Privileged Access Management (pam) Sr. Analyst

Bank of America Bank of America · Banking · Boston, MA +1

This role focuses on Privileged Access Management (PAM) within a financial institution, ensuring security controls are enforced across platforms and applications to comply with Information Security and IAM standards. It involves partnering with various security and compliance functions, influencing technology owners to implement enhanced PAM solutions, developing PAM requirements, and managing PAM risks. The role requires extensive knowledge of PAM, Active Directory security, and relevant financial services regulations and security standards.

What you'd actually do

  1. This role reports directly to the Technology Executive for Authentication, Privilege Access Management Service and Cloud IAM. This role is primarily responsible for ensuring that relevant Privileged Access Controls are adequately enforced across platforms and applications to comply with IAM Standard.
  2. Partner with PAM Governance leads to ensure that Privileged Access Controls are appropriately measured, reported and governed.
  3. Appropriately assess Privileged Access risk when business and technology decisions are made, demonstrating risk management mindset and practices to safeguard BAC’s reputation, its clients, and assets by driving compliance with applicable laws, rules, and regulations, adhering to BAC Policy and Standards.
  4. Monitors industry information security and PAM trends and engages peer organizations to refine and enhance BAC’s PAM strategy.
  5. Apply industry PAM best practices, templates, and documentation while also proposing improvements based on practical knowledge.

Skills

Required

  • Privileged Access Management (PAM)
  • Information Security
  • IAM Standards
  • Risk Management
  • Compliance
  • Active Directory Security
  • NIST
  • ISO/IEC
  • FFIEC
  • Financial Services Regulations
  • Cloud Security
  • Policy and Standards Interpretation

Nice to have

  • CISSP certification

What the JD emphasized

  • 10 years relevant hands-on experience in PAM with at least of 5 years of management experience
  • Extensive knowledge and understanding of PAM-specific laws, rules, and regulations within the financial services sector.
  • Understanding and interpreting BAC’s established information security Policy, Standards, Procedure and Guides, and applying this knowledge to related PAM decisions and response. Serve as the Subject Matter Experts in advising BAC business and technology counterparts on effective ways to achieve or exceed compliance with applicable Policy, Standards, Procedures and Guides
  • Strong understanding and risk management mindset, proactively mitigating PAM related risks.