Solution Lead, Privileged Access Management (PAM)

McKesson

Irving (TX)

On-site

USD 141,000 - 235,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Competitive compensation

Job summary

McKesson seeks a Solution Lead, PAM to advance and scale enterprise privileged access management across hybrid environments. You will own solution architecture, drive PAM strategy, and partner with security and engineering teams to deliver secure, automated controls for privileged accounts, credentials, and secrets.

The role requires deep PAM expertise, 10+ years of cybersecurity experience, and strong collaboration skills to align with enterprise architecture and risk reduction goals in a large

Qualifications

  • Degree or equivalent and typically 10+ years of relevant experience.
  • 8+ years in cybersecurity, PAM, IAM security, or security engineering.
  • Hands-on experience with enterprise PAM platforms.
  • Experience leading security initiatives from requirements to implementation.
  • Strong communication skills with stakeholders across teams.

Responsibilities

  • Design, implement, and improve enterprise PAM across cloud and on‑prem environments.
  • Shape PAM roadmap by identifying gaps and prioritizing initiatives.
  • Collaborate with application teams and business stakeholders to deliver practical PAM solutions.
  • Own solution architecture and implement controls for privileged accounts, vaulting, secrets, and machine identities.
  • Escalate and guide resolution for PAM incidents to reduce recurrence.
  • Develop standards and automation to improve PAM adoption and scalability.
  • Evaluate emerging PAM technologies and trends to strengthen security postures.

Skills

PAM expertise
Cloud IAM
Zero Trust
Security architecture
Incident management
Stakeholder communication
Automation

Education

Bachelor’s degree or higher

Tools

CyberArk
Delinea
HashiCorp Vault

Job description

McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve – we care.

What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow’s health today, we want to hear from you.

McKesson is seeking a Solution Lead, PAM to help advance and scale enterprise privileged access management capabilities. This role will serve as the technical lead for the PAM service area, responsible for shaping PAM strategy, owning solution architecture and design patterns, identifying capability gaps, and helping drive practical solutions that protect privileged accounts, credentials, secrets, machine identities, and cloud privileges across hybrid environments.

The Solution Lead will partner closely with security architects, engineers, application teams, and business stakeholders to ensure PAM capabilities are secure, scalable, automated, supportable, and aligned to enterprise architecture, service priorities, and risk reduction objectives.

What You'll Do
  • Lead the design, implementation, and continuous improvement of enterprise PAM capabilities across cloud and on-premises environments.
  • Help shape and evolve the PAM roadmap by identifying capability gaps, prioritizing initiatives, and driving strategic security outcomes.
  • Partner with application teams and business stakeholders to understand requirements, shape practical and supportable PAM solutions, and ensure outcomes are delivered.
  • Own solution architecture and lead implementation of controls for privileged accounts, credential vaulting, secrets management, session monitoring, service accounts, and machine identities.
  • Serve as an escalation point for PAM operational issues and incidents, helping assess impact, guide resolution, and identify follow-up actions to reduce recurrence.
  • Develop standards, automation, and operational processes that improve PAM adoption, supportability, scalability, and alignment with Zero Trust principles.
  • Evaluate emerging technologies, industry trends, and threats related to privileged access, secrets management, cloud privilege management, and privileged identity security.
  • Provide technical leadership, mentoring, and guidance across cybersecurity engineering initiatives.
Basic Requirements
  • Degree or equivalent and typically requires 10+ years of relevant experience. Less years required if has relevant Master’s degree etc.
  • 8+ years of experience in cybersecurity, PAM, IAM security, or security engineering roles.
  • Hands‑on experience with enterprise Privileged Access Management platforms.
  • Strong knowledge of privileged accounts and identities, credential management, session management, secrets management, service accounts, machine identities, and cloud privilege management.
  • Experience leading security initiatives from requirements through solution design, implementation, and operationalization.
  • Experience supporting operational escalations, incident management, or production issues for security platforms or services.
  • Experience partnering with application teams, architects, engineers, and cross‑functional stakeholders to shape and deliver practical security solutions.
  • Ability to identify capability gaps, contribute to roadmap planning, prioritize work, and drive continuous improvement initiatives.
  • Strong written and verbal communication skills with the ability to influence technical and business stakeholders.
Preferred Skills/Experience
  • Experience with CyberArk strongly preferred; experience with similar enterprise PAM technologies such as Delinea, BeyondTrust, or HashiCorp Vault also considered.
  • Experience leading large-scale PAM, IAM security, or privileged identity security transformations.
  • Experience securing cloud environments such as Azure, AWS, or GCP.
  • Knowledge of Privileged Identity Management (PIM), Zero Trust principles, and adjacent IAM capabilities such as Identity Governance and Administration (IGA).
  • Experience with DevSecOps, CI/CD security controls, and infrastructure automation.
  • Experience with PAM, secrets, or access control patterns for APIs, containers, Kubernetes, or cloud-native platforms.
  • Knowledge of regulatory and compliance frameworks in healthcare or other regulated industries.
  • Relevant certifications such as CISSP, CyberArk certifications, or equivalent.

We are proud to offer a competitive compensation package at McKesson as part of our Total Rewards. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered. For more information regarding benefits at McKesson, please click here.

Our Base Pay Range for this position

$140,700 - $234,500

McKesson is an Equal Opportunity Employer

McKesson provides equal employment opportunities to applicants and employees, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, age, genetic information, or any other legally protected category. For additional information on McKesson’s full Equal Employment Opportunity policies, visit our Equal Employment Opportunity page.

McKesson is committed to being an Equal Employment Opportunity Employer and offers opportunities to all job seekers including job seekers with disabilities. If you need a reasonable accommodation to assist with your job search or application for employment, please contact us by sending an email to (United States) Disability_Accommodation@McKesson.com or (Canada) Accessibility@mckesson.ca. Resumes or CVs submitted to this email box will not be accepted.

Join us at McKesson!
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Manager, Network Security Engineering
Senior Manager, Network Security Engineering

McKesson • Irving (TX)

On-site
USD 137,000 - 228,000
Sr Product Security Engineer, AI & DevSecOps
Sr Product Security Engineer, AI & DevSecOps

Rx Savings Solutions • Columbus (OH)

On-site
USD 140,000 - 234,000
Lead Cyber Security Architect
Lead Cyber Security Architect

RXinsider LTD. • Richmond (VA)

On-site
USD 143,000 - 238,000
Senior Manager, Network Security Engineering
Senior Manager, Network Security Engineering

McKesson’s Corporate • Irving (TX)

On-site
USD 137,000 - 228,000
Software Engineer - Identity & Access Management
Software Engineer - Identity & Access Management

McKesson Corporation • United States

On-site
USD 100,000 - 167,000
Senior Information Security Analyst
Senior Information Security Analyst

McKesson • Irving (TX)

Remote
USD 170,000 - 179,000
Director, Infrastructure & Cloud Engineering
Director, Infrastructure & Cloud Engineering

McKesson • Irving (TX)

Hybrid
USD 148,000 - 247,000
Competitive compensation
Total rewards program
Director, Infrastructure & Cloud Engineering
Director, Infrastructure & Cloud Engineering

McKesson • Richmond (VA)

On-site
USD 148,000 - 247,000
Sr Product Security Engineer, AI & DevSecOps
Sr Product Security Engineer, AI & DevSecOps

McKesson • Columbus (OH)

On-site
USD 140,000 - 234,000
Director, Infrastructure & Cloud Engineering
Director, Infrastructure & Cloud Engineering

McKesson Corporation • Richmond (VA)

Hybrid
USD 148,000 - 247,000