The Apex Group was established in Bermuda in 2003 and is now one of the world’s largest fund administration and middle office solutions providers.
Our business is unique in its ability to reach globally, service locally and provide cross-jurisdictional services. With our clients at the heart of everything we do, our hard-working team has successfully delivered on an unprecedented growth and transformation journey, and we are now represented by over circa 13,000 employees across 112 offices worldwide.Your career with us should reflect your energy and passion.
That’s why, at Apex Group, we will do more than simply ‘empower’ you. We will work to supercharge your unique skills and experience.
Take the lead and we’ll give you the support you need to be at the top of your game. And we offer you the freedom to be a positive disrupter and turn big ideas into bold, industry-changing realities.
For our business, for clients, and for you
The Role
As a Privileged Access Management Analyst, you will play a critical role in safeguarding Apex's privileged access landscape by owning and delivering end-to-end Privileged Access Management (PAM) services. This includes managing and supporting the CyberArk platform, driving the onboarding of applications, infrastructure, cloud platforms, and privileged accounts, and ensuring privileged access controls remain secure, compliant, and operationally effective.
You will serve as a trusted advisor to Business Units, Application Owners, Infrastructure and Cloud Engineering teams, helping them adopt PAM controls that reduce risk while enabling business operations. Working closely with Security, Risk, Compliance, Audit, and Identity Governance teams, you will ensure privileged access is governed in accordance with regulatory requirements, internal policies, and Zero Trust security principles.
The role requires a combination of technical expertise, operational excellence, stakeholder management, and continuous improvement, contributing to Apex's broader identity security strategy by expanding PAM coverage, improving automation, supporting cloud-native privileged access controls, and enhancing audit readiness across the organisation.
Success in this role is measured by secure and compliant onboarding of privileged accounts, high platform availability, effective risk reduction, successful audit outcomes, strong stakeholder engagement, and continuous improvement of PAM capabilities across the enterprise.
Key duties and responsibilities:
CyberArk Platform Operations & Support
- Administer, maintain, and support the CyberArk PAM platform, including PVWA, CPM, PSM, Safes, Platforms, Secure Cloud Access (SCA), and Endpoint Privilege Manager (EPM), ensuring platform stability, security, and availability.
- Manage day-to-day PAM operations, including service requests, privileged account lifecycle activities, user support, and operational escalations in line with agreed service levels.
- Monitor platform health, password rotation, reconciliation, session activity, system performance, and capacity to proactively identify and resolve issues.
- Troubleshoot incidents and platform failures, perform root cause analysis, and implement corrective actions to improve service reliability and user experience.
- Plan, coordinate, and execute CyberArk upgrades, patching, maintenance activities, and platform enhancements while minimising business disruption.
- Maintain operational procedures, runbooks, knowledge articles, and support documentation, while driving service improvements, operational efficiency, and adherence to support SLAs.
Privileged Access Onboarding, Integration & Automation
- Own and deliver the end-to-end onboarding lifecycle for applications, infrastructure platforms, cloud services, and privileged accounts into CyberArk, including Safe and Platform configuration and enabling applications to leverage Privileged Session Manager (PSM).
- Lead onboarding engagements with application owners and technical teams, from discovery and requirements gathering through implementation, testing, go-live, and operationalisation.
- Analyse privileged account usage, technical dependencies, and business requirements to design and implement CyberArk onboarding solutions for Windows, Linux/Unix, database, cloud, service, and application accounts.
- Configure and support CyberArk Secure Cloud Access (SCA) and Endpoint Privilege Manager (EPM) to secure privileged access across cloud and endpoint environments.
- Configure and validate password rotation, reconciliation, credential retrieval, privileged session management, and application integrations to ensure secure and compliant access controls.
- Drive automation, standardisation, documentation, and continuous improvement initiatives to accelerate onboarding delivery, improve operational efficiency, and expand PAM coverage across the organisation.
Privileged Access Governance, Risk & Compliance
- Administer, maintain, and support the CyberArk PAM platform, including PVWA, CPM, PSM, Safes, Platforms, Secure Cloud Access (SCA), and Endpoint Privilege Manager (EPM), ensuring platform stability, security, and availability.
- Manage day-to-day PAM operations, including service requests, privileged account lifecycle activities, user support, and operational escalations in line with agreed service levels.
- Monitor platform health, password rotation, reconciliation, session activity, system performance, and capacity to proactively identify and resolve issues.
- Troubleshoot incidents and platform failures, perform root cause analysis, and implement corrective actions to improve service reliability and user experience.
- Plan, coordinate, and execute CyberArk upgrades, patching, maintenance activities, and platform enhancements while minimising business disruption.
- Maintain operational procedures, runbooks, knowledge articles, and support documentation, while driving service improvements, operational efficiency, and adherence to support SLAs.
Cloud Security, Identity Governance & Stakeholder Engagement
- Support and enhance privileged access controls across Microsoft Azure, Entra ID, cloud-hosted environments, and CyberArk Secure Cloud Access (SCA) to ensure secure administration of cloud platforms and services.
- Collaborate with Security Engineering, Cloud Engineering, Infrastructure, Application Owners, Risk, Audit, and Service Management teams to deliver secure and compliant privileged access solutions.
- Support the integration of CyberArk with enterprise Identity Governance and Administration (IGA) platforms, including identity correlation, entitlement modelling, provisioning processes, and certification campaigns.
