Privileged Access Specialist (Cyberark)
Galderma · Hybrid
Galderma is the emerging pure-play dermatology category leader, present in approximately 90 countries. We deliver an innovative, science-based portfolio of premium flagship brands and services that span the full spectrum of the fast-growing dermatology market through Injectable Aesthetics, Dermatological Skincare and Therapeutic Dermatology. Since our foundation in 1981, we have dedicated our focus and passion to the human body’s largest organ - the skin - meeting individual consumer and patient needs with superior outcomes in partnership with healthcare professionals. Because we understand that the skin, we are in shapes our lives, we are advancing dermatology for every skin story.
We look for people who focus on getting results, embrace learning and bring a positive energy. They must combine initiative with a sense of teamwork and collaboration. Above all, they must be passionate about doing something meaningful for consumers, patients, and the healthcare professionals we serve every day. We aim to empower each employee and promote their personal growth while ensuring business needs are met now and into the future. Across our company, we embrace diversity and respect the dignity, privacy, and personal rights of every employee.
At Galderma, we actively give our teams reasons to believe in our bold ambition to become the leading dermatology company in the world. With us, you have the ultimate opportunity to gain new and challenging work experiences and create an unparalleled, direct impact.
Job Title: Privileged Access Specialist (CyberArk) - JR020283 Location: Krakow/Poland – 3 days on-site Department: IT – Cyber Security
About the role As PAM Engineer, Privileged Access Specialist (CyberArk) you will be responsible for architecting, supporting, and continuously improving Galderma’s Privileged Access Management (PAM) framework. You will serve as the primary technical authority for the CyberArk platform, ensuring privileged credentials and session security are managed robustly across our global IT and OT environments. You will partner with IT, application, audit, and business stakeholders to deliver secure and compliant privileged access controls in a regulated setting.
Main Responsibilities
Administer and operate Galderma’s CyberArk platform, including Vault, CPM, PSM, PVWA, HTML5 Gateway, PTA, PSMP, and Identity/SIA components.
Lead platform lifecycle activities: upgrades, patching, disaster recovery testing, backup and restore, certificate management, and system hardening following industry standards.
Configure and maintain privileged access, policies, including password rotation, reconciliation, session isolation and recording, exclusive access and dual control workflows
Onboard privileged accounts across Windows, Unix/Linux, databases, network devices, cloud environments, SaaS applications, and OT/manufacturing systems
Develop and maintain custom integrations with CPM plugins and PSM connectors for non-standard targets and business-critical platforms
Support privileged session inspection, monitoring, and recording, integrating with SIEM to enhance detection of privileged misuse
Manage secrets and machine identities, including Conjur/Secrets Hub, Credential Providers and API key lifecycles, with a focus on eliminating hard-coded credentials
Contribute to PAM architecture and automation, including onboarding and compliance reporting through REST API, PowerShell and version control best practices
Support audit and compliance requirements by providing evidence and documentation for privileged access controls, access reviews, session coverage, and remediation actions
Maintain operational documentation and support incident response, forensic review and break-glass procedures with the IAM team
Key Requirements
Higher education in Information Technology, Information Security or equivalent experience
Minimum 5 years in privileged access management or IT security, including at least 3 years hands-on with CyberArk PAS/Privilege Cloud in production
Strong practical experience with Vault, CPM, PSM and PVWA administration, privileged account onboarding, and policy configuration
Demonstrated ability to create or maintain custom CPM plugins and PSM connectors for complex environments
Robust knowledge of Windows Server, Active Directory (Kerberos, delegation, GPO tiering), Unix/Linux and networking concepts (TLS, firewalls, load balancing)
Proficiency in PowerShell scripting, REST API integration; Python is an advantage
Experience with secrets management (Conjur, Secrets Hub, CCP/CP, HashiCorp Vault) and integrating with CI/CD or Kubernetes pipelines
Experience in regulated environments (SOX/ITGC; GxP is an advantage) and producing audit evidence/documentation
Exposure to SIA/just-in-time access models, OT/manufacturing environments, or cloud privileged access controls is advantageous.
CyberArk Defender certification required; Sentry preferred
Fluent English
Skills & Competencies
Deep expertise in privileged access management and CyberArk platform engineering
Excellent understanding of privileged account lifecycle, session security, and access governance
Strong analytic and troubleshooting skills for platform and integration issues
Effective communication and stakeholder engagement across technical and business teams
Strong organizational skills to manage platform operations and improvement programs
Continuous improvement mindset with a focus on automation and operational excellence
What we offer in return:
You will be working for an organization that embraces diversity & inclusion and believe we will deliver better outcomes by reflecting the perspectives of our diverse customer base.
You will receive a competitive compensation package with bonus structure and extended benefit package.
You will be able to work in an onsite work culture.
You will participate in feedback loops, during which a personalized career path will be established.
You will be joining a growing company that believes in ownership from day one where everyone is empowered to grow and to take on accountability.
Next Steps:
If your profile is a match, we will invite you for a first virtual conversation with the recruiter.
The next step is a virtual conversation with the hiring manager and the wider team.
The final step is an in-person interview with the local HRBP
Our people make a difference
At Galderma, you’ll work with people who are like you. And people that are different. We value what every member of our team brings. Professionalism, collaboration, and a friendly, supportive ethos is the perfect environment for people to thrive and excel in what they do.
#LI-Hybrid
.