Bank of America logo

Identity, Authentication, Authorization & Governance (IAM) Sr. Security Specialist (Leadership experience required)

Bank of America

Chicago, ILJobSeen todaySeen in employer's feed today

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
No compensation found
Location
Chicago, IL
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

The IAM Senior Security Specialist sits within Global Information Security and shapes enterprise governance of human, machine, and service identities. The role partners with senior stakeholders across technology, risk, compliance, and audit to strengthen authentication and authorization controls as cloud and digital growth evolve. It is presented as an opportunity for an internal candidate to broaden their impact and contribute to the bank’s security agenda.

Skills & qualifications

RequiredNice to have

Skills

Enterprise IAM TransformationOAuth 2.0OpenID ConnectSAMLService-to-Service AccessToken-Based AuthenticationCloud Identity GovernanceSaaS Identity GovernanceAPI Identity GovernanceApplication Identity GovernanceHybrid Identity GovernanceHuman Identity RiskNon-Human Identity RiskWorkload Identity RiskService Identity RiskMachine Identity RiskAI-Agent Identity RiskDelegated AuthorityIdentity Lifecycle AccountabilityRegulatory Identity ControlsNISTISOFFIECSOXSOCExecutive AdvisingExecutive BriefingWritten CommunicationVerbal CommunicationAnalytical Decision-MakingPrioritizationCross-Functional Alignment

Qualifications

10+ Years IAM or Security ExperienceLeadership ExperienceAt Least 18 Years Old

Benefits

Medical Insurance

Full job description

Identity, Authentication, Authorization & Governance (IAM) Sr. Security Specialist (Leadership experience required)

Washington, District of Columbia;Boston, Massachusetts; Chicago, Illinois

To proceed with your application, you must be at least 18 years of age.

Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Washington/Identity--Authentication--Authorization---Governance--IAM--Sr-Security-Specialist--Leadership-experience-required-\_26036653-2)

Bank of America employees are required to meet all posting eligibility requirements prior to applying for any new position.

Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Washington/Identity--Authentication--Authorization---Governance--IAM--Sr-Security-Specialist--Leadership-experience-required-\_26036653-2)

Refer a friend

To proceed with your application, you must be at least 18 years of age.

Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Washington/Identity--Authentication--Authorization---Governance--IAM--Sr-Security-Specialist--Leadership-experience-required-\_26036653-2)

Bank of America employees are required to meet all posting eligibility requirements prior to applying for any new position.

Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Washington/Identity--Authentication--Authorization---Governance--IAM--Sr-Security-Specialist--Leadership-experience-required-\_26036653-2)

Job Description:

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.

Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.

We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.

Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

Role Description:

The IAM Identity, Authentication, Authorization & Governance Senior Security Specialist sits within Global Information Security (GIS) and plays a highly visible role in shaping how human, machine, and service identities are governed across the enterprise. This role offers the opportunity to influence strategic security priorities, partner with senior stakeholders across technology, risk, compliance, and audit, and help strengthen how authentication and authorization controls evolve to support cloud and digital growth. It is an excellent opportunity for an internal candidate looking to broaden their impact, build enterprise-wide relationships, and contribute to a critical and evolving security agenda.

Responsibilities:

Risk Management, Governance & Compliance

  • Establish IAM control requirements, governance measures, and escalation paths in partnership with risk and control organizations.

  • Translate internal policy, regulatory, and audit requirements into practical, sustainable controls across enterprise platforms and processes.

  • Drive remediation of identity risks and control gaps across business and technology organizations, escalating risk acceptance decisions as appropriate.

  • Provide executive-level reporting and recommendations on identity risk, control health, adoption, exceptions, and remediation progress.

  • Support audit readiness and sustainable issue closure through clear accountability, evidence, metrics, and ongoing control monitoring.

Collaboration & Influence

  • Build trusted partnerships across GIS, Core Technology, Application Development, Risk, Compliance, Audit, and Third-Party Management.

  • Advise and influence senior leaders on complex identity, technology, security, and risk matters, including strategic options and trade-offs.

  • Drive cross-functional alignment, ownership, and adoption across teams operating at different speeds and maturity levels.

  • Translate complex technical and risk concepts into clear executive recommendations, decisions, and measurable outcomes.

Enterprise IAM Strategy, Architecture & Access Controls

  • Define enterprise business requirements, strategic direction, and standards for authentication, authorization, and identity governance.

  • Establish governance for human, non-human, workload, service, and AI-agent identities, including ownership, lifecycle management, delegated authority, credential rotation and revocation, and human accountability.

  • Set enterprise standards for API authentication and authorization, service-to-service access, token-based controls, and consistent secure identity patterns.

  • Drive adoption of zero trust, least privilege, phishing-resistant and passwordless authentication, continuous access evaluation, and fine-grained, context-aware authorization.

  • Advance policy-as-code, automated control enforcement, and identity threat detection to improve control consistency and reduce manual risk.

  • Embed IAM requirements into application, platform, API, cloud, and AI solution design and development lifecycles.

  • Influence investment priorities and modernization roadmaps that reduce standing privilege, unmanaged identities, inconsistent access patterns, and control gaps.

