Identity and Access Management (IAM) Access Controls & Entitlement Senior Specialist (Cloud Security required)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+17 more
Job description
Global Information Security (GIS) is responsible for protecting bank information systems, confidential and proprietary data, and customer information. GIS develops the bank’s Information Security strategy and policy, manages the Information Security program, identifies and addresses vulnerabilities and operates a global security operations center that monitors, detects and responds to cybersecurity incidents. Within GIS, Identity and Access Management (IAM) is a security discipline that enables the right individuals to access the right resources at the right times and in the right context. IAM addresses the mission-critical need to ensure appropriate access to the resources across increasingly heterogeneous technology environments, and to meet increasingly rigorous compliance requirements., Reporting to the Access Controls & Segregation of Duties Leader, this role is responsible for defining, operationalizing, and modernizing enterprise access control capabilities across traditional and cloud-native environments. The role will drive the evolution of role-based, attribute-based, policy-based, and segregation of duties access control models while establishing sustainable cloud entitlement management practices that reduce risk, improve visibility, and simplify access administration across the enterprise. The role will partner closely with Architecture, Engineering, Cloud Security, IAM Service Catalogue, and Line of Business stakeholders to establish modern access models that support the Bank’s continued cloud transformation., * Modernize enterprise access control capabilities through automation, AI-assisted analysis, workflow optimization, and data-driven insights.
- Drive transformation initiatives focused on cloud entitlement visibility, access intelligence, permission analytics, and access lifecycle efficiencies.
- Establish enterprise standards for cloud role engineering, entitlement taxonomy, permission management, and cloud access model design.
- Drive adoption of RBAC, ABAC, PBAC, and SOD controls within enterprise and cloud environments.
- Modernize the SOD design, implementation, controls, and oversight framework and practices for sustainable risk reduction.
- Develop sustainable approaches for governing cloud permissions, cloud identities, and cloud resource access at scale.
- Partner with cloud engineering and architecture teams to implement scalable cloud access models while reducing entitlement sprawl and excessive permissions.
- Operate through ambiguity, break down complex problems, and create structure where processes or accountabilities are unclear.
- Improve role quality, entitlement quality, access profiling, and access model effectiveness across technology platforms.
- Identify opportunities to reduce manual activities and simplify operational processes while strengthening risk mitigation.
- Act as a senior advisor on cloud access controls, entitlement strategy, and access modeling.
- Partner across IAM, Security, Technology, Product, and Line of Business teams to drive adoption of modern access control frameworks.
- Lead complex initiatives involving cloud permissions, entitlement management, role engineering, and access risk reduction.
- Translate technical access control concepts into actionable business outcomes for senior leadership.
- Lead the strategy and execution of cloud access control capabilities across AWS, Azure, GCP, SaaS platforms, and emerging cloud-native technologies., Key Stakeholders:
- GIS Executive Leadership
- IAM Governance Services
- IAM Product, Architecture, Engineering, and Operations teams
- LOB and technology stakeholders
- GIS, GT, Audit, Compliance, Risk, & other control partners
Shift:
1st shift (United States of America)
Hours Per Week:
40
Bank of America and its affiliates consider for employment and hire qualified candidates without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity, in accordance with all applicable federal, state, provincial and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our teammates.
View your “Know your Rights (https://www.eeoc.gov/sites/default/files/2023-06/22-088_EEOC_KnowYourRights6.12.pdf) “ poster.
View the LA County Fair Chance Ordinance (https://dcba.lacounty.gov/wp-content/uploads/2024/08/FCOE-Official-Notice-Eng-Final-8.30.2024.pdf) .
Requirements
- 10+ years of IAM, Cybersecurity, Cloud Security, or Access Management experience.
- Experience with Industry Standards & Framework (ISO, NIST, FFIEC, COBIT, CSA) related to Segregation of Duties (SoD).
- Experience implementing RBAC, ABAC, PBAC, JIT, Runtime, and cloud access control frameworks within large financial services or banking organizations.
- Experience designing and managing Cloud Permission Models & Entitlement Analytics across AWS, Azure, and GCP.
- Experience leading enterprise-scale IAM transformation and modernization initiatives.
- Experience partnering with Architecture, Engineering, Cloud Security, and Business stakeholders.
- Experience using analytics, automation, and process optimization to improve security outcomes.
- Experience implementing Automation, AI-Enabled Solutions & Workflow Optimization
- Experience performing data analytics and design solutions using scripting (Python, R, SQL) and industry tools (Wiz, Bloodhound, Splunk, Tableau, PowerBI, Pivot Tables).
- Experience with Microsegmentation and monitoring tools.
- Strong understanding of Cloud & Enterprise Infrastructure Platforms & Network
- Strong analytical and data-driven decision-making capabilities
Desired Qualifications:
- Strong expertise in Cloud Access Controls & Entitlement Management
- Deep knowledge of RBAC, ABAC, PBAC, JIT, Runtime Access Models
- Strong proficiency in IAM Architecture, Identity Attributes & Metadata
- Working knowledge of Authentication & Federation Technologies
- Excellent executive communication and stakeholder engagement skills
- Demonstrated ability to influence through expertise, collaboration, and credibility
- Industry information security certification:
- CISSP
- CCSP
- CRISC
- CISM
- AWS Security Specialty or Azure Security Engineer
- Azure AI Engineer Associate or AWS AI Practitioner
About the company
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!, Bank of America aims to create a workplace free from the dangers and resulting consequences of illegal and illicit drug use and alcohol abuse. Our Drug-Free Workplace and Alcohol Policy (“Policy”) establishes requirements to prevent the presence or use of illegal or illicit drugs or unauthorized alcohol on Bank of America premises and to provide a safe work environment.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. Should you be offered a role with Bank of America, your hiring manager will provide you with information on the in-office expectations associated with your role. These expectations are subject to change at any time and at the sole discretion of the Company. To the extent you have a disability or sincerely held religious belief for which you believe you need a reasonable accommodation from this requirement, you must seek an accommodation through the Bank’s required accommodation request process before your first day of work.
This communication provides information about certain Bank of America benefits. Receipt of this document does not automatically entitle you to benefits offered by Bank of America. Every effort has been made to ensure the accuracy of this communication. However, if there are discrepancies between this communication and the official plan documents, the plan documents will always govern. Bank of America retains the discretion to interpret the terms or language used in any of its communications according to the provisions contained in the plan documents. Bank of America also reserves the right to amend or terminate any benefit plan in its sole discretion at any time for any reason.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud
7 Cloud Computing Trends Coming in 2025 for Developers
Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production
Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence