- Location
- Cape Town, Mariendahl House, South Africa
- Type
- Full-time
- Department
- Customer Service
- Education
- Bachelor
- Source
- Workday
Description
The Apex Group was established in Bermuda in 2003 and is now one of the world’s largest fund administration and middle office solutions providers.
Our business is unique in its ability to reach globally, service locally and provide cross-jurisdictional services. With our clients at the heart of everything we do, our hard-working team has successfully delivered on an unprecedented growth and transformation journey, and we are now represented by over circa 13,000 employees across 112 offices worldwide.Your career with us should reflect your energy and passion.
That’s why, at Apex Group, we will do more than simply ‘empower’ you. We will work to supercharge your unique skills and experience.
Take the lead and we’ll give you the support you need to be at the top of your game. And we offer you the freedom to be a positive disrupter and turn big ideas into bold, industry-changing realities.
For our business, for clients, and for you
The Role
As a Privileged Access Management Analyst, you will play a critical role in safeguarding Apex's privileged access landscape by owning and delivering end-to-end Privileged Access Management (PAM) services. This includes managing and supporting the CyberArk platform, driving the onboarding of applications, infrastructure, cloud platforms, and privileged accounts, and ensuring privileged access controls remain secure, compliant, and operationally effective.
You will serve as a trusted advisor to Business Units, Application Owners, Infrastructure and Cloud Engineering teams, helping them adopt PAM controls that reduce risk while enabling business operations. Working closely with Security, Risk, Compliance, Audit, and Identity Governance teams, you will ensure privileged access is governed in accordance with regulatory requirements, internal policies, and Zero Trust security principles.
The role requires a combination of technical expertise, operational excellence, stakeholder management, and continuous improvement, contributing to Apex's broader identity security strategy by expanding PAM coverage, improving automation, supporting cloud-native privileged access controls, and enhancing audit readiness across the organisation.
Success in this role is measured by secure and compliant onboarding of privileged accounts, high platform availability, effective risk reduction, successful audit outcomes, strong stakeholder engagement, and continuous improvement of PAM capabilities across the enterprise.
Key duties and responsibilities:
CyberArk Platform Operations & Support
- Administer, maintain, and support the CyberArk PAM platform, including PVWA, CPM, PSM, Safes, Platforms, Secure Cloud Access (SCA), and Endpoint Privilege Manager (EPM), ensuring platform stability, security, and availability.
- Manage day-to-day PAM operations, including service requests, privileged account lifecycle activities, user support, and operational escalations in line with agreed service levels.
- Monitor platform health, password rotation, reconciliation, session activity, system performance, and capacity to proactively identify and resolve issues.
- Troubleshoot incidents and platform failures, perform root cause analysis, and implement corrective actions to improve service reliability and user experience.
- Plan, coordinate, and execute CyberArk upgrades, patching, maintenance activities, and platform enhancements while minimising business disruption.
- Maintain operational procedures, runbooks, knowledge articles, and support documentation, while driving service improvements, operational efficiency, and adherence to support SLAs.
Privileged Access Onboarding, Integration & Automation
- Own and deliver the end-to-end onboarding lifecycle for applications, infrastructure platforms, cloud services, and privileged accounts into CyberArk, including Safe and Platform configuration and enabling applications to leverage Privileged Session Manager (PSM).
- Lead onboarding engagements with application owners and technical teams, from discovery and requirements gathering through implementation, testing, go-live, and operationalisation.
- Analyse privileged account usage, technical dependencies, and business requirements to design and implement CyberArk onboarding solutions for Windows, Linux/Unix, database, cloud, service, and application accounts.
- Configure and support CyberArk Secure Cloud Access (SCA) and Endpoint Privilege Manager (EPM) to secure privileged access across cloud and endpoint environments.
- Configure and validate password rotation, reconciliation, credential retrieval, privileged session management, and application integrations to ensure secure and compliant access controls.
- Drive automation, standardisation, documentation, and continuous improvement initiatives to accelerate onboarding delivery, improve operational efficiency, and expand PAM coverage across the organisation.
