Privileged Access Management (pam) Sr. Analyst

Bank of America Bank of America · Banking · Boston, MA +1

This role is for a Senior Analyst in Privileged Access Management (PAM) at Bank of America, focusing on enforcing security controls across platforms and applications to meet regulatory and internal IAM standards. The role involves risk assessment, monitoring industry trends, providing Active Directory security consultation, developing new PAM requirements (including cloud-based solutions), and collaborating with various Global Information Security (GIS) functions, business units, and regulatory agencies. The ideal candidate will have extensive knowledge of PAM methodologies, security standards (NIST, ISO, FFIEC, MITRE ATT&CK), compliance certifications (SOX, SOC2), and experience with PAM tools.

What you'd actually do

  1. This role is primarily responsible for ensuring that relevant Privileged Access Controls are enforced across platforms and applications to provide optimal security.
  2. Partner with PAM Governance leads to ensure that Privileged Access Controls are appropriately measured, reported and governed.
  3. Appropriately assess Privileged Access risk when business and technology decisions are made, demonstrating an outstanding risk management mindset and best practices to safeguard BAC’s reputation, its clients, and assets by driving or exceeding compliance with applicable laws, rules, and regulations, adhering to BAC Policy and Standards.
  4. Monitor industry information security and PAM trends and engages peer organizations to refine and enhance BAC’s PAM strategy.
  5. Apply industry PAM best practices, templates, and documentation while also proposing improvements based on practical knowledge.

Skills

Required

  • 10+ years experience
  • Extensive knowledge and understanding of PAM-specific laws, rules, and regulations within the financial services sector.
  • Expert level knowledge of privileged access management methodologies and techniques for on-prem and Cloud implementation.
  • Familiarity with security standards such as NIST, ISO/EC, FFIEC, and MITRE ATT&CK framework.
  • Knowledge of Compliance Certifications such as SOX, SOC, SOC2.
  • Understanding and interpreting BAC’s established information security Policy, Standards, Procedure and Guides, and applying this knowledge to related PAM decisions and response.
  • Proficiency in implementing and governing Risk and Role based access security controls.
  • Extensive experience in managing Active Directory to enforce privileged access controls.
  • Ability to influence platform and application owners to build more secure processes.
  • Strong understanding and risk management mindset, proactively mitigating PAM related risks.
  • 10 years relevant hands-on experience in PAM with at least of 5 years of management experience
  • Deep security knowledge

Nice to have

  • Expert knowledge of PAM related tools which support session proxy, vaulting, just-in-time provision, integration with service management tool would be an advantage.

What the JD emphasized

  • Privileged Access Management
  • PAM
  • security controls
  • IAM Standard
  • risk management
  • compliance
  • laws, rules, and regulations
  • Policy, Standards, Procedure and Guides
  • SOX
  • SOC
  • SOC2