  • Define measures of adoption, control health, identity risk, and remediation progress, and use results to drive accountable outcomes.

Required Qualifications:

  • 10+ years of experience in identity and access management, cybersecurity, cloud security, or access management within large, complex organizations.

  • Leadership experience required

  • Demonstrated success setting direction for or influencing enterprise-scale IAM transformation, modernization, governance, or control programs.

  • Deep knowledge of modern authentication, federation, and authorization standards and patterns, including OAuth 2.0, OpenID Connect, SAML, service-to-service access, and token-based authentication.

  • Experience governing identity and access across cloud, SaaS, API, application, and hybrid environments.

  • Strong understanding of human and non-human identity risk, including workload, service, machine, and AI-agent identities, delegated authority, and lifecycle accountability.

  • Experience translating policy, regulatory, and audit requirements into practical identity controls within regulated environments.

  • Knowledge of relevant standards and frameworks, including NIST, ISO, FFIEC, SOX, SOC, or equivalent.

  • Demonstrated ability to advise, brief, and influence senior leaders on complex technology, security, and risk matters.

  • Exceptional written and verbal communication skills, with experience translating complex concepts into clear executive-level presentations and recommendations.

  • Strong judgment and analytical decision-making skills, with the ability to operate effectively in ambiguous and rapidly evolving environments.

  • Proven ability to prioritize competing demands, drive cross-functional alignment, and deliver measurable outcomes.

Desired Qualifications:

  • Experience in financial services, banking, or another highly regulated industry.

  • Knowledge of RBAC, ABAC, PBAC, segregation of duties, just-in-time access, runtime authorization, and cloud entitlement management.

  • Experience with identity platforms such as Active Directory, Microsoft Entra ID, Ping, or equivalent technologies.

  • Experience with identity analytics, automation, policy-as-code, AI-enabled security solutions, or workflow optimization.

  • Familiarity with scripting and analytics tools such as Python, R, SQL, Splunk, Tableau, Power BI, Microsoft Copilot Studio, Power Automate, or equivalent.

  • Experience with cloud security, infrastructure, microsegmentation, monitoring, infrastructure-as-code, or related technologies.

  • Industry certification such as CISSP, CCSP, CRISC, CISM, or equivalent.

Shift:

1st shift (United States of America)

Hours Per Week:

40

Bank of America and its affiliates consider for employment and hire qualified candidates without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity, in accordance with all applicable federal, state, provincial and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our teammates.

View your "Know your Rights (https://www.eeoc.gov/sites/default/files/2023-06/22-088\_EEOC\_KnowYourRights6.12.pdf) " poster.

View the LA County Fair Chance Ordinance (https://dcba.lacounty.gov/wp-content/uploads/2024/08/FCOE-Official-Notice-Eng-Final-8.30.2024.pdf) .

Bank of America aims to create a workplace free from the dangers and resulting consequences of illegal and illicit drug use and alcohol abuse. Our Drug-Free Workplace and Alcohol Policy (“Policy”) establishes requirements to prevent the presence or use of illegal or illicit drugs or unauthorized alcohol on Bank of America premises and to provide a safe work environment.

Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. Should you be offered a role with Bank of America, your hiring manager will provide you with information on the in-office expectations associated with your role. These expectations are subject to change at any time and at the sole discretion of the Company. To the extent you have a disability or sincerely held religious belief for which you believe you need a reasonable accommodation from this requirement, you must seek an accommodation through the Bank’s required accommodation request process before your first day of work.

This communication provides information about certain Bank of America benefits. Receipt of this document does not automatically entitle you to benefits offered by Bank of America. Every effort has been made to ensure the accuracy of this communication. However, if there are discrepancies between this communication and the official plan documents, the plan documents will always govern. Bank of America retains the discretion to interpret the terms or language used in any of its communications according to the provisions contained in the plan documents. Bank of America also reserves the right to amend or terminate any benefit plan in its sole discretion at any time for any reason.

Investment products offered through MLPF&S and insurance and annuity products offered through MLLA:

Are Not FDIC Insured Are Not Bank Guaranteed May Lose Value

Are Not Deposits Are Not Insured by Any Federal Government Agency Are not a condition to Any Banking Service or Activity

Merrill Lynch, Pierce, Fenner & Smith Incorporated (also referred to as “MLPF&S” or “Merrill”) makes available certain investment products sponsored, managed, distributed or provided by companies that are affiliates of Bank of America Corporation (“BofA Corp.”). MLPF&S is a registered broker-dealer, registered investment adviser, Member SIPC and a wholly owned subsidiary of BofA Corp. Insurance and annuity products are offered through Merrill Lynch Life Agency Inc., a licensed insurance agency and wholly owned subsidiary of Bank of America Corporation.

Trust, fiduciary and investment management services are provided by Bank of America, N.A., Member FDIC and wholly owned subsidiary of Bank of America Corporation (“BofA Corp.”).

Bank of America Private Bank is a division of Bank of America, N.A.

Banking products are provided by Bank of America, N.A. and affiliated banks, Members FDIC and wholly owned subsidiaries of Bank of America Corporation.

© 2026 Bank of America Corporation. All rights reserved.

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.