{"schemaVersion":"jobsearcher.job.v1","id":"0b268c0e1f0a9a8ec5ccb183","url":"https://jobsearcher.com/jobs/0b268c0e1f0a9a8ec5ccb183","canonicalUrl":"https://jobsearcher.com/jobs/0b268c0e1f0a9a8ec5ccb183","title":"Security Engineer","description":"Role: CyberArk & Endpoint Security EngineerWork address: Lutz FL 33549Work Schedule: onsite 4 days/1 day WFHJob SummaryWe are seeking a CyberArk & Endpoint Security Engineer to design, implement, and maintain our enterprise identity and endpoint security platforms. In this role, you will lead the deployment and management of CyberArk PAM (Privileged Access Management) and CyberArk EPM (Endpoint Privilege Manager). Your primary goal will be to enforce the principle of least privilege, eliminate standing local administrator rights across thousands of workstations, and secure high-value infrastructure credentials.Core ResponsibilitiesPlatform Administration: Manage the health, configuration, and scaling of CyberArk PAM (Privilege Cloud or Self-Hosted) and CyberArk EPM environments.Least Privilege Enforcement: Design, test, and implement EPM application control policies to remove local admin rights from Windows and macOS endpoints without disrupting business operations.Credential Management: Configure automated password rotation, verification, and session monitoring policies via CyberArk Central Policy Manager (CPM) and Privileged Session Manager (PSM).Agent Deployment: Partner with Desktop Engineering teams to package and distribute the CyberArk EPM agent globally using tools like Microsoft Intune and Jamf.Policy Optimization: Analyze EPM discovery logs to create just-in-time (JIT) privilege elevation rules and trusted application definitions for standard users.Integration & Automation: Develop PowerShell or Python scripts using CyberArk REST APIs to automate account onboarding and integrate workflows with ServiceNow.Incident Support: Act as the Tier 3 escalation point for troubleshooting credential rotation failures, agent communication issues, and application elevation blocks.Required Technical Skills & QualificationsCyberArk Expertise: Minimum 3+ years of hands-on experience managing CyberArk PAM and EPM policy structures.Operating Systems: Deep technical knowledge of Windows OS architecture (UAC, Registry, Local Groups) and macOS security frameworks.Directory Services: Strong understanding of Active Directory, Azure AD/Entra ID, Group Policy Objects (GPOs), and LDAP.Endpoint Management Tools: Proven experience deploying software and configuration profiles via Microsoft Intune, SCCM, or Jamf.Scripting: Proficiency in PowerShell, Bash, or Python for task automation and API integration.Security Fundamentals: Solid grasp of enterprise network architecture, TLS/SSL certificates, SIEM integrations (e.g., Splunk), and modern IAM concepts (SAML, OIDC, MFA).Preferred QualificationsCertifications: CyberArk Certified Defender, Sentry, or CDE (CyberArk Delivery Engineer). CISSP or CompTIA Security+ is a plus.Experience: Prior experience executing a successful global rollout of EPM or similar application whitelisting solutions.","company":"Rulesiq","rawCompany":"rulesiq","city":"Lutz","state":"FL","isRemote":false,"isActive":false,"createdAt":"2026-08-19T12:13:59.574Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1244.00","title":"Network and Computer Systems Administrators","slug":"network-and-computer-systems-administrators"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security Engineer","description":"Role: CyberArk & Endpoint Security EngineerWork address: Lutz FL 33549Work Schedule: onsite 4 days/1 day WFHJob SummaryWe are seeking a CyberArk & Endpoint Security Engineer to design, implement, and maintain our enterprise identity and endpoint security platforms. In this role, you will lead the deployment and management of CyberArk PAM (Privileged Access Management) and CyberArk EPM (Endpoint Privilege Manager). Your primary goal will be to enforce the principle of least privilege, eliminate standing local administrator rights across thousands of workstations, and secure high-value infrastructure credentials.Core ResponsibilitiesPlatform Administration: Manage the health, configuration, and scaling of CyberArk PAM (Privilege Cloud or Self-Hosted) and CyberArk EPM environments.Least Privilege Enforcement: Design, test, and implement EPM application control policies to remove local admin rights from Windows and macOS endpoints without disrupting business operations.Credential Management: Configure automated password rotation, verification, and session monitoring policies via CyberArk Central Policy Manager (CPM) and Privileged Session Manager (PSM).Agent Deployment: Partner with Desktop Engineering teams to package and distribute the CyberArk EPM agent globally using tools like Microsoft Intune and Jamf.Policy Optimization: Analyze EPM discovery logs to create just-in-time (JIT) privilege elevation rules and trusted application definitions for standard users.Integration & Automation: Develop PowerShell or Python scripts using CyberArk REST APIs to automate account onboarding and integrate workflows with ServiceNow.Incident Support: Act as the Tier 3 escalation point for troubleshooting credential rotation failures, agent communication issues, and application elevation blocks.Required Technical Skills & QualificationsCyberArk Expertise: Minimum 3+ years of hands-on experience managing CyberArk PAM and EPM policy structures.Operating Systems: Deep technical knowledge of Windows OS architecture (UAC, Registry, Local Groups) and macOS security frameworks.Directory Services: Strong understanding of Active Directory, Azure AD/Entra ID, Group Policy Objects (GPOs), and LDAP.Endpoint Management Tools: Proven experience deploying software and configuration profiles via Microsoft Intune, SCCM, or Jamf.Scripting: Proficiency in PowerShell, Bash, or Python for task automation and API integration.Security Fundamentals: Solid grasp of enterprise network architecture, TLS/SSL certificates, SIEM integrations (e.g., Splunk), and modern IAM concepts (SAML, OIDC, MFA).Preferred QualificationsCertifications: CyberArk Certified Defender, Sentry, or CDE (CyberArk Delivery Engineer). CISSP or CompTIA Security+ is a plus.Experience: Prior experience executing a successful global rollout of EPM or similar application whitelisting solutions.","datePosted":"2026-08-19T12:13:59.574Z","dateModified":"2026-08-19T12:13:59.574Z","hiringOrganization":{"@type":"Organization","name":"Rulesiq","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Lutz","addressRegion":"FL","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"0b268c0e1f0a9a8ec5ccb183"},"url":"https://jobsearcher.com/jobs/0b268c0e1f0a9a8ec5ccb183"}}