CyberArk/Azure Privileged Access Engineer (Montreal)

CyberArk/Azure Privileged Access Engineer (Montreal)

06 Oct
|
Microgreen Technologies
|
Montreal

06 Oct

Microgreen Technologies

Montreal

Role: CyberArk/Azure Privileged Access Engineer Montreal or Alpharetta, 3 days/week onsite We're looking for a hands-on Senior Privileged Access Engineer to design, configure, integrate, and troubleshoot CyberArk privileged access capabilities within a large-scale, enterprise Microsoft cloud environment. Design, configure, integrate, and troubleshoot CyberArk privileged access capabilities, including SIA, PAS/Privilege Cloud, PSM, EPM, and CPM/Vault components, along with privileged-session controls in Microsoft cloud environments.

Implement

CyberArk Secure Infrastructure Access/Privileged Session Management and Zero Standing Privilege patterns for Windows endpoints --- including ephemeraadministrative access, account provisioning, connector deployment, session brokering, credential rotation, revocation, and recovery workflows. Engineer integrations with Microsoft Entra ID, including Conditional Access, phishing-resistant MFA, privileged identity separation, service principals/workload identities, and appropriate use of Entra Privileged Identity Management (PIM). Design and implement secure access paths for Windows 365 and Azure-hosted Windows environments, including private connectivity, firewall requirements, connector placement, RDP/SMB/RPC dependencies, regional resiliency, and network troubleshooting.

Configure

CyberArk EPM for least-privilege application and task elevation, approved/JIT workflows, endpoint policies, local group controls, and coexistence with Microsoft Intune, Windows LAPS, Entra PIM, and other endpoint-management technologies. Define and implement privileged-account lifecycle controls with clear ownership across CyberArk CPM/SIA, Windows LAPS,



EPM, Intune, and other automation mechanisms --- ensuring password rotation, local-group membership, and privilege activation controls don't conflict with one another. Implement privileged-session monitoring and audit capabilities, including CyberArk session recording, audit APIs, Azure-native logging, and integration with enterprise security monitoring and evidence-retention platforms.

Perform hands-on validation of privilege activation, expiration, emergency revocation, disconnected-session behavior, ephemera-account cleanup, LAPS recovery, connector failures, resiliency, and privileged-session controls.

Develop

PowerShell and API-based automation, deployment tooling, configuration-as-code, operational runbooks, monitoring, health checks, and troubleshooting procedures. Advise on architecture and design decisions for extending privileged access management into cloud environments at enterprise scale, in addition to hands-on implementation. Strong, demonstrated hands-on CyberArk experience (PAS/Privilege Cloud, PSM, EPM, CPM/Vault, SIA).

Robust practical Azure and Microsoft security knowledge, including Entra ID, PIM, Conditional Access, Managed Identities, service principals, Key Vault, Azure networking, Azure Monitor, Windows 365, Intune, Windows LAPS, and Microsoft Graph. Solid understanding of PAM concepts, endpoint security, and Intune-based endpoint management. Deep Windows security experience, including local accounts/groups, Windows authentication, RDP, WinRM/PowerShell remoting, UAC, credential protections, and endpoint hardening.

Experience with large-enterprise CyberArk implementations. #

📌 CyberArk/Azure Privileged Access Engineer (Montreal)
🏢 Microgreen Technologies
📍 Montreal

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: cyberark/azure privileged access engineer (montreal) / montreal

Subscribe to this job alert:

Get the latest job offers by email for: cyberark/azure privileged access engineer (montreal) / montreal