Identity and Access Management Senior Consultant

Bank of America Bank of America · Banking · Boston, MA +1

This role focuses on Identity and Access Management (IAM) within Global Information Security at Bank of America. The Senior IAM Information Security Controls Lead will analyze, strengthen, and secure the company's IAM systems and risk posture. Responsibilities include defining IAM standards, driving application/platform IAM modernization, collaborating with cybersecurity and compliance teams, and managing documentation and governance routines. The role requires extensive experience in IAM, knowledge of various authentication protocols and cloud platforms, and familiarity with security frameworks and data analytics tools.

What you'd actually do

  1. Define and steer IAM standards including designing enterprise appropriate adherence models, and related measures for governance, controls and effectiveness management.
  2. Drive application/platform IAM modernization approach and program for information & data synchronization/management, moving from legacy manual to modernized identity automation solutions, such as connector frameworks.
  3. Collaborate with partner cybersecurity, engineering, and compliance teams to develop and align controls with industry standards, to mitigate known threat vectors, adopt best practice principles and meet regulatory requirements.
  4. Drive optimization & adoption of innovative and transformational strategies including but not limited to tooling integrations with enterprise platforms such as Active Directory, Mainframe and Public Cloud.
  5. Drive requirements, modernization and derisk efforts for processes, controls, systems and platforms, reducing technical debt, improving identity hygiene and supporting continual risk reduction efforts.

Skills

Required

  • 10+ years of bank and finance industry hands-on experience in Identity Governance & Administration (IGA) or Identity and Access Management (IAM), managing identity lifecycle and enterprise-scale modernization initiatives.
  • High proficiency and working knowledge of Active Directory, Entra ID (Azure AD), and federated authentication protocols (SAML, OIDC, OAuth2).
  • Proven experience IAM functionality and tools for Azure, AWS, and Google Cloud and with platforms such as PingIDM, SailPoint, Saviynt, IdentityIQ (IIQ), ForgeRock, Okta, or Oracle IDCS.
  • Expertise in connector frameworks (e.g., OpenICF), identity workflows, role management, and policy development.
  • Familiarity with common Information Security and data protection frameworks and standards (i.e., CIS, NIST, MITRE, ITIL, COBIT, HIPAA, GDPR, PCI DSSS, ISO 270001)
  • Familiarity with Zero Trust architecture, FIDO2, and passwordless authentication concepts.
  • Proficiency in data analytics and reporting tools (SQL, Tableau, PowerBI) for compliance and risk metrics.

What the JD emphasized

  • regulatory requirements
  • compliance requirements
  • industry standards