/CD
Analytics
Tableau
Power BI
Plotly
Apply
$159k – $193k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Princeton
Management
Agile
Apply
$13k – $31k per year (Estimated) • In office • Full-Time • 3+ years exp • Hyderabad
Apply
$17k – $38k per year (Estimated) • In office • Full-Time • 6+ years exp • Master's Degree • Hyderabad
Apply
$72k – $125k per year (Estimated) • In office • Full-Time • Erlangen • Dresden • Würzburg
Apply
$62k – $142k per year (Estimated) • In office • Full-Time • 5+ years exp • Dublin
DevOps
GCP
Management
ServiceNow
Apply
Data Engineer 2 days ago
$21k – $50k per year (Estimated) • In office • Full-Time • 3+ years exp • Bengaluru • Hyderabad
Python
Python
pySpark
AI/ML
Spark
Analytics
ETL/ELT
Apply
Data Engineer 2 days ago
$18k – $42k per year (Estimated) • In office • Full-Time • 3+ years exp • Hyderabad
Python
Python
pySpark
AI/ML
Spark
Analytics
ETL/ELT
Apply
$25k – $58k per year (Estimated) • In office • Full-Time • 5+ years exp • Hyderabad • Chennai • Pune • Bhubaneswar • Ahmedabad
Management
Agile
Apply
$18k – $43k per year (Estimated) • In office • Full-Time • 5+ years exp • Hyderabad
DevOps
CI/CD
Apply
Web Developer 2 days ago
$25k – $59k per year (Estimated) • In office • Full-Time • 5+ years exp • Hyderabad
Python
JavaScript
Frontend
Web Components
Apply
See all jobs
This is one of many
566,730 more open roles from verified company boards, updated every day.