Work Flexibility: Remote
As a PAM Manager, you will lead Stryker's enterprise Privileged Access Management program, protecting privileged accounts, credentials, secrets, and sessions across on-premises, cloud, and hybrid environments. You will own the PAM strategy and operating model, lead a team of analysts, and partner with Infrastructure, Cloud, Security Operations, Application, and Audit teams to reduce privileged access risk and support regulatory compliance.
What you will do:Technical Responsibilities: • Own the enterprise PAM strategy, roadmap, engineering standards, and operating model aligned with Zero Trust and least-privilege principles.
• Lead the deployment and operation of CyberArk, BeyondTrust, or Delinea across privileged account, credential, secrets, and session-management use cases.
• Manage the privileged account lifecycle, including provisioning, deprovisioning, vaulting, rotation, and check-in/check-out for human and shared privileged accounts.
• Implement privileged session monitoring and recording for high-risk administrative access, just-in-time and time-bound access, and endpoint privilege management to remove local administrator rights and enforce application control.
• Design and govern break-glass access procedures with approval and audit controls, and manage brokered, monitored, and time-limited third-party privileged access.
• Partner with Infrastructure, Cloud, Security Operations, and Application teams to onboard privileged accounts and integrate PAM controls.
• Support SOX, HIPAA, ISO 27001, and NIST Cybersecurity Framework requirements through reporting and audit evidence for privileged access controls.
Leadership & People Management Responsibilities: • Lead PAM analysts by setting priorities, engineering standards, performance expectations, and day-to-day operating practices.
Knowledge and Capabilities: • Assess privileged access risks, resolve complex identity-security issues, and balance competing program priorities.
• Translate PAM risks, control requirements, and implementation decisions into clear guidance for technical teams, business partners, and auditors.
What You Need: Required Qualifications • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, Business Administration or a related discipline
• Minimum 8 years of experience in identity or cybersecurity, including a minimum 4 years of experience focused on privileged access management.
• Hands-on experience deploying and operating CyberArk, BeyondTrust, or Delinea.
• Experience with credential vaulting, privileged session management, just-in-time access, endpoint privilege management, and secrets management.
• Experience securing privileged access across Microsoft Azure, Amazon Web Services, Google Cloud Platform, and on-premises environments.
• People-leadership or team-lead experience managing analysts or engineers.
Preferred Qualifications • Master's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or a related discipline.
• CyberArk Defender or Sentry, CISSP, BeyondTrust, or Delinea certification, or formal training in privileged access management, identity security, or Zero Trust architecture.
United States of America Pay Ranges:- USN: $135,600 - $225,900 USD Annual
- US5: $142,400 - $237,200 USD Annual
- US10: $149,200 - $248,500 USD Annual
- US15: $155,900 - $259,800 USD Annual
- US20: $162,700 - $271,100 USD Annual
- US30: $176,300 - $293,700 USD Annual
View the U.S. work location and transparency guide to find the pay range for your location.
Travel Percentage: None