Solution Lead, Privileged Access Management (PAM)

McKesson Medical-Surgical Inc.Irving, Alpharetta, Texas, GeorgiaOn-siteFull-timePrincipal, 12–15+ yearsListed 53 minutes ago

Apply now

About this role

McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve – we care.

What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow’s health today, we want to hear from you.

McKesson is seeking a Solution Lead, PAM to help advance and scale enterprise privileged access management capabilities. This role will serve as the technical lead for the PAM service area, responsible for shaping PAM strategy, owning solution architecture and design patterns, identifying capability gaps, and helping drive practical solutions that protect privileged accounts, credentials, secrets, machine identities, and cloud privileges across hybrid environments.

The Solution Lead will partner closely with security architects, engineers, application teams, and business stakeholders to ensure PAM capabilities are secure, scalable, automated, supportable, and aligned to enterprise architecture, service priorities, and risk reduction objectives.

What You'll Do :

- Lead the design, implementation, and continuous improvement of enterprise PAM capabilities across cloud and on-premises environments.

- Help shape and evolve the PAM roadmap by identifying capability gaps, prioritizing initiatives, and driving strategic security outcomes.

- Partner with application teams and business stakeholders to understand requirements, shape practical and supportable PAM solutions, and ensure outcomes are delivered.

- Own solution architecture and lead implementation of controls for privileged accounts, credential vaulting, secrets management, session monitoring, service accounts, and machine identities.

- Serve as an escalation point for PAM operational issues and incidents, helping assess impact, guide resolution, and identify follow-up actions to reduce recurrence.

- Develop standards, automation, and operational processes that improve PAM adoption, supportability, scalability, and alignment with Zero Trust principles.

- Evaluate emerging technologies, industry trends, and threats related to privileged access, secrets management, cloud privilege management, and privileged identity security.

- Provide technical leadership, mentoring, and guidance across cybersecurity engineering initiatives.

Basic Requirements :

- Degree or equivalent and typically requires 10+ years of relevant experience. Less years required if has relevant Master’s degree etc.
- 8+ years of experience in cybersecurity, PAM, IAM security, or security engineering roles.

- Hands-on experience with enterprise Privileged Access Management platforms.

- Strong knowledge of privileged accounts and identities, credential management, session management, secrets management, service accounts, machine identities, and cloud privilege management.

- Experience leading security initiatives from requirements through solution design, implementation, and operationalization.

- Experience supporting operational escalations, incident management, or production issues for security platforms or services.

- Experience partnering with application teams, architects, engineers, and cross-functional stakeholders to shape and deliver practical security solutions.

- Ability to identify capability gaps, contribute to roadmap planning, prioritize work, and drive continuous improvement initiatives.

- Strong written and verbal communication skills with the ability to influence technical and business stakeholders.

Preferred Skills/Experience :

- Experience with CyberArk strongly preferred; experience with similar enterprise PAM technologies such as Delinea, BeyondTrust, or HashiCorp Vault also considered.

- Experience leading large-scale PAM, IAM security, or privileged identity security transformations.

- Experience securing cloud environments such as Azure, AWS, or GCP.

- Knowledge of Privileged Identity Management (PIM), Zero Trust principles, and adjacent IAM capabilities such as Identity Governance and Administration (IGA).

- Experience with DevSecOps, CI/CD security controls, and infrastructure automation.

- Experience with PAM, secrets, or access control patterns for APIs, containers, Kubernetes, or cloud-native platforms.

- Knowledge of regulatory and compliance frameworks in healthcare or other regulated industries.

- Relevant certifications such as CISSP, CyberArk certifications, or equivalent.

We are proud to offer a competitive compensation package at McKesson as part of our Total Rewards. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered. For more information regarding benefits at McKesson, please  click here.

Our Base Pay Range for this position

$140,700 - $234,500

McKesson has become aware of online recruiting-related scams in which individuals who are not affiliated with or authorized by McKesson are using McKesson’s (or affiliated entities, like CoverMyMeds or RxCrossroads) name in fraudulent emails, job postings or social media messages. In light of these scams, please bear the following in mind:

McKesson Talent Advisors will never solicit money or credit card information in connection with a McKesson job application.

McKesson Talent Advisors do not communicate with candidates via online chatrooms or using email accounts such as Gmail or Hotmail. Note that McKesson does rely on a virtual assistant (Gia) for certain recruiting-related communications with candidates.

McKesson job postings are posted on our career site: careers.mckesson.com .

McKesson is an Equal Opportunity Employer

McKesson provides equal employment opportunities to applicants and employees, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, age, genetic information, or any other legally protected category. For additional information on McKesson’s full Equal Employment Opportunity policies, visit our Equal Employment Opportunity page.

McKesson is committed to being an Equal Employment Opportunity Employer and offers opportunities to all job seekers including job seekers with disabilities. If you need a reasonable accommodation to assist with your job search or application for employment, please contact us by sending an email to (United States) [email protected] or (Canada) [email protected] . Resumes or CVs submitted to this email box will not be accepted.

Join us at McKesson!