Identity, Authentication, Authorization & Governance (IAM) Sr. Security Specialist (Leadership experience required)

Bank of America

Chicago (IL)

On-site

USD 140,000 - 200,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Discretionary incentive eligible
Industry-leading benefits

Job summary

Bank of America is seeking an IAM Identity, Authentication, Authorization & Governance Senior Security Specialist within Global Information Security. You will shape enterprise identity governance across human, machine, and service identities, partnering with technology, risk, compliance, and audit leaders to strengthen authentication and access controls for cloud and digital growth.

The role offers visibility, internal mobility, and opportunities to influence security strategy, policy

Qualifications

  • 10+ years of experience in identity and access management, cybersecurity, cloud security, or access management within large, complex organizations.
  • Leadership experience required.
  • Demonstrated success setting direction for or influencing enterprise-scale IAM transformation, modernization, governance, or control programs.
  • Deep knowledge of modern authentication, federation, and authorization standards and patterns, including OAuth 2.0, OpenID Connect, SAML, service-to-service access, and token-based authentication.
  • Experience governing identity and access across cloud, SaaS, API, application, and hybrid environments.
  • Strong understanding of human and non-human identity risk, including workload, service, machine, and AI-agent identities, delegated authority, and lifecycle accountability.
  • Experience translating policy, regulatory, and audit requirements into practical identity controls within regulated environments.
  • Knowledge of relevant standards and frameworks, including NIST, ISO, FFIEC, SOX, SOC, or equivalent.
  • Demonstrated ability to advise, brief, and influence senior leaders on complex technology, security, and risk matters.
  • Exceptional written and verbal communication skills, with experience translating complex concepts into clear executive-level presentations and recommendations.
  • Strong judgment and analytical decision-making skills, with the ability to operate effectively in ambiguous and rapidly evolving environments.
  • Proven ability to prioritize competing demands, drive cross-functional alignment, and deliver measurable outcomes.

Responsibilities

  • Risk Management, Governance & Compliance: Establish IAM control requirements, governance measures, and escalation paths in partnership with risk and control organizations. Translate internal policy, regulatory, and audit requirements into practical, sustainable controls across enterprise platforms and processes. Drive remediation of identity risks and control gaps across business and technology organizations, escalating risk acceptance decisions as appropriate. Provide executive-level reporting and recommendations on identity risk, control health, adoption, exceptions, and remediation progress. Support audit readiness and sustainable issue closure through clear accountability, evidence, metrics, and ongoing control monitoring.
  • Collaboration & Influence: Build trusted partnerships across GIS, Core Technology, Application Development, Risk, Compliance, Audit, and Third-Party Management. Advise and influence senior leaders on complex identity, technology, security, and risk matters, including strategic options and trade-offs. Drive cross-functional alignment, ownership, and adoption across teams operating at different speeds and maturity levels. Translate complex technical and risk concepts into clear executive recommendations, decisions, and measurable outcomes.
  • Enterprise IAM Strategy, Architecture & Access Controls: Define enterprise business requirements, strategic direction, and standards for authentication, authorization, and identity governance. Establish governance for human, non-human, workload, service, and AI-agent identities, including ownership, lifecycle management, delegated authority, credential rotation and revocation, and human accountability. Set enterprise standards for API authentication and authorization, service-to-service access, token-based controls, and consistent secure identity patterns. Drive adoption of zero trust, least privilege, phishing-resistant and passwordless authentication, continuous access evaluation, and fine-grained, context-aware authorization. Advance policy-as-code, automated control enforcement, and identity threat detection to improve control consistency and reduce manual risk. Embed IAM requirements into application, platform, API, cloud, and AI solution design and development lifecycles. Influen

Skills

IAM
Cybersecurity
Cloud security
Leadership
OAuth 2.0
OpenID Connect
SAML
Policy translation
Executive communication
Risk management

Tools

Active Directory
Microsoft Entra ID
Ping
Python
SQL
Splunk
Tableau
Power BI
Power Automate

Job description

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits. We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve. Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role‑specific responsibilities and business needs. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact.

Join us!

