Identity & Access Management (IAM) Info Security Controls Specialist
Bank of America · Boston, MA · Yesterday
ManagementFull-time
Role Overview
The IAM Info Security Controls Specialist analyzes, strengthens, and secures the company's IAM systems and risk posture across End User Access Management and Application Services. This role collaborates across Lines of Business and Technology teams to continuously enhance access control compliance, improve governance programs, and ensure swift and accurate adherence to IAM Standards.
Responsibilities
- Maintain high-quality QA documentation, audit artifacts, process workflows, and training materials to support transparency and repeatability.
- Lead QA governance activities for End User Access Management and Application Services, ensuring alignment with IAM Standards and enterprise policies.
- Manage and maintain exceptions to the IAM Standard, ensuring appropriate risk justification, approvals, and periodic recertification per governance protocols.
- Ensure technology systems meet enterprise standards and fully comply with regulatory, legal, and risk requirements, escalating concerns as needed.
- Partner with security, technology, and business teams to design, implement, and scale identity and access controls supporting Frontier AI, machine identities, emerging digital capabilities, and next-generation governance frameworks.
- Perform Quality Assurance (QA) activities to validate access control compliance, monitor control health, and support accurate and sustainable metrics reporting.
Required Qualifications
- 5+ years of bank and finance industry hands-on experience in Identity Governance & Administration (IGA) or Identity and Access Management (IAM), managing identity lifecycle and associated enterprise initiatives.
- 5+ years implementing and governing IAM cloud solutions, controls, and capabilities.
- High proficiency, experience and working knowledge of Active Directory, Entra ID (Azure AD), SailPoint, Ping Identity, and connector frameworks, other mainstream IAM products.
- Experience supporting identity governance, authorization models, or access control frameworks for AI-enabled platforms, cloud-native services, emerging technologies, and large-scale digital transformation initiatives.
- Familiarity with common Information security and data protection frameworks and standards.
- Familiarity with Zero Trust architecture, FIDO2, and passwordless authentication concepts.
- Proficiency in data analytics and reporting tools (SQL, Tableau, PowerBI) for compliance and risk metrics.
- Strong ability to articulate data-driven insights and partner effectively with stakeholders to drive risk reduction and compliance with IAM Standards.
- Advanced proficiency and analytical skills, data management and data analysis with strong attention to detail, and background in quality assurance.
- Excellent problem-solving, documentation, and communication skills with the ability to work effectively across cross-functional teams.