Cyber Security Privileged Access Management (pam) Analyst

Bank of America Bank of America · Banking · Boston, MA +1

Cyber Security Analyst focused on Privileged Access Management (PAM) within a financial institution, ensuring compliance with IAM standards, partnering with governance leads, documenting requirements, and collaborating with technology partners for PAM modernization. Requires deep experience in PAM, IAM platforms, and security knowledge, with familiarity with financial sector regulations and security standards.

What you'd actually do

  1. This role is primarily responsible for ensuring that relevant Privileged Access Controls are adequately enforced across platforms and applications to comply with IAM Standard.
  2. Partner with PAM Governance leads to ensure that Privileged Access Controls are appropriately measured, reported and governed.
  3. Apply industry PAM best practices, templates, and documentation while also proposing improvements based on practical knowledge.
  4. Document and convey PAM related requirements to technology partners to build/implement enhanced PAM solutions that are efficient, effective, and modern and able to result in material risk reduction in sustainable manner.
  5. Collaborate with stakeholders to develop PAM requirements that iteratively support long term PAM modernization and transformation (covers Process, Data and Technology aspects).

Skills

Required

  • PAM
  • Identity and Access Management (IAM)
  • Linux
  • Windows
  • Cloud
  • Single Sign-On
  • Multi Factor Authentication
  • Authorization services
  • PAM services design and architecture
  • Ping Identity
  • Active Directory
  • OpenLDAP
  • OpenDJ
  • Web Service APIs
  • JSON
  • XML
  • Large and complex projects
  • On-prem and Cloud PAM implementation
  • Authentication platforms
  • Kerberos
  • Radius
  • PAM related tools (session proxy, vaulting, just-in-time provision, integration with service management tool)
  • Core technology infrastructure security (network, storage, servers, databases)
  • Application security practice
  • Federation platforms
  • Federation protocols (Oauth, OpenID, SAML, WS-Fed)
  • PAM-specific laws, rules, and regulations (financial services sector)
  • Microsoft Office suite
  • NIST
  • ISO/EC
  • FFIEC
  • Information Security Policy, Standards, Procedure and Guides
  • CISSP certification
  • SOX
  • SOC
  • SOC2
  • Articulating facts and data-driven plans
  • Attention to detail
  • Advanced analytical skills
  • Communication skills
  • Presentation skills
  • Prioritizing multiple tasks

Nice to have

  • CISSP certification
  • Knowledge of Compliance Certifications such as SOX, SOC, SOC2.

What the JD emphasized

  • 7 years relevant hands-on experience in PAM in complex and heterogenous technology environment.
  • Deep experience with Linux, Windows, Cloud scale Identity, Access Management (Single Sign-On, Multi Factor Authentication), Authorization services or design and architecture of PAM services
  • Deep knowledge of bank financial practices and policies and ability to adapt to fast changing environment
  • Expert level knowledge of privileged access management methodologies and techniques for on-prem and Cloud implementation.
  • Deep security knowledge which covers core technology infrastructure (network, storage, servers, databases, etc.) identity management and application security practice.
  • Good knowledge and understanding of PAM-specific laws, rules, and regulations within the financial services sector.
  • Knowledge of Compliance Certifications such as SOX, SOC, SOC2.