Privileged Access Management (pam) Analyst

Bank of America Bank of America · Banking · Boston, MA +1

This role focuses on ensuring Privileged Access Controls are enforced across platforms and applications to comply with IAM standards within a financial institution. It involves partnering with governance leads, applying PAM best practices, documenting requirements for technology partners, and collaborating with stakeholders on PAM modernization. The role requires deep experience in PAM, IAM platforms, and security knowledge, with a focus on compliance and risk reduction in a complex technology environment.

What you'd actually do

  1. Ensuring that relevant Privileged Access Controls are adequately enforced across platforms and applications to comply with IAM Standard.
  2. Partner with PAM Governance leads to ensure that Privileged Access Controls are appropriately measured, reported and governed.
  3. Apply industry PAM best practices, templates, and documentation while also proposing improvements based on practical knowledge.
  4. Document and convey PAM related requirements to technology partners to build/implement enhanced PAM solutions that are efficient, effective, and modern and able to result in material risk reduction in sustainable manner.
  5. Collaborate with stakeholders to develop PAM requirements that iteratively support long term PAM modernization and transformation (covers Process, Data and Technology aspects).

Skills

Required

  • 3+ years relevant hands-on experience in PAM in complex and heterogenous technology environment
  • Deep experience with Linux, Windows, Cloud scale Identity, Access Management (Single Sign-On, Multi Factor Authentication), Authorization services or design and architecture of PAM services
  • Deep knowledge of bank financial practices and policies and ability to adapt to fast changing environment
  • Working level experience with IAM platforms such as Ping Identity, Active Directory OpenLDAP, OpenDJ
  • Experience in consumption of Web Service APIs such as JSON / XML
  • Hands on experience and involvement in large and complex projects
  • Expert level knowledge of privileged access management methodologies and techniques for on-prem and Cloud implementation
  • Expert level knowledge of authentication platforms such as Active Directory, LDAP, Kerberos, LDAP, Radius
  • Deep security knowledge which covers core technology infrastructure (network, storage, servers, databases, etc.) identity management and application security practice
  • Deep knowledge on Federation platforms or protocols such as Oauth, OpenID, SAML, WS-Fed, etc.
  • Proficient in Microsoft Office suite of products with ability to quickly analyze and synthesize large volumes of data
  • Familiarity with security standards such as NIST, ISO/EC, FFIEC

Nice to have

  • Expert knowledge of PAM related tools which support session proxy, vaulting, just-in-time provision, integration with service management tool would be an advantage
  • Good knowledge and understanding of PAM-specific laws, rules, and regulations within the financial services sector

What the JD emphasized

  • 3+ years relevant hands-on experience in PAM in complex and heterogenous technology environment
  • Deep knowledge of bank financial practices and policies
  • Good knowledge and understanding of PAM-specific laws, rules, and regulations within the financial services sector