Cybersecurity Architect (Cyberark)

Sopra Steria

Downtown Core, SGonsitePosted Jul 31, 2026
Posting intelligenceActively listed

Skills

kubernetespythonazurecicdgooglecloudaws

About the role

Company Description

Sopra Steria is a listed European technology leader specializing in Consulting, Digital Services, and Software. With over 51,000 employees worldwide across Europe, North America and Asia, the Group supports organizations in driving their digital transformation and delivering sustainable business value.

In Asia Pacific, Singapore serves as the regional headquarter for Sopra Steria’s Infrastructure, Cloud and Cybersecurity services.

Descriptions:

For this position, we are looking for a Cybersecurity Architect (Cyberark) to assist one of our clients in the banking industry – a leading global investment bank.

As the APAC IAM Production-Cybersecurity Architect CyberArk Expert, you will lead the design, implementation, and continuous improvement of CyberArk vault and associated PAM solutions across all APAC operations.

Reporting to the APAC Head of IAM Production, this role is accountable for securing, monitoring, and governing all privileged credentials and sessions, thereby reducing the risk of credential‑theft, insider abuse, and lateral movement in the enterprise environment.

You will be measured on the following four performance drivers that will dictate how individual impact is considered on the platform:

Expert knowledge of CyberArk (Vault, PSM, CPM), and PAM solutions.

Demonstrated L3-level expertise in Conjur (design, policy-as-code, secret lifecycle automation, and Kubernetes integration) combined with deep, hands-on experience in CyberArk Privileged Access Management, enabling the architect to drive end-to-end secret-management and privileged-account implementation

Proven track record of building high-availability, resilient identity platforms with robust monitoring, automated remediation, and documented DR procedures

Client, Customer and Stakeholder Focus, Compliance Culture and Conduct

Job Description

Responsibilities:

Define and own the enterprise‑wide CyberArk architecture (Vault, CPM, PSM, PVWA, Conjur, ) to support the banks technical accounts inventory.

Design and enforce privileged‑access policies (least‑privilege, separation‑of‑duties, time‑bound access) across Windows, Linux, UNIX, databases, cloud platforms (AWS, Azure, GCP)

3. Provide high-availability support for the CyberArk, establishing robust monitoring, incident-response, and disaster-recovery processes that keep critical services up and running 24×7.

Drive the secret‑management lifecycle – automatic password rotation, SSH key management, API‑credential vaulting, and on‑demand retrieval.

Partner with engineering, application, and cloud teams to embed secure identity controls into every new service launch, migration, or platform upgrade.

Automate PAM processes using PowerShell, Python, and CyberArk REST APIs (e.g., bulk onboarding/off‑boarding, credential rotation schedules).

Evaluate emerging PAM technologies (e.g., CyberArk Conjur, Secret-Zero, Zero-Trust Privilege) and build business cases for adoption.

Collaborate with DevSecOps, Cloud, and Application teams to embed privileged-access controls into CI/CD pipelines and cloud-native workload

Qualifications

Requirements:

Requires a minimum of 8+ years of experience as security professional

Bachelor’s degree in Computer Science, Information Security, or related field (Master’s ).

Hands-on experience architecting, deploying, and operating CyberArk PAS (Vault, CPM, PSM, PVWA) at enterprise scale.

Conjur (CyberArk) – L3 – policy-as-code (CPL/HCL), secret rotation, dynamic secrets, Kubernetes side-car injection, API/CLI integrations

Deep expertise in CyberArk Core PAS components and CyberArk Privileged Threat Analytics.

Strong knowledge of Windows/UNIX/Linux authentication mechanisms, Kerberos, LDAP/AD, SSH, database authentication.

Experience integrating CyberArk with SSO/IdP solutions (SAML, OIDC, AD).

Proficiency in PowerShell, Python, and CyberArk REST API for automation.

Familiarity with cloud providers (AWS Secrets Manager, Azure Key Vault) and Hybrid‑IAM environments.

Solid understanding of Zero‑Trust concepts for privileged access.

Excellent interpersonal and communication skills; ability to influence and motivate

Leverage PAM analytics (session recordings, anomaly scores) to drive risk-based decisions

Ability to handle high pressure situations with key stakeholders to collaborate and communicate effectively and respectfully with both business-oriented executives and technology-oriented personnel in teams across the organization

Specific qualifications:

CyberArk Certified Defender (CCD)

Secrets Manager (Conjur) certified

Additional Information

Work-life balance: Hybrid working mode and 18 days of Annual leave

Health & insurance: Comprehensive coverage including General Practitioner, hospitalization, dental, and optical

•Performance incentives: Annual bonus based on individual performance

•Learning & development: Training programs, certification opportunities, and training incentives to support career growth

•Team culture: Regular team-building activities and social events

Questions about this role

Click "Apply with AI Applyd" above and you are done. Your resume is rewritten for this advert, the screening questions are answered, and it is submitted on Sopra Steria's own hiring system. No retyping your history, no fourteen tabs, no evening lost.

Compensation for Security Engineer roles in Singapore varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Security Engineer hub for Singapore medians across recent openings.

You never touch the form - the application is filled and submitted for you on Sopra Steria's own hiring system. It is not marked sent when we press submit. It is marked sent when a confirmation from their system arrives at the address we apply with, and your dashboard shows which stage each application is at until then.

Twelve applicant tracking systems have a real apply path: Workday, Greenhouse, Lever, Ashby, Workable, iCIMS, Personio, Recruitee, Teamtailor, Rippling, Breezy and SmartRecruiters. Your application goes in on the employer's own hiring system, never into an aggregator queue.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.