{"id":1242744,"url":"https://alion.io/job/we-plus-cybersecurity-architect","title":"Cybersecurity Architect","company":{"id":3802230,"name":"We-Plus","domain":"we-plus.com","url":"https://alion.io/company/we-plus-2","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":null,"truth_index":null},"role":"Security","role_family":"Security","seniority":"staff","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Singapore"],"countries":["SG"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":7000,"max":11400,"currency":"SGD","period":"month","gross":true,"usd_annual":107112},"salary_estimate":null,"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"CI/CD","optional":false},{"name":"CyberArk","optional":false},{"name":"GCP","optional":false},{"name":"IAM","optional":false},{"name":"Kubernetes","optional":false},{"name":"LDAP","optional":false},{"name":"Least Privilege","optional":false},{"name":"Linux","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"Rest API","optional":false},{"name":"Unix","optional":false},{"name":"Windows","optional":false},{"name":"Zero Trust","optional":false}],"status":"live","first_seen_at":"2026-09-23T00:00:00Z","employer_posted_date":null,"last_verified_at":"2026-09-23T00:00:00Z","board_verified":false,"closed_at":null,"days_open":5,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":5},"description":"⇒ Role Summary\nAs the APAC IAM Production-Cybersecurity Architect CyberArk, leads the design, implementation, and continuous improvement of CyberArk vault and associated PAM solutions across all APAC operations. Reporting to the APAC Head of IAM Production, This role is accountable for securing, monitoring, and governing all privileged credentials and sessions, thereby reducing the risk of credential-theft, insider abuse, and lateral movement in the enterprise environment.\nCandidates will be measured on the following four performance drivers that will dictate how individual impact is considered on the platform:\nExpert knowledge of CyberArk (Vault, PSM, CPM), and PAM solutions.\nDemonstrated L3-level expertise in Conjur (design, policy-as-code, secret lifecycle automation, and Kubernetes integration) combined with deep, hands-on experience in CyberArk Privileged Access Management, enabling the architect to drive end-to-end secret-management and privileged-account implementation.\nProven track record of building high-availability, resilient identity platforms with robust monitoring, automated remediation, and documented DR procedures.\nClient, Customer and Stakeholder Focus\nCompliance Culture and Conduct\n\n ⇒ Main Responsibilities\nDefine and own the enterprise-wide CyberArk architecture (Vault, CPM, PSM, PVWA, Conjur, ) to support the banks technical accounts inventory.\nDesign and enforce privileged-access policies (least-privilege, separation-of-duties, time-bound access) across Windows, Linux, UNIX, databases, cloud platforms (AWS,Azure, GCP).\nProvide high-availability support for the CyberArk, establishing robust monitoring, incident-response, and disaster-recovery processes that keep critical services up and running 24Å~7.\nDrive the secret-management lifecycle – automatic password rotation, SSH key management, API-credential vaulting, and on-demand retrieval.\nPartner with engineering, application, and cloud teams to embed secure identity controls into every new service launch, migration, or platform upgrade.\nAutomate PAM processes using PowerShell, Python, and CyberArk REST APIs (e.g., bulk onboarding/off-boarding, credential rotation schedules).\nEvaluate emerging PAM technologies (e.g., CyberArk Conjur, Secret-Zero, Zero-Trust Privilege) and build business cases for adoption.\nCollaborate with DevSecOps, Cloud, and Application teams to embed privileged-access controls into CI/CD pipelines and cloud-native workloads.\n\n⇒ Qualifications & Experience\nBachelor’s Degree in Computer Science, Information Security, or related field (Master’s preferred).\nRequires a minimum of 8 years of experience as security professional.\nHands-on experience architecting, deploying, and operating CyberArk PAS (Vault, CPM, PSM, PVWA) at enterprise scale.\nConjur (CyberArk) – L3 – policy-as-code (CPL/HCL), secret rotation, dynamic secrets, Kubernetes side-car injection, API/CLI integrations.\nDeep expertise in CyberArk Core PAS components and CyberArk Privileged Threat Analytics.\nStrong knowledge of Windows/UNIX/Linux authentication mechanisms, Kerberos, LDAP/AD, SSH, database authentication.\nExperience integrating CyberArk with SSO/IdP solutions (SAML, OIDC, AD).\nProficiency in PowerShell, Python, and CyberArk REST API for automation.\nFamiliarity with cloud providers (AWS Secrets Manager, Azure Key Vault) and Hybrid-IAM environments.\nSolid understanding of Zero-Trust concepts for privileged access.\nExcellent interpersonal and communication skills; ability to influence and motivate\nLeverage PAM analytics (session recordings, anomaly scores) to drive risk-based decisions\nAbility to handle high pressure situations with key stakeholders to collaborate and communicate effectively and respectfully with both business-oriented executives and technology-oriented personnel in teams across the organization.\nCyberArk Certified Defender (CCD); Secrets Manager (Conjur) certified.\nSkills\nSAML, authentication process, Powershell Scripting, PowerShell, Azure Key Vault, Identity Management Systems, Threat Analysis, Trade Secrets, Computer Science, Cryptographic Key Management, Access Control Management, Technical Account Management, Disaster Recovery Management, Develop Business Cases, Deployment, DevSecOps","description_format":"text","description_chars":4237,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security"],"lifecycle":[{"event":"open","at":"2026-09-25T16:15:06Z"}],"liveness":{"score":85,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.855,"p_room":1,"age_days":5,"expected_fill_days":30,"reasons":["seen:5","velocity","win:early"],"computed_at":"2026-09-28T05:45:00Z"},"pay":{"stated_usd_annual":107112,"is_top_pay":false},"html_url":"https://alion.io/job/we-plus-cybersecurity-architect","json_url":"https://alion.io/job/we-plus-cybersecurity-architect.json","meta":{"generated_at":"2026-09-28T06:12:46Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4326,"day_limit":5000,"remaining_today":674,"minute_limit":60,"resets_at":"2026-09-29T00:00:00Z"}}}