Sr Solution Architect - Identity and Access Management (iam)

Bank of America Bank of America · Banking · Denver, CO +2

The Sr Solution Architect for Identity and Access Management (IAM) will design, strengthen, and secure the bank's IAM systems and security posture. This role involves collaborating across business units and CIO teams, designing solutions, documenting inefficiencies, and prioritizing improvements in IAM and authentication projects. The architect will also apply knowledge of relevant laws, rules, and regulations (NIST, COBIT, ISO) to establish security policies and standards, and work with engineering and product teams to define the overall identity and access strategy.

What you'd actually do

  1. Manage all aspects of delivery for solution design, including capturing of security requirements, identifying risks & opportunities, and alignment to information security policy.
  2. Create portfolio level, high‑level and low‑level design (PLD/HLD/LLD) documentation for IAM architectures, integrations, and solution components.
  3. Perform IAM-focused threat modeling to assess security risks, identify attack vectors, and define mitigation strategies across identity platforms and authentication workflows.
  4. Maintain thought leadership role in identity and access technology, remaining up to date on offerings of various service providers.
  5. Conduct research on emerging IAM technologies, authentication protocols, threat landscapes, and best practices to inform platform strategy and improve architectural robustness.

Skills

Required

  • 5+ years relevant hands-on experience in identity and authentication fields in a large and complex organization.
  • Knowledge of identity and authentication methodologies, techniques, and technologies.
  • Experience with Linux, Windows, Cloud Identity, Access Management, design and architecture of authentication services or Identity Store.
  • Security knowledge which covers core technology infrastructure (Account management, servers, databases, etc.) identity management and application security practice.
  • Proficient in articulating facts and data-driven plans and ability to partner with stakeholders to implement intended solutions to drive risk reductions and adherence to relevant Identity and Authentication requirement within IAM standards.
  • Knowledge and understanding of Identity and Access Management specific laws, rules, regulations, and Guidelines such as SOX, OCC, NIST, ISO/EC, FFIEC within the financial services sector.
  • Strong attention to detail and advanced analytical skills.
  • Excellent communication and presentation skills.
  • Excellent organizational skills and be able to effectively prioritize multiple tasks.
  • Proficient in data management which includes strong data analytical capabilities with advanced understanding of the collection and management of metadata.

Nice to have

  • Experience with PING products is a plus
  • Knowledge of IAM IGA related tools which support, vaulting, integration with service management tool would be an advantage.
  • Possession of CISSP certification would be an advantage.

What the JD emphasized

  • Knowledge and understanding of Identity and Access Management specific laws, rules, regulations, and Guidelines such as SOX, OCC, NIST, ISO/EC, FFIEC within the financial services sector.