Identity and Access Management; IAM Senior Consultant
Listed on 2025-12-16
-
IT/Tech
Cybersecurity, Information Security
Identity and Access Management (IAM) Senior Consultant
Company: Bank of America
Location: Boston, MA
Employment Type: Full Time
Date Posted: 12/03/2025
Job Categories: Computers, Software, Finance/Economics, Information Technology, Executive Management
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates’ physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.
Bank of America is committed to an in‑office culture with specific requirements for office‑based attendance and an appropriate level of flexibility for our teammates and businesses based on role‑specific considerations.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
LOB SummaryGlobal Information Security (GIS) is responsible for protecting bank information systems, confidential and proprietary data, and customer information. GIS develops the bank’s Information Security strategy and policy, manages the Information Security program, identifies and addresses vulnerabilities, and operates a global security operations center that monitors, detects, and responds to cybersecurity incidents. Within GIS, Identity and Access Management (IAM) is a security discipline that enables the right individuals to access the right resources at the right times and in the right context.
IAM addresses the mission‑critical need to ensure appropriate access across increasingly heterogeneous technology environments and to meet increasingly rigorous compliance requirements.
In today’s highly connected world, managing and securing the identity of users is essential to the safety and success of our workforce. The IAM team works within Global Information Services (GIS) and in close participation with all other LOB teams as well as second and third line of defense partners. This role is highly visible and requires frequent interaction with senior management and key stakeholders.
The Senior IAM Information Security Controls Lead will analyze, strengthen, and secure the company’s IAM systems and overall risk posture for end user, application and privileged access management. The individual in this role will be a leader in the IAM innovation space, working with senior leaders to implement new technologies and frameworks. This role requires collaboration with technology peers to modernize the IAM ecosystem for securing evolving technologies and identities.
The role also applies knowledge of laws, rules, regulations, and information security frameworks (e.g., NIST, COBIT, ISO) to establish and maintain policies, validate alignment of processes and controls to requirements, report on adherence to policy requirements, and maintain governance programs related to IAM Standard controls. Expectations include leveraging data analytics, governance process management, and cross‑functional partnerships to verify policy compliance, identify gaps, and support remediation activities.
Responsibilities- Define and steer IAM standards including designing enterprise appropriate adherence models, and related measures for governance, controls and effectiveness management.
- Drive application/platform IAM modernization approach and program for information & data synchronization/management, moving from legacy manual to modernized identity automation solutions, such as connector frameworks.
- Collaborate with partner cybersecurity, engineering, and compliance teams to develop and align controls with industry standards, to mitigate known threat vectors, adopt best practice principles and meet regulatory requirements.
- Drive optimization & adoption of innovative and transformational strategies including but…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).