Demo

Identity and Access Management IGA Governance Lead

Bank of America
Denver, NC Full Time
POSTED ON 1/25/2025
AVAILABLE BEFORE 2/21/2025

Job Description:

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection.

Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day. One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world. We're devoted to being a diverse and inclusive workplace for everyone. We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well-being.

Bank of America believes both in the importance of working together and offering flexibility to our employees. We use a multi-faceted approach for flexibility, depending on the various roles in our organization.

Working at Bank of America will give you a great career with opportunities to learn, grow and make an impact, along with the power to make a difference.

LOB Overview:

Global Information Security (GIS) is responsible for protecting bank information systems, confidential and proprietary data, and customer information. GIS develops the bank's Information Security strategy and policy, manages the Information Security program, identifies and addresses vulnerabilities and operates a global security operations center that monitors, detects and responds to cybersecurity incidents. Within GIS, Identity and Access Management (IAM) is a security discipline that enables the right individuals to access the right resources at the right times and in the right context. IAM addresses the mission-critical need to ensure appropriate access to the resources across increasingly heterogeneous technology environments, and to meet increasingly rigorous compliance requirements

Role Description:

The IAM Role Based Access & Segregation of Duties Manager is a senior leader of the Identity and Access Management team.

This person should have a vision for how to best leverage technologies and processes to protect our data and systems, while allowing our business partners to move quickly and securely by automating identity life cycle, access provisioning/deprovisioning, and will plan and execute at a strategic level, lead, and influence resources with other teams and organizations. The team reporting to this leader provides consulting, subject matter expertise, control management, risk mitigation, product direction, and oversight for the entire Identity Governance and Administration (IGA) ecosystem related to role-based access, identity attributes, policy-based access, and segregations of duty for all lines of business including Information Technology. The person in this role will provide leadership by working closely with cross-functional teams, operations, product management, architecture, engineering teams, project managers, and analysts, partnering with stakeholders across the LOBs, and GIS leadership.

Responsibilities:

  1. An advocate and leader reinforcing the need for restricting permission assignment to users and birthright access application through hands on support activities.
  2. Leads the team in providing tool and process support on bundle creation and maintenance.
  3. Connects with First Line of Defense on product pain points and recommends product and capability improvements.
  4. Respond to audit and regulatory requests as needed.
  5. Work closely with Cybersecurity, audit, compliance, legal, and stakeholders to define access policies, user roles, and access control procedures for our diverse technology and lines of business landscape.
  6. Ensure the team coordinates with Governance services on new or changing controls and executes accordingly.
  7. Establishes a framework of policies and technologies as it relates to role and attribute-based access controls through collaboration with FLU, Technology, Product, and Architecture.
  8. Advises on access model best practices by acting as SME.
  9. Support the team members by providing technical guidance as well as assist other on-going engagements for resolving critical issues.
  10. Investigate and troubleshoot complex technical issues, perform root-cause analysis for high severity issues, and provide permanent resolution.
  11. Work with technology vendors as appropriate to resolve product issues, technology evaluations, and design reviews.
  12. Meets demands of managing multiple work streams, communicating effectively with senior technology and business leadership, and demonstrate experience leading large and complex projects and global programs.
  13. Assess and advise on modernizing IAM capabilities and methodologies, including development of strategies, readiness assessment, development of training and communications.
  14. Operate as an advisor for our distributed IAM teams to help them to elect the best solution for resolving the identified / possible technical issues or security threats in the system / infrastructure.
  15. Harness familiarity with IT security and risk management practices on risk mitigants.

Required Qualifications:

  • 10 years experience in IAM working on complex projects and programs.
  • Strong interpersonal and influencing skills.
  • Excellent organizational skills, able to manage multiple work streams simultaneously and respond to rapidly changing demands.
  • Demonstrated experience working with frequently-utilized IAM vendor solutions such as SailPoint, Savyint, ForgeRock, Ping, Okta, Varonis, and CyberArk in large enterprises for the purpose of governing security.
  • Experience in configuring and deployment of Single Sign On and MFA solutions, IGA solutions, and PAM Solutions.
  • Hands-on on WAM products and particularly on Ping suite of products (Ping Access, Ping Federate and PingID) and federation concepts.

Desired Qualifications:

  • Good knowledge of Web / Application servers (e.g. IIS, WebSphere, WebLogic, JBoss, and Apache etc.).
  • Strong technical knowledge of authentication and authorization including Authz and Authn, OIDC, SAML, XACML, LDAP, OAuth, OpenID.
  • Experience working on various operating systems such as Windows, Linux, Solaris etc.
  • Working knowledge on Databases such as MS SQL, Oracle, mySQL.
  • Good understanding or hands-on experience on JSON, REST and SOAP.
  • Advanced knowledge of cloud platforms (AWS, Azure, GCP etc.) experience in deploying and managing AM solutions on cloud platforms. AWS is preferred.
  • Deep knowledge and experience working with technology infrastructure including Windows, Active Directory, LDAP, Unix/Linux, databases, authentication protocols, and containers.

This job will be open and accepting applications for a minimum of seven days from the date it was posted.

Shift: 1st shift (United States of America)

Hours Per Week: 40

Pay Transparency details: US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540)

Pay and benefits information: Pay range $160,000.00 - $185,100.00 annualized salary, offers to be determined based on experience, education and skill set.

Discretionary incentive eligible: This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.

Benefits: This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.

Salary : $160,000 - $185,100

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Identity and Access Management IGA Governance Lead?

Sign up to receive alerts about other jobs on the Identity and Access Management IGA Governance Lead career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$134,170 - $182,234
Income Estimation: 
$173,507 - $234,155
Income Estimation: 
$59,454 - $77,232
Income Estimation: 
$74,206 - $95,716
Income Estimation: 
$74,206 - $95,716
Income Estimation: 
$94,625 - $127,578
Income Estimation: 
$94,625 - $127,578
Income Estimation: 
$132,795 - $178,786
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Bank of America

Bank of America
Hired Organization Address Rogers, AR Full Time
Job Description: Merrill Wealth Management is a leading provider of comprehensive wealth management and investment produ...
Bank of America
Hired Organization Address Birmingham, AL Full Time
Job Description: Merrill Wealth Management is a leading provider of comprehensive wealth management and investment produ...
Bank of America
Hired Organization Address Hanover, MD Full Time
Job Description: At Bank of America, we are guided by a common purpose to help make financial lives better through the p...
Bank of America
Hired Organization Address Phoenix, AZ Temporary
Job Description: Merrill Wealth Management is a leading provider of comprehensive wealth management and investment produ...

Not the job you're looking for? Here are some other Identity and Access Management IGA Governance Lead jobs in the Denver, NC area that may be a better fit.

Access Management IGA Strategist

Bank of America, Denver, NC

Identity and Access Governance Specialist

Bank of America, Denver, NC

AI Assistant is available now!

Feel free to start your new journey!