Job DescriptionNavy Federal Credit Union currently does not provide sponsorship for this role. Applicants must be authorized to work in the United States without the need for current or future sponsorship.Seeking an experienced and strategic Manager II, Identity Access Management (PAM) to lead the day-to-day operations, engineering execution, and strategic direction of the enterprise PAM program at NFCU. This leader will oversee a high-performing team of PAM engineers and analysts responsible for securing privileged identities, accounts, credentials, and access across on-premises, cloud, and hybrid environments.
The ideal candidate combines strong technical expertise with exceptional leadership and program management skills. This individual will partner with Information Security, Infrastructure, Application Development, Risk, Audit, Compliance, and executive leadership to mature the organization's privileged access capabilities while ensuring regulatory compliance and operational excellence.
ResponsibilitiesLeadership & People Management
- Lead, mentor, and develop a team of PAM engineers and analysts, fostering a culture of accountability, innovation, and continuous improvement.
- Manage day-to-day operations, workload prioritization, resource planning, and performance management.
- Remove technical roadblocks and provide guidance on complex engineering challenges and production issues.
- Promote operational excellence through coaching, knowledge sharing, and process improvements.
PAM Strategy & Roadmap
- Define, communicate, and execute the enterprise Privileged Access Management strategy aligned with cybersecurity and business objectives.
- Own the multi-year PAM roadmap, balancing operational stability, security enhancements, technical debt reduction, and modernization initiatives.
- Evaluate emerging PAM technologies and industry best practices to continuously improve the program.
- Drive adoption of modern privileged access capabilities including Just-in-Time (JIT) access, Zero Standing Privileges (ZSP), credential rotation, session monitoring, secrets management, and cloud privileged access.
Program & Project Leadership
- Lead multiple concurrent PAM initiatives from planning through implementation.
- Establish project priorities, timelines, risks, and dependencies while ensuring successful delivery.
- Partner with cross-functional technology teams to integrate PAM capabilities into enterprise platforms and applications.
- Provide regular status updates and executive-level reporting on program health, milestones, risks, and key metrics.
Operations & Engineering
- Oversee daily operational support of the enterprise PAM platform, ensuring high availability, reliability, and performance.
- Drive incident resolution, root cause analysis, and continuous service improvement.
- Ensure operational procedures, monitoring, maintenance, upgrades, disaster recovery, and lifecycle management are effectively executed.
- Collaborate with engineering teams to automate privileged account onboarding, credential management, and policy enforcement.
Governance, Risk & Compliance
- Partner with Internal Audit, External Audit, Risk Management, and Regulatory Compliance teams to support examinations and assessments.
- Ensure PAM controls align with regulatory requirements and industry frameworks, and other applicable financial industry standards.
- Develop remediation plans for audit findings and drive timely closure of identified risks.
- Maintain policies, standards, procedures, and technical documentation supporting the PAM program.
Stakeholder & Executive Engagement
- Build strong partnerships across Information Security, Infrastructure, Identity & Access Management, Cloud Engineering, DevOps, Architecture, and Application Development teams.
- Present program updates, strategic initiatives, operational metrics, and risk posture to senior leadership and executive stakeholders.
- Influence enterprise security decisions through data-driven recommendations and business-focused communication.
- Serve as the primary escalation point for complex privileged access issues.
Continuous Improvement
- Establish KPIs and operational metrics to measure program effectiveness.
- Drive automation and process optimization to improve operational efficiency.
- Champion continuous improvement initiatives that strengthen the organization's privileged access maturity.
Qualifications- Bachelor's degree in Computer Science, Information Security, Information Technology, or related field, or equivalent experience.
- 7+ years of cybersecurity or identity and access management experience.
- 3+ years of people leadership experience managing technical engineering teams, or equivalent experience as the subject matter lead or expert in area of expertise.
- Deep understanding of Privileged Access Management principles, privileged identity governance, and credential security.
- Experience managing enterprise PAM platforms such as CyberArk, Delinea, BeyondTrust, or similar solutions.
- Experience leading enterprise technology implementations and security transformation initiatives.
- Strong understanding of Windows, Linux, Active Directory, Entra ID, cloud platforms, service accounts, APIs, and infrastructure security.
- Experience working within highly regulated environments, preferably financial services.
- Excellent communication and executive presentation skills.
- Demonstrated ability to influence stakeholders across all organizational levels.
Desired Qualifications- Experience implementing cloud-native PAM and secrets management solutions.
- Knowledge of Zero Trust architecture and Just-in-Time privilege models.
- Experience securing machine identities, service accounts, and non-human identities.
- Familiarity with DevSecOps, Infrastructure as Code, and automation frameworks.
- Professional certifications such as CISSP, CISM, Security+, CyberArk Defender/Sentry, Azure Security Engineer, or equivalent.
Additional InformationHours:- Monday - Friday, 8:00AM - 4:30PM ET
Location: