Full Job Description
McKesson is seeking a Solution Lead, PAM to help advance and scale enterprise privileged access management capabilities. This role will serve as the technical lead for the PAM service area, responsible for shaping PAM strategy, owning solution architecture and design patterns, identifying capability gaps, and helping drive practical solutions that protect privileged accounts, credentials, secrets, machine identities, and cloud privileges across hybrid environments.
The Solution Lead will partner closely with security architects, engineers, application teams, and business stakeholders to ensure PAM capabilities are secure, scalable, automated, supportable, and aligned to enterprise architecture, service priorities, and risk reduction objectives.
What You'll Do:
• Lead the design, implementation, and continuous improvement of enterprise PAM capabilities across cloud and on-premises environments.
• Help shape and evolve the PAM roadmap by identifying capability gaps, prioritizing initiatives, and driving strategic security outcomes.
• Partner with application teams and business stakeholders to understand requirements, shape practical and supportable PAM solutions, and ensure outcomes are delivered.
• Own solution architecture and lead implementation of controls for privileged accounts, credential vaulting, secrets management, session monitoring, service accounts, and machine identities.
• Serve as an escalation point for PAM operational issues and incidents, helping assess impact, guide resolution, and identify follow-up actions to reduce recurrence.
• Develop standards, automation, and operational processes that improve PAM adoption, supportability, scalability, and alignment with Zero Trust principles.
• Evaluate emerging technologies, industry trends, and threats related to privileged access, secrets management, cloud privilege management, and privileged identity security.
• Provide technical leadership, mentoring, and guidance across cybersecurity engineering initiatives.
Basic Requirements:
• Degree or equivalent and typically requires 10+ years of relevant experience. Less years required if has relevant Master's degree etc.
• 8+ years of experience in cybersecurity, PAM, IAM security, or security engineering roles.
• Hands-on experience with enterprise Privileged Access Management platforms.
• Strong knowledge of privileged accounts and identities, credential management, session management, secrets management, service accounts, machine identities, and cloud privilege management.
• Experience leading security initiatives from requirements through solution design, implementation, and operationalization.
• Experience supporting operational escalations, incident management, or production issues for security platforms or services.
• Experience partnering with application teams, architects, engineers, and cross-functional stakeholders to shape and deliver practical security solutions.
• Ability to identify capability gaps, contribute to roadmap planning, prioritize work, and drive continuous improvement initiatives.
• Strong written and verbal communication skills with the ability to influence technical and business stakeholders.
Preferred Skills/Experience:
• Experience with CyberArk strongly preferred; experience with similar enterprise PAM technologies such as Delinea, BeyondTrust, or HashiCorp Vault also considered.
• Experience leading large-scale PAM, IAM security, or privileged identity security transformations.
• Experience securing cloud environments such as Azure, AWS, or GCP.
• Knowledge of Privileged Identity Management (PIM), Zero Trust principles, and adjacent IAM capabilities such as Identity Governance and Administration (IGA).
• Experience with DevSecOps, CI/CD security controls, and infrastructure automation.
• Experience with PAM, secrets, or access control patterns for APIs, containers, Kubernetes, or cloud-native platforms.
• Knowledge of regulatory and compliance frameworks in healthcare or other regulated industries.
• Relevant certifications such as CISSP, CyberArk certifications, or equivalent.
We are proud to offer a competitive compensation package at McKesson as part of our Total Rewards. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered. For more information regarding benefits at McKesson, please click here.
Our Base Pay Range for this position
$140,700 - $234,500