Role Description

The IAM Identity, Authentication, Authorization & Governance Senior Security Specialist sits within Global Information Security (GIS) and plays a highly visible role in shaping how human, machine, and service identities are governed across the enterprise. This role offers the opportunity to influence strategic security priorities, partner with senior stakeholders across technology, risk, compliance, and audit, and help strengthen how authentication and authorization controls evolve to support cloud and digital growth. It is an excellent opportunity for an internal candidate looking to broaden their impact, build enterprise‑wide relationships, and contribute to a critical and evolving security agenda.

Responsibilities
  • Risk Management, Governance & Compliance

    Establish IAM control requirements, governance measures, and escalation paths in partnership with risk and control organizations. Translate internal policy, regulatory, and audit requirements into practical, sustainable controls across enterprise platforms and processes. Drive remediation of identity risks and control gaps across business and technology organizations, escalating risk acceptance decisions as appropriate. Provide executive‑level reporting and recommendations on identity risk, control health, adoption, exceptions, and remediation progress. Support audit readiness and sustainable issue closure through clear accountability, evidence, metrics, and ongoing control monitoring.

  • Collaboration & Influence

    Build trusted partnerships across GIS, Core Technology, Application Development, Risk, Compliance, Audit, and Third‑Party Management. Advise and influence senior leaders on complex identity, technology, security, and risk matters, including strategic options and trade‑offs. Drive cross‑functional alignment, ownership, and adoption across teams operating at different speeds and maturity levels. Translate complex technical and risk concepts into clear executive recommendations, decisions, and measurable outcomes.

  • Enterprise IAM Strategy, Architecture & Access Controls

    Define enterprise business requirements, strategic direction, and standards for authentication, authorization, and identity governance. Establish governance for human, non‑human, workload, service, and AI‑agent identities, including ownership, lifecycle management, delegated authority, credential rotation and revocation, and human accountability. Set enterprise standards for API authentication and authorization, service‑to‑service access, token‑based controls, and consistent secure identity patterns. Drive adoption of zero trust, least privilege, phishing‑resistant and passwordless authentication, continuous access evaluation, and fine‑grained, context‑aware authorization. Advance policy‑as‑code, automated control enforcement, and identity threat detection to improve control consistency and reduce manual risk. Embed IAM requirements into application, platform, API, cloud, and AI solution design and development lifecycles. Influence investment priorities and modernization roadmaps that reduce standing privilege, unmanaged identities, inconsistent access patterns, and control gaps. Define measures of adoption, control health, identity risk, and remediation progress, and use results to drive accountable outcomes.

Required Qualifications
  • 10+ years of experience in identity and access management, cybersecurity, cloud security, or access management within large, complex organizations.
  • Leadership experience required.
  • Demonstrated success setting direction for or influencing enterprise‑scale IAM transformation, modernization, governance, or control programs.
  • Deep knowledge of modern authentication, federation, and authorization standards and patterns, including OAuth 2.0, OpenID Connect, SAML, service‑to‑service access, and token‑based authentication.
  • Experience governing identity and access across cloud, SaaS, API, application, and hybrid environments.
  • Strong understanding of human and non‑human identity risk, including workload, service, machine, and AI‑agent identities, delegated authority, and lifecycle accountability.
  • Experience translating policy, regulatory, and audit requirements into practical identity controls within regulated environments.
  • Knowledge of relevant standards and frameworks, including NIST, ISO, FFIEC, SOX, SOC, or equivalent.
  • Demonstrated ability to advise, brief, and influence senior leaders on complex technology, security, and risk matters.
  • Exceptional written and verbal communication skills, with experience translating complex concepts into clear executive‑level presentations and recommendations.
  • Strong judgment and analytical decision‑making skills, with the ability to operate effectively in ambiguous and rapidly evolving environments.
  • Proven ability to prioritize competing demands, drive cross‑functional alignment, and deliver measurable outcomes.
Desired Qualifications
  • Experience in financial services, banking, or another highly regulated industry.
  • Knowledge of RBAC, ABAC, PBAC, segregation of duties, just‑in‑time access, runtime authorization, and cloud entitlement management.
  • Experience with identity platforms such as Active Directory, Microsoft Entra ID, Ping, or equivalent technologies.
  • Experience with identity analytics, automation, policy‑as‑code, AI‑enabled security solutions, or workflow optimization.
  • Familiarity with scripting and analytics tools such as Python, R, SQL, Splunk, Tableau, Power BI, Microsoft Copilot Studio, Power Automate, or equivalent.
  • Experience with cloud security, infrastructure, microsegmentation, monitoring, infrastructure‑as‑code, or related technologies.
  • Industry certification such as CISSP, CCSP, CRISC, CISM, or equivalent.
Shift

