Job Description:
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Global Information Security (GIS) is responsible for protecting the bank’s information systems, confidential and proprietary data, and customer information. GIS develops and executes the bank’s information security strategy, manages the enterprise security program, identifies and remediates vulnerabilities, and operates a global security operations center that monitors, detects, and responds to cybersecurity incidents.
Within GIS, Identity & Access Management (IAM) ensures the right individuals have the right access to the right resources at the right time—across increasingly heterogeneous environments and within rigorous compliance standards.
What you can expect in Identity & Access Management
In today’s connected ecosystem, safeguarding user identity is critical to the safety and success of our global workforce. The IAM team partners closely within Global Information Security, all Lines of Business, and second- and third-line functions. This highly visible role involves frequent engagement with senior leaders and key stakeholders.
If you excel in dynamic, fast-paced, global environments and are passionate about modern security technologies, this is the place for you. You will collaborate with subject-matter experts, drive meaningful risk reduction, support operational excellence, and help strengthen the bank’s overall identity security posture.
Role Overview:
The IAM Info Security Controls Specialist analyzes, strengthens, and secures the company’s IAM systems and risk posture across End User Access Management and Application Services. This role collaborates across Lines of Business and Technology teams to continuously enhance access control compliance, improve governance programs, and ensure swift and accurate adherence to IAM Standards.
Establish and maintain strong partnerships across GIS, Global Technology (GT), Cyber Security Technology (CST), Third Party Management, Global Compliance & Operational Risk (GCOR), internal audit, and external regulators; provide accurate and timely audit and regulatory responses.
Partner with security, technology, and business teams to design, implement, and scale identity and access controls supporting Frontier AI, machine identities, emerging digital capabilities, and next-generation governance frameworks.
Perform Quality Assurance (QA) activities to validate access control compliance, monitor control health, and support accurate and sustainable metrics reporting.
Monitor and support GT application adherence to IAM controls; manage governance programs, respond to program inquiries, maintain source-of-record updates, execute ARM ticket management, and ensure comprehensive program documentation.
Identify opportunities to de-risk IAM controls by analyzing current capabilities, detecting framework or process gaps, and recommending targeted enhancements aligned with enterprise security strategy.
Responsibilities:
Maintain high-quality QA documentation, audit artifacts, process workflows, and training materials to support transparency and repeatability.
Lead QA governance activities for End User Access Management and Application Services, ensuring alignment with IAM Standards and enterprise policies.
Manage and maintain exceptions to the IAM Standard, ensuring appropriate risk justification, approvals, and periodic recertification per governance protocols.
Ensure technology systems meet enterprise standards and fully comply with regulatory, legal, and risk requirements, escalating concerns as needed.
Support Software Development Life Cycle (SDLC) initiatives, including requirements validation, control testing, and providing risk-focused signoff for application changes prior to implementation.
Establish and maintain strong partnerships across GIS, Global Technology (GT), Cyber Security Technology (CST), Third Party Management, Global Compliance & Operational Risk (GCOR), internal audit, and external regulators; provide accurate and timely audit and regulatory responses.
Partner with security, technology, and business teams to design, implement, and scale identity and access controls supporting Frontier AI, machine identities, emerging digital capabilities, and next-generation governance frameworks.
Perform Quality Assurance (QA) activities to validate access control compliance, monitor control health, and support accurate and sustainable metrics reporting.
Required Qualifications:
5+ years of bank and finance industry hands-on experience in Identity Governance & Administration (IGA) or Identity and Access Management (IAM), managing identity lifecycle and associated enterprise initiatives.
5+ years implementing and governing IAM cloud solutions, controls, and capabilities.
High proficiency, experience and working knowledge of Active Directory, Entra ID (Azure AD), SailPoint, Ping Identity, and connector frameworks, other mainstream IAM products.
Experience supporting identity governance, authorization models, or access control frameworks for AI-enabled platforms, cloud-native services, emerging technologies, and large-scale digital transformation initiatives.
Familiarity with common Information security and data protection frameworks and standards.
Familiarity with Zero Trust architecture, FIDO2, and passwordless authentication concepts.
Proficiency in data analytics and reporting tools (SQL, Tableau, PowerBI) for compliance and risk metrics.
Strong ability to articulate data-driven insights and partner effectively with stakeholders to drive risk reduction and compliance with IAM Standards.
Advanced proficiency and analytical skills, data management and data analysis with strong attention to detail, and background in quality assurance.
Excellent problem-solving, documentation, and communication skills with the ability to work effectively across cross-functional teams.
This job will be open and accepting applications for a minimum of seven days from the date it was posted
Shift:
1st shift (United States of America)Hours Per Week:
40Pay Transparency details
US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - MA - Boston - 100 Federal St - 100 Federal St Lp (MA5100)Pay and benefits informationPay range$78,200.00 - $136,300.00 annualized salary, offers to be determined based on experience, education and skill set.Discretionary incentive eligibleThis role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.BenefitsThis role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.Skills Required
- 5+ years of hands-on banking and finance industry experience in Identity Governance and Administration or Identity and Access Management, including identity lifecycle management and enterprise initiatives
- 5+ years implementing and governing IAM cloud solutions, controls, and capabilities
- High proficiency and working experience with Active Directory, Entra ID or Azure AD, SailPoint, Ping Identity, connector frameworks, and other mainstream IAM products
- Experience supporting identity governance, authorization models, or access control frameworks for AI-enabled platforms, cloud-native services, emerging technologies, and large-scale digital transformation initiatives
- Familiarity with information security and data protection frameworks and standards
- Familiarity with Zero Trust architecture, FIDO2, and passwordless authentication concepts
- Proficiency with SQL, Tableau, and Power BI for compliance and risk metrics
- Strong ability to articulate data-driven insights and partner with stakeholders to drive risk reduction and IAM Standards compliance
- Advanced analytical, data management, data analysis, and quality assurance skills with strong attention to detail
- Excellent problem-solving, documentation, and communication skills; ability to work effectively across cross-functional teams
Bank of America Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Bank of America and has not been reviewed or approved by Bank of America.
-
Healthcare Strength — Health coverage is described as comprehensive, with medical, dental, vision, virtual care via Teladoc, wellness programs, and specialized support for cancer and menopause. Wellness credits and an always‑on EAP with in‑person sessions add to the depth of care.
-
Parental & Family Support — New parents can access up to 26 weeks of leave, including 16 weeks fully paid for eligible teammates, alongside back‑up child and adult care. Family‑building resources and reimbursements (e.g., fertility, adoption, surrogacy) and a dedicated Life Event Services team extend support across life stages.
-
Equity Value & Accessibility — Broad‑based equity through the Sharing Success program, including $1B in stock to nearly all non‑executive employees in January 2026, is intended to foster an ownership mindset. Stock awards (including RSUs) are a recurring component that aligns employees’ interests with shareholders.
Bank of America Insights
What We Do
We make financial lives better for our clients and our communities through the power of every connection. Our employees are at the heart of this purpose, and are key to driving responsible growth. Every day, across the globe, our employees bring a commitment to our purpose and to driving responsible growth by living our values: deliver together, act responsibly, realize the power of our people and trust the team. A key aspect of driving responsible growth is doing so in a sustainable manner, a critical pillar of which is being a great place to work for our teammates.
Gallery







