Identity and Access Management (IAM) Senior Consultant
Bank of America
- Location
- Boston
- Work model
- On-Site
- Level
- Senior
- H-1B history
- 278 approvals (FY2023)
- Posted
- 8h ago
Skills
About this role
Job Description
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits. We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve. Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Position
Summary: Global Information Security (GIS) is responsible for protecting bank information systems, confidential and proprietary data, and customer information. GIS develops the bank’s Information Security strategy and policy, manages the Information Security program, identifies and addresses vulnerabilities, and operates a global security operations center that monitors, detects, and responds to cybersecurity incidents. Within GIS, Identity and Access Management (IAM) is a security discipline that enables the right individuals to access the right resources at the right times and in the right context. IAM addresses the mission-critical need to ensure appropriate access across increasingly heterogeneous technology environments and to meet increasingly rigorous compliance requirements.
Responsibilities
Define and steer IAM standards, governance models, controls, and effectiveness measures for public cloud, SaaS, Generative AI, machine learning, and Agentic AI environments. Lead comparative assessments of IAM and identity-security capabilities across AWS, Microsoft Azure, Google Cloud Platform, and emerging AI platforms, evaluating strategic alignment, security, control coverage, integration complexity, sustainability, and implementation effort. Evaluate cloud-native, enterprise, and vendor-provided IAM solutions against business requirements, regulatory expectations, target-state architecture, existing investments, and long-term operating-model objectives. Develop recommendations, decision frameworks, roadmaps, and reusable IAM patterns for cloud and AI adoption, including identity lifecycle management, human and non-human identities, authentication, authorization, privileged access, secrets management, and entitlement governance. Assess identity and access implications of AI solutions, including AI agents, models, platforms, APIs, data sources, tools, and agent-to-agent interactions, with particular focus on ownership, least privilege, lifecycle governance, runtime authorization, traceability, and access drift. Partner with cloud, AI, cybersecurity, architecture, engineering, product, risk, and compliance teams to identify control gaps, compare solution alternatives, and translate strategic requirements into actionable recommendations. Monitor public cloud, AI, IAM, and cybersecurity market developments and use industry research, peer practices, and regulatory guidance to inform IAM strategy, standards, investment priorities, and vendor