Identity and Access Management (IAM) Security Administration Senior Specialist (Identity Platforms highly desired)
Bank of America · Denver, CO · 1 mo ago
OTHRFull-time
Identity and Access Management (IAM) Security Administration Senior Specialist
Responsibilities
- Lead the design, implementation, and ongoing management of access provisioning solutions across enterprise platforms, ensuring alignment with security policies and regulatory requirements.
- Serve as the subject matter expert for Active Directory, Microsoft Azure, Amazon Web Services (AWS), and Mainframe, Oracle and SQL databases, file systems, and enterprise storage, with a focus on enforcing least privileged access.
- Develop and maintain access control policies, group structures, and role-based access models to support scalable and secure provisioning.
- Collaborate with application owners, infrastructure teams, and business stakeholders to define and implement access requirements for new and existing systems.
- Drive automation initiatives to streamline provisioning and de-provisioning workflows, integrating with identity governance platforms and HR systems and IAM controls.
- Conduct periodic access reviews, entitlement audits, and certification campaigns to ensure compliance and identify access anomalies.
- Investigate and remediate access-related incidents, working closely with cybersecurity and risk teams to address vulnerabilities and improve controls.
- Provide technical leadership and mentorship to junior IAM team members, fostering a culture of security-first thinking and operational excellence.
- Stay current with emerging IAM technologies, regulatory changes, and industry best practices to continuously enhance the access provisioning program.
- Prepare and present metrics, reports, and recommendations to senior leadership and audit teams regarding access provisioning effectiveness and risk posture.
Required Qualifications
- 10+ years of progressive experience in Identity and Access Management, with a strong focus on access provisioning across enterprise environments.
- Deep technical expertise in Active Directory, Microsoft Azure AWS, Mainframe, Oracle Database, SQL Server, Windows and Unix file systems, and enterprise storage platforms.
- Proven ability to design, implement, and manage access provisioning solutions that enforce least privileged access and align with regulatory and internal compliance requirements.
- Strong understanding of IAM governance frameworks, platforms (e.g., SailPoint, Saviynt) role-based access control (RBAC), group policy management, and privileged access management (PAM) tools, CyberArk, Hashi Corp and Beyond Trust.
- Experience with automated provisioning/de-provisioning workflows, including integration with HR systems to demonstrated proficiency in scripting and automation (e.g., PowerShell, Python) to support scalable access provisioning and audit processes.
- Familiarity with cloud infrastructure security and access controls in hybrid environments, particularly within Microsoft Azure AWS and Oracle Cloud.
- Ability to conduct access reviews, entitlement audits, and risk assessments to identify and remediate access-related vulnerabilities.
- Excellent analytical, problem-solving, and communication skills, with the ability to collaborate across technical and business teams.
Shift
- 1st shift (United States of America)
- Hours Per Week: 40