- Contribute to strategic identity security initiatives, cloud access governance programmes, PAM expansion projects, and the adoption of modern privileged access management capabilities.
- Provide technical guidance and CyberArk subject matter expertise during solution design, onboarding engagements, operational reviews, and security transformation initiatives.
- Communicate risks, control gaps, recommendations, and progress updates to stakeholders while supporting business objectives, regulatory compliance, and continuous improvement of the identity security landscape.
Experience and Knowledge:
- 5+ years' experience in Privileged Access Management (PAM), Identity & Access Management (IAM), Cyber Security, or related IT security disciplines within enterprise environments.
- Strong hands-on experience administering and supporting CyberArk PAM solutions, including PVWA, CPM, PSM, Safes, Platforms, Secure Cloud Access (SCA), and Endpoint Privilege Manager (EPM).
- Proven experience delivering end-to-end onboarding of applications, infrastructure, cloud platforms, and privileged accounts into CyberArk, including discovery, design, implementation, testing, and operational handover.
- Solid understanding of privileged access management principles, including least privilege, privileged session management, password rotation, credential management, segregation of duties, and Zero Trust security models.
- Experience supporting privileged access governance activities, including access reviews, audit engagements, compliance requirements, risk remediation, and control validation.
- Strong analytical, troubleshooting, and problem-solving skills, with the ability to perform business and technical analysis and resolve complex PAM-related issues.
- Experience working with Microsoft Azure, Entra ID, Active Directory, ServiceNow, cloud platforms, and related identity and security technologies.
- Excellent stakeholder engagement and communication skills, with the ability to collaborate effectively across technical teams, business units, audit, risk, and compliance functions.
- Demonstrated ability to drive automation, process improvement, and operational efficiency initiatives within PAM or broader identity security programmes.
- Self-motivated, proactive, and accountable, with the ability to take ownership of deliverables and manage activities through to successful completion.
Qualifications & Certifications:
- Bachelor's degree in Information Technology, Computer Science, Information Security, or a related discipline, or equivalent industry experience.
- CyberArk Defender Certification (or equivalent CyberArk certification) preferred.
- Industry certifications such as CyberArk Sentry, Microsoft Security, Identity and Access Administrator (SC-300), AZ-500, Security+, or equivalent are advantageous.
- Demonstrated experience working within regulated, audit-driven, or highly controlled environments is highly desirable.
Disclaimer: Unsolicited CVs sent to Apex (Talent Acquisition Team or Hiring Managers) by recruitment agencies will not be accepted for this position. Apex operates a direct sourcing model and where agency assistance is required, the Talent Acquisition team will engage directly with our exclusive recruitment partners.
Skills Required
- 5+ years experience in Privileged Access Management (PAM), Identity & Access Management (IAM), or IT security in enterprise environments.
- Hands-on administration and support of CyberArk components (PVWA, CPM, PSM, Safes, Platforms, Secure Cloud Access, Endpoint Privilege Manager).
- Proven experience delivering end-to-end onboarding of applications, infrastructure, cloud platforms, and privileged accounts into CyberArk.
- Solid understanding of PAM principles (least privilege, privileged session management, password rotation, credential management, segregation of duties, Zero Trust).
- Experience supporting privileged access governance: access reviews, audits, compliance, risk remediation, and control validation.
- Strong analytical, troubleshooting, and problem-solving skills for complex PAM issues.
- Experience with Microsoft Azure, Entra ID, Active Directory, ServiceNow, and cloud identity/security technologies.
- Bachelor's degree in IT, Computer Science, Information Security, or equivalent industry experience.
- CyberArk Defender (or equivalent CyberArk) certification.
- Industry certifications such as CyberArk Sentry, Microsoft SC-300, AZ-500, Security+, or equivalent.
- Experience working within regulated, audit-driven, or highly controlled environments.
Apex Group Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Apex Group and has not been reviewed or approved by Apex Group.
-
Flexible Benefits — Flexible benefits are positioned as being tailored by country, with localized packages and perks that can differ by jurisdiction. Mobility options such as the JUMP program add a non-cash element that can increase the perceived total rewards value for those who can access it.
-
Wellbeing & Lifestyle Benefits — Wellbeing support is described as including EAPs, mental-health workshops, mentoring support, and local lifestyle perks like gym or cycle-to-work schemes. These offerings broaden the benefits mix beyond purely financial rewards.
-
Retirement Support — Retirement support is described in at least one jurisdiction as including an employer match structure and an additional automatic contribution after tenure. This can strengthen the non-salary portion of total compensation where offered.
Apex Group Insights
What We Do
We are a single-source financial solutions provider dedicated to driving positive change while supporting the growth and ambitions of asset managers, allocators, financial institutions, and family offices around the world. Established in Bermuda in 2003, we have continually disrupted the industry through our investment in innovation and talent. Today, we set the pace in fund and asset servicing and stand out for our unique single-source solution and unified cross asset-class platform which supports the entire value chain, harnesses leading innovative technology, and benefits from cross-jurisdictional expertise delivered by a long-standing management team and over 13,000 highly integrated professionals. As a pioneering data and fintech-enabled company, we are a disruptor driving digital tools into fund and asset servicing. However, our vision to drive positive change extends beyond the industry. The Apex Foundation, a not-for-profit entity, is our passionate commitment to empower sustainable change








