Bank of America Logo

Bank of America

Identity & Access Management (IAM) Governance Executive

Reposted 16 Days Ago
Be an Early Applicant
In-Office
Boston, MA, USA
240K-350K Annually
Senior level
In-Office
Boston, MA, USA
240K-350K Annually
Senior level
Senior executive leading global IAM governance: define strategy, policy, and controls; oversee IGA, federation/SSO/MFA, PAM, secrets vaulting, and directory services; ensure regulatory alignment (NIST, ISO, FFIEC), auditability, identity risk metrics, and cross-functional adoption across the bank.
The summary above was generated by AI

Job Description:

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates’ physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
 

Summary:

Global Information Security (GIS) is responsible for protecting bank information systems, confidential and proprietary data, and customer information.  GIS develops the bank’s Information Security strategy and policy, manages the Information Security program, identifies and addresses vulnerabilities and operates a global security operations center that monitors, detects and responds to cybersecurity incidents.  Within GIS, Identity and Access Management (IAM) is a security discipline that enables the right individuals to access the right resources at the right times and in the right context.

IAM addresses the mission-critical need to ensure appropriate access to the resources across increasingly heterogeneous technology environments, and to meet increasingly rigorous compliance requirements

Role Description:
The Senior Vice President executive of Identity & Access Management (IAM) Governance serves as the enterprise authority for identity governance strategy, policy, and risk management within Global Information Security. This leader defines and drives the IAM governance vision across the bank, ensuring that identity controls, technologies, and processes align with globally recognized frameworks, regulatory expectations, and the bank’s strategic objectives.

The role oversees enterprise-wide, global, IAM governance, including policy, standards, lifecycle controls, access certifications, privileged access governance, authentication, and identity risk metrics, anchored to leading industry standards: NIST SP 800‑63‑4 Digital Identity Guidelines, NIST SP 800‑53 Access Control & Identification/Authentication controls, ISO/IEC 27001:2022 Annex A 5.16 Identity Management, and FFIEC Authentication & Access Management guidance for financial institutions.

As the global IAM Governance leader, you will shape the long‑term direction of the IAM technology ecosystem, including Identity Governance & Administration (IGA), federation/SSO/MFA, privileged access management (PAM), secrets vaulting, and directory services, and ensure robust auditability, regulatory alignment, and measurable risk reduction across all identity domains.

Required Skillset:

Expertise in IAM Governance & Control Framework

Deep command of identity standards and regulatory expectations including NIST 800‑63‑4 (digital identity assurance), NIST 800‑53 AC/IA controls, and ISO 27001 Annex A 5.16 identity lifecycle requirements.
Ability to translate these frameworks into enterprise policy, standards, and measurable control objectives.
Participate in industry forums and represent the bank as needed, to ensure evolution of IAM governance in alignment with peer banks.

Identity Technologies & Architecture Mastery

Extensive experience with enterprise IGA platforms (e.g., SailPoint, Saviynt), federation/SSO/MFA (OIDC, SAML), directory services, and privileged access technologies—consistent with senior‑level role expectations in industry postings.

Privileged Access & Zero Standing Privilege (ZSP)

Strong understanding of Just‑in‑Time (JIT) privileged access models and risk‑based reduction of standing admin privileges aligned with modern PAM best practices.

Regulatory & Audit Alignment for Financial Services

Ability to interpret, operationalize, and evidence compliance with FFIEC Authentication & Access Guidance as well as global regulatory expectations for layered security, MFA, and monitoring expectations.

Executive Communication & Governance Leadership

Exceptional ability to articulate technical identity risks, residual exposure, and compliance posture to senior business leaders, regulators, Internal Audit, Compliance, and Operational Risk, and relate the same in governance routines.

Enterprise Metrics & Identity Risk Insight  

Skilled in designing and governing IAM KRIs/KPIs (e.g., certification quality, toxic entitlement reduction, IGA onboarding velocity, JIT/ZSP adoption), as emphasized in senior IGA director roles.

Cross‑Functional Influence & Three‑Lines‑of‑Defense Partnership

Ability to influence technology executives, CIO organizations, BISOs, and control partners to drive identity risk reduction and consistent taxonomy and control adoption.

Required Qualifications:

10+ years of leadership experience in IAM, information security governance, risk management, or related executive technology functions within large-scale, regulated enterprises, aligned with senior and executive‑level identity roles.
Proven experience leading large global teams, managing executive‑level governance forums, and directing complex IAM transformation initiatives.
Demonstrated success overseeing and continually improving IGA, federation, privileged access, secrets management, and identity lifecycle modernization programs across hybrid environments.
Experience preparing for and responding to regulatory exams and internal/external audits, ensuring alignment to FFIEC requirements and NIST/ISO frameworks.
Track record driving adoption of modern authentication and identity proofing approaches aligned with NIST SP 800‑63‑4.
Ability to reduce privileged access risk through JIT/ZSP and PAM modernization initiatives in alignment with IAM policy requirements.
Professional certifications preferred: CISSP, CISM, CISA, CGEIT, and IAM platform‑specific certifications.

Shift:

1st shift (United States of America)

Hours Per Week: 

40

Pay Transparency details

US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - MA - Boston - 100 Federal St - 100 Federal St Lp (MA5100)

Pay and benefits information

Pay range$240,000.00 - $350,000.00 annualized salary, offers to be determined based on experience, education and skill set.

Discretionary incentive eligible

This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.

Benefits

This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.

Similar Jobs

7 Hours Ago
Remote or Hybrid
United States
22-33 Hourly
Mid level
22-33 Hourly
Mid level
Artificial Intelligence • Automotive • Greentech • Information Technology • Machine Learning • Software • Cybersecurity
The SEO Specialist II enhances clients' online presence through data analysis, local SEO tactics, strategic content implementation, and collaboration with internal teams. They provide performance reports, client support, and ongoing SEO education while managing SEO-related requests and trends.
Top Skills: CopyscapeDba PlatformGoogle AnalyticsGoogle Search ConsoleLocal FalconMajestic SeoMoz ProSem Rush
9 Hours Ago
Hybrid
Boston, MA, USA
150K-170K Annually
Mid level
150K-170K Annually
Mid level
HR Tech • Software
As an iOS Developer, you'll enhance our native iOS application, collaborating with a cross-functional team, focusing on delivery, debugging, and improving performance while writing maintainable code.
Top Skills: Ios FrameworksSwift
9 Hours Ago
Hybrid
Boston, MA, USA
170K-200K Annually
Senior level
170K-200K Annually
Senior level
HR Tech • Software
The Senior Product Manager will lead the enterprise integration strategy, manage partnerships, drive product development, and support pre-sales efforts while collaborating cross-functionally to meet customer needs.
Top Skills: APIsFigmaIntegration PlatformsOracle HcmSAPServicenowWorkday

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account