Sr Solution Architect - Identity and Access Management (iam)

Bank of America Bank of America · Banking · Denver, CO +2

This role is for a Sr. Solution Architect focused on Identity and Access Management (IAM) within Global Information Security at Bank of America. The architect will design, strengthen, and secure IAM systems, collaborate with business units and CIO teams, and improve security adherence. Responsibilities include designing IAM architectures, performing threat modeling, researching emerging IAM technologies, and consulting on design decisions. The role requires knowledge of IAM methodologies, technologies (experience with PING products is a plus), cloud identity, access management, and security concepts, as well as understanding of financial sector regulations like SOX, OCC, NIST, ISO/EC, and FFIEC. CISSP certification is advantageous.

What you'd actually do

  1. Manage all aspects of delivery for solution design, including capturing of security requirements, identifying risks & opportunities, and alignment to information security policy.
  2. Create portfolio level, high‑level and low‑level design (PLD/HLD/LLD) documentation for IAM architectures, integrations, and solution components.
  3. Perform IAM-focused threat modeling to assess security risks, identify attack vectors, and define mitigation strategies across identity platforms and authentication workflows.
  4. Maintain thought leadership role in identity and access technology, remaining up to date on offerings of various service providers.
  5. Serve as a technical security design resource through the Systems Development Lifecyle and provide expert level guidance on design decisions, standards, and operational practices.

Skills

Required

  • 5+ years relevant hands-on experience in identity and authentication fields in a large and complex organization.
  • Knowledge of identity and authentication methodologies, techniques, and technologies.
  • Experience with Linux, Windows, Cloud Identity, Access Management, design and architecture of authentication services or Identity Store.
  • Security knowledge which covers core technology infrastructure (Account management, servers, databases, etc.) identity management and application security practice.
  • Proficient in articulating facts and data-driven plans and ability to partner with stakeholders to implement intended solutions to drive risk reductions and adherence to relevant Identity and Authentication requirement within IAM standards.
  • Knowledge and understanding of Identity and Access Management specific laws, rules, regulations, and Guidelines such as SOX, OCC, NIST, ISO/EC, FFIEC within the financial services sector.
  • Strong attention to detail and advanced analytical skills.
  • Excellent communication and presentation skills.
  • Excellent organizational skills and be able to effectively prioritize multiple tasks.
  • Proficient in data management which includes strong data analytical capabilities with advanced understanding of the collection and management of metadata.

Nice to have

  • Experience with PING products is a plus
  • Knowledge of IAM IGA related tools which support, vaulting, integration with service management tool would be an advantage.
  • Possession of CISSP certification would be an advantage.

What the JD emphasized

  • Knowledge and understanding of Identity and Access Management specific laws, rules, regulations, and Guidelines such as SOX, OCC, NIST, ISO/EC, FFIEC within the financial services sector.