Privileged Access Governance, Risk & Compliance
- Administer, maintain, and support the CyberArk PAM platform, including PVWA, CPM, PSM, Safes, Platforms, Secure Cloud Access (SCA), and Endpoint Privilege Manager (EPM), ensuring platform stability, security, and availability.
- Manage day-to-day PAM operations, including service requests, privileged account lifecycle activities, user support, and operational escalations in line with agreed service levels.
- Monitor platform health, password rotation, reconciliation, session activity, system performance, and capacity to proactively identify and resolve issues.
- Troubleshoot incidents and platform failures, perform root cause analysis, and implement corrective actions to improve service reliability and user experience.
- Plan, coordinate, and execute CyberArk upgrades, patching, maintenance activities, and platform enhancements while minimising business disruption.
- Maintain operational procedures, runbooks, knowledge articles, and support documentation, while driving service improvements, operational efficiency, and adherence to support SLAs.
Cloud Security, Identity Governance & Stakeholder Engagement
- Support and enhance privileged access controls across Microsoft Azure, Entra ID, cloud-hosted environments, and CyberArk Secure Cloud Access (SCA) to ensure secure administration of cloud platforms and services.
- Collaborate with Security Engineering, Cloud Engineering, Infrastructure, Application Owners, Risk, Audit, and Service Management teams to deliver secure and compliant privileged access solutions.
- Support the integration of CyberArk with enterprise Identity Governance and Administration (IGA) platforms, including identity correlation, entitlement modelling, provisioning processes, and certification campaigns.
- Contribute to strategic identity security initiatives, cloud access governance programmes, PAM expansion projects, and the adoption of modern privileged access management capabilities.
- Provide technical guidance and CyberArk subject matter expertise during solution design, onboarding engagements, operational reviews, and security transformation initiatives.
- Communicate risks, control gaps, recommendations, and progress updates to stakeholders while supporting business objectives, regulatory compliance, and continuous improvement of the identity security landscape.
Experience and Knowledge:
- 5+ years' experience in Privileged Access Management (PAM), Identity & Access Management (IAM), Cyber Security, or related IT security disciplines within enterprise environments.
- Strong hands-on experience administering and supporting CyberArk PAM solutions, including PVWA, CPM, PSM, Safes, Platforms, Secure Cloud Access (SCA), and Endpoint Privilege Manager (EPM).
- Proven experience delivering end-to-end onboarding of applications, infrastructure, cloud platforms, and privileged accounts into CyberArk, including discovery, design, implementation, testing, and operational handover.
- Solid understanding of privileged access management principles, including least privilege, privileged session management, password rotation, credential management, segregation of duties, and Zero Trust security models.
- Experience supporting privileged access governance activities, including access reviews, audit engagements, compliance requirements, risk remediation, and control validation.
- Strong analytical, troubleshooting, and problem-solving skills, with the ability to perform business and technical analysis and resolve complex PAM-related issues.
- Experience working with Microsoft Azure, Entra ID, Active Directory, ServiceNow, cloud platforms, and related identity and security technologies.
- Excellent stakeholder engagement and communication skills, with the ability to collaborate effectively across technical teams, business units, audit, risk, and compliance functions.
- Demonstrated ability to drive automation, process improvement, and operational efficiency initiatives within PAM or broader identity security programmes.
- Self-motivated, proactive, and accountable, with the ability to take ownership of deliverables and manage activities through to successful completion.
Qualifications & Certifications:
- Bachelor's degree in Information Technology, Computer Science, Information Security, or a related discipline, or equivalent industry experience.
- CyberArk Defender Certification (or equivalent CyberArk certification) preferred.
- Industry certifications such as CyberArk Sentry, Microsoft Security, Identity and Access Administrator (SC-300), AZ-500, Security+, or equivalent are advantageous.
- Demonstrated experience working within regulated, audit-driven, or highly controlled environments is highly desirable.
Disclaimer: Unsolicited CVs sent to Apex (Talent Acquisition Team or Hiring Managers) by recruitment agencies will not be accepted for this position. Apex operates a direct sourcing model and where agency assistance is required, the Talent Acquisition team will engage directly with our exclusive recruitment partners.