Galderma
Privileged Access Specialist (Cyberark)
Krakow
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Mid level
- Country
- PL
- Work mode
- On-site / unstated
- First seen by hirly
- 27 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Whether it's the unique breadth of our integrated offering that covers Injectable Aesthetics, Dermatological Skincare and Therapeutic Dermatology products; or our commitment to recognizing and rewarding people for the contribution they make - working here isn't like anywhere else.
At Galderma, we actively give our teams reasons to believe in our ambition to become the leading dermatology company in the world. With us, you have the ultimate opportunity to gain new and challenging work experiences and create an unparalleled, direct impact.
- Job Title: Privileged Access Specialist (CyberArk) - JR020283
- Location: Krakow/Poland – 3 days on-site
- Department: IT – Cyber Security
- About the role
- As PAM Engineer, Privileged Access Specialist (CyberArk) you will be responsible for architecting, supporting, and continuously improving Galderma’s Privileged Access Management (PAM) framework. You will serve as the primary technical authority for the CyberArk platform, ensuring privileged credentials and session security are managed robustly across our global IT and OT environments. You will partner with IT, application, audit, and business stakeholders to deliver secure and compliant privileged access controls in a regulated setting.
Main Responsibilities
- Administer and operate Galderma’s CyberArk platform, including Vault, CPM, PSM, PVWA, HTML5 Gateway, PTA, PSMP, and Identity/SIA components.
- Lead platform lifecycle activities: upgrades, patching, disaster recovery testing, backup and restore, certificate management, and system hardening following industry standards.
- Configure and maintain privileged access, policies, including password rotation, reconciliation, session isolation and recording, exclusive access and dual control workflows
- Onboard privileged accounts across Windows, Unix/Linux, databases, network devices, cloud environments, SaaS applications, and OT/manufacturing systems
- Develop and maintain custom integrations with CPM plugins and PSM connectors for non-standard targets and business-critical platforms
- Support privileged session inspection, monitoring, and recording, integrating with SIEM to enhance detection of privileged misuse
- Manage secrets and machine identities, including Conjur/Secrets Hub, Credential Providers and API key lifecycles, with a focus on eliminating hard-coded credentials
- Contribute to PAM architecture and automation, including onboarding and compliance reporting through REST API, PowerShell and version control best practices
- Support audit and compliance requirements by providing evidence and documentation for privileged access controls, access reviews, session coverage, and remediation actions
- Maintain operational documentation and support incident response, forensic review and break-glass procedures with the IAM team
Key Requirements
- Higher education in Information Technology, Information Security or equivalent experience
- Minimum 5 years in privileged access management or IT security, including at least 3 years hands-on with CyberArk PAS/Privilege Cloud in production
- Strong practical experience with Vault, CPM, PSM and PVWA administration, privileged account onboarding, and policy configuration
- Demonstrated ability to create or maintain custom CPM plugins and PSM connectors for complex environments
- Robust knowledge of Windows Server, Active Directory (Kerberos, delegation, GPO tiering), Unix/Linux and networking concepts (TLS, firewalls, load balancing)
- Proficiency in PowerShell scripting, REST API integration; Python is an advantage
- Experience with secrets management (Conjur, Secrets Hub, CCP/CP, HashiCorp Vault) and integrating with CI/CD or Kubernetes pipelines
- Experience in regulated environments (SOX/ITGC; GxP is an advantage) and producing audit evidence/documentation
- Exposure to SIA/just-in-time access models, OT/manufacturing environments, or cloud privileged access controls is advantageous.
- CyberArk Defender certification required; Sentry preferred
- Fluent English
Skills & Competencies
- Deep expertise in privileged access management and CyberArk platform engineering
- Excellent understanding of privileged account lifecycle, session security, and access governance
- Strong analytic and troubleshooting skills for platform and integration issues
- Effective communication and stakeholder engagement across technical and business teams
- Strong organizational skills to manage platform operations and improvement programs
- Continuous improvement mindset with a focus on automation and operational excellence
What we offer in return:
- You will be working for an organization that embraces diversity & inclusion and believe we will deliver better outcomes by reflecting the perspectives of our diverse customer base.
- You will receive a competitive compensation package with bonus structure and extended benefit package.
- You will be able to work in an onsite work culture.
- You will participate in feedback loops, during which a personalized career path will be established.
- You will be joining a growing company that believes in ownership from day one where everyone is empowered to grow and to take on accountability.
Next Steps:
- If your profile is a match, we will invite you for a first virtual conversation with the recruiter.
- The next step is a virtual conversation with the hiring manager and the wider team.
- The final step is an in-person interview with the local HRBP
Our people make a difference
At Galderma, you’ll work with people who are like you. And people that are different. We value what every member of our team brings. Professionalism, collaboration, and a friendly, supportive ethos is the perfect environment for people to thrive and excel in what they do.
#LI-Hybrid
.
Similar jobs
- Patient Access Specialist - Radiation OncologyInova Military · Alexandria, VA, United StatesFirst seen today
- Patient Access Specialist - Behavioral Health Call CenterInova Military · VA, United StatesFirst seen today
- Patient Access Specialist IWellstar · Kennestone HospitalFirst seen today
- Patient Logistics Access Specialist - Davenport, Des Moines, Mason CityTrinityhealth · 2 LocationsFirst seen today
- Patient Access Specialist - Medical ImagingLuriechildrens · Streeterville, Chicago, ILFirst seen today
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job