1st shift (United States of America)

Hours Per Week

40

Pay Transparency details

US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540), US - MA - Boston - 100 Federal St - 100 Federal St Lp (MA5100)

Pay range

$140,000.00 - $200,000.00 annualized salary, offers to be determined based on experience, education and skill set.

Discretionary incentive eligible

Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.

Benefits

This role is currently benefits eligible. We provide industry‑leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.

Privacy Statement: https://careers.bankofamerica.com/en-us/privacy-notice

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day. One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world. We’re devoted to being a diverse and inclusive workplace for everyone. We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well‑being. Bank of America believes both in the importance of working together and offering flexibility to our employees. We use a multi‑faceted approach for flexibility, depending on the various roles in our organization. Working at Bank of America will give you a great career with opportunities to learn, grow and make an impact, along with the power to make a difference.

Partnering Locally Learn about some of the ways Bank of America is making a difference in the communities we serve. Global Impact Learn about the six areas that guide Bank of America’s efforts to help make financial lives better for customers, clients, communities and our teammates. Opportunity and Inclusion Each employee brings unique skills, background and opinions. We see opportunity and inclusion as our platform for innovation and a key component in our success. Our Values Learn about our four values that represent what we believe.

Pay Transparency: https://careers.bankofamerica.com/en-us/pay-transparency

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Identity, Authentication, Authorization & Governance (IAM) Sr. Security Specialist (Leadership experience required)
Identity, Authentication, Authorization & Governance (IAM) Sr. Security Specialist (Leadership experience required)

Bank of America • Washington

On-site
USD 140,000 - 200,000
Discretionary incentive
Benefits
Identity & Access Management (IAM) Info Security Controls Specialist
Identity & Access Management (IAM) Info Security Controls Specialist

Bank of America • Boston (MA)

On-site
USD 78,000 - 136,000
Benefits eligible
Discretionary incentive
Paid time off
Identity, Authentication, Authorization & Governance (IAM) Sr. Security Specialist (Leadership experience required)
Identity, Authentication, Authorization & Governance (IAM) Sr. Security Specialist (Leadership experience required)

Bank of America • Washington

On-site
USD 140,000 - 200,000
Discretionary incentive
Benefits eligible
Identity and Access Management (IAM) Senior Consultant (Cloud exp. required)
Identity and Access Management (IAM) Senior Consultant (Cloud exp. required)

Bank of America • Denver (CO)

On-site
USD 140,000 - 200,000
Industry-leading benefits
Discretionary incentive plan
Annual discretionary award
Identity & Access Management (IAM) Info Security Controls Specialist
Identity & Access Management (IAM) Info Security Controls Specialist

HITEC • Boston (MA), Northern (KY)

On-site
USD 78,000 - 136,000
Benefits eligible
Discretionary incentive plan
Wellness and financial benefits
Data Architect – Global Information Security
Data Architect – Global Information Security

Bank of America • Chicago (IL)

On-site
USD 120,000 - 136,000
AI Security Enablement - Strategy and Standards Lead
AI Security Enablement - Strategy and Standards Lead

Bank of America • Chicago (IL)

On-site
USD 142,000 - 203,000
Business Information Security Officer (BISO) - CFO and GRM
Business Information Security Officer (BISO) - CFO and GRM

Bank of America • Washington

On-site
USD 99,000 - 145,000
Identity and Access Management (IAM) Senior Consultant (Cloud exp. required)
Identity and Access Management (IAM) Senior Consultant (Cloud exp. required)

Bank of America • Washington

On-site
USD 140,000 - 200,000
Discretionary incentive eligible
Comprehensive benefits
Identity and Access Management (IAM) Senior Consultant (Cloud exp. required)
Identity and Access Management (IAM) Senior Consultant (Cloud exp. required)

Bank of America • Chicago (IL)

On-site
USD 140,000 - 200,000