Principal Engineer - CyberArk | On-site, Bangalore

Optiv

Job Summary

The Principal Engineer will be responsible for creating procedures, implementing processes, and developing staff for managing and maintaining security systems across internal and client environments. This role involves working closely with management, engineers, and clients to deliver high-profile, critical services to existing Managed Security Service clients. The Principal Engineer will serve as a subject matter expert and team lead for Managed Security Services, addressing client configuration issues and internal projects.

Must Have

  • Serve as primary technical responder for CyberArk Privileged Access Management incidents and requests.
  • Provide CyberArk-related troubleshooting services for projects and post-production support.
  • Perform account onboarding, safe creation, platform creation, and management.
  • Collect logs, analyze failures, troubleshoot issues, and implement solutions.
  • Assist with CyberArk postproduction activities, connector configuration, custom rule development, and third-party integration.
  • Document incident resolutions, RCA/RFOs, SOPs, design specifications, and reference architectures.
  • Perform routine changes and maintenance including hotfix, security patching, reboots, and configuration backups.
  • 8-10 years of experience implementing, administering, and supporting PAM technologies (CyberArk).
  • 4-5 years of experience deploying CyberArk Privilege Cloud (ISPSS) and associated services.
  • Proven engineering experience with end-to-end implementation and PSM/CPM plugin development.
  • Hands-on experience with Credential Provider (CP/CCP) installation and configuration.
  • Advanced scripting skills in PowerShell and Python, with practical REST API experience.
  • Experience managing service accounts with dependencies.
  • Strong troubleshooting and issue isolation skills.
  • Proficiency in CyberArk, system administration, JavaScript/Python scripting, LDAP, and Active Directory.
  • Familiarity with Privileged Access Management architecture.
  • Experience administering Windows Server OS and Unix/Linux systems via command line.
  • Familiarity with diagnostic tools and error log analysis.
  • Strong written and verbal communication skills.
  • Bachelor’s degree in computer science, Engineering, or equivalent experience.
  • Ready to relocate to Bangalore.
  • Ability to provide 24/7 support and work from office.

Good to Have

  • Relevant industry certifications (e.g., CISSP, CEH, CHFI, SSCP, CCSP).
  • Prior experience or familiarity with a NOC/SOC environment.
  • MCSE and/or MS Azure certifications.
  • CyberArk Certified Privilege Cloud (CPC) Delivery Engineer.
  • CyberArk Certified Delivery Engineer (CDE-PAM).
  • CyberArk Sentry - CyberArk Privilege Cloud (CPC).

Perks & Benefits

  • A company committed to championing Diversity, Equality, and Inclusion through Employee Resource Groups.
  • Work/life balance.
  • Professional training resources.
  • Creative problem-solving and the ability to tackle unique, complex projects.
  • Volunteer Opportunities through "Optiv Chips In" program.
  • Ability and technology necessary to productively work remotely/from home (where applicable).

Job Description

The Principal Engineer will be responsible for creation of procedures, implementation of processes and development of staff for managing and maintaining security systems across internal and client environments. The Principal Engineer will work closely with Management, Senior Engineers, Solution Architects, Senior Security Engineers, other Principal Security Engineers and clients to complete high profile, critical services to existing Managed Security Service clients. Serve as a subject matter expert and team lead for Managed Security Services, staying in tune with all client configuration issues and all internal projects.

How you’ll make an impact

  • Serve as a primary technical responder for incidents and requests pertaining to various technologies including, but not limited to: CyberArk Privileged Access Management
  • Provide CyberArk -related troubleshooting services as part of project or post-production support activities.
  • Perform account onboarding, safe creation, platform creation and management.
  • Troubleshooting of safes, platform creation and account management.
  • Collect logs, analyze failure situations, troubleshoot issues, and implement known solutions while maintaining established OLAs/SLAs.
  • Assist with all CyberArk postproduction activities, connector configuration, custom rule development, and third-party system integration.
  • Document incident resolutions, RCA/RFOs, and SOPs, design specifications, and reference architectures as needed.
  • Perform routine changes and maintenance including hotfix and security patching, device reboots, and configuration backups

What we’re looking for

  • 8–10 years of experience implementing, administering, and supporting Privileged Access Management (PAM) technologies and related infrastructure (preferably CyberArk).
  • 4–5 years of experience deploying CyberArk Privilege Cloud (ISPSS) and associated services (Identity, WPM, SIA, SWS, and SCA).
  • Proven engineering experience with end-to-end implementation and strong knowledge of PSM and CPM plugin development.
  • Hands-on experience with Credential Provider (CP/CCP) installation and configuration.
  • Advanced scripting skills in PowerShell and Python (preferred), with practical experience using REST API.
  • Experience on managing service accounts with dependencies.
  • Strong troubleshooting and issue isolation skills.
  • Proficiency in CyberArk and related technologies, including system administration, JavaScript/Python scripting, LDAP directories, and Active Directory.
  • Familiarity with Privileged Access Management architecture.
  • Experience administering Windows Server OS and Unix/Linux systems via command line (MCSE and/or MS Azure certifications a plus).
  • Familiarity with diagnostic tools and error log analysis.
  • Strong written and verbal communication skills.
  • Relevant industry certifications highly desired (e.g., CISSP, CEH, CHFI, SSCP, CCSP, etc.)
  • Prior experience or familiarity with a NOC/SOC environment highly desired.
  • Bachelor’s degree in computer science, Engineering, or equivalent experience.
  • CyberArk Certified Privilege Cloud (CPC) Delivery Engineer (Preferred)
  • CyberArk Certified Delivery Engineer (CDE-PAM)
  • CyberArk Sentry - CyberArk Privilege Cloud (CPC)
  • Ready to relocate to Bangalore
  • This team provides 24/7 support and Work from Office role.

What you can expect from Optiv

  • A company committed to championing Diversity, Equality, and Inclusion through our Employee Resource Groups.
  • Work/life balance
  • Professional training resources
  • Creative problem-solving and the ability to tackle unique, complex projects
  • Volunteer Opportunities. “Optiv Chips In” encourages employees to volunteer and engage with their teams and communities.
  • The ability and technology necessary to productively work remotely/from home (where applicable)

13 Skills Required For This Role

Account Management Communication Problem Solving Talent Acquisition Game Texts Ldap Linux Azure Unix Windows Server Powershell Python Javascript