Back to search results

Information Security Identity and Access Management (IAM) Architect

Denver, Colorado;

Job Description:

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day.

One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world. We’re devoted to being a diverse and inclusive workplace for everyone. We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well-being.

Bank of America believes both in the importance of working together and offering flexibility to our employees. We use a multi-faceted approach for flexibility, depending on the various roles in our organization.

Working at Bank of America will give you a great career with opportunities to learn, grow and make an impact, along with the power to make a difference. Join us!

Job Description:
This job is responsible for defining an architectural vision and solution that supports the strategic outcomes of the Business' Products and Services. Key responsibilities include defining the target operating environment, designing for client resiliency, assisting with solution design, and defining non-functional requirements. Job expectations include working with stakeholders and service providers aligned to the Business' strategic objectives, evaluating the impact of strategic design decisions, and contributing to the architecture roadmap.

LOB Overview:

Global Information Security (GIS) is responsible for protecting bank information systems, confidential and proprietary data, and customer information. GIS develops the bank’s Information Security strategy and policy, manages the Information Security program, identifies and addresses vulnerabilities and operates a global security operations center that monitors, detects and responds to cybersecurity incidents. Within GIS, Identity and Access Management (IAM) is a security discipline that enables the right individuals to access the right resources at the right times and in the right context. IAM addresses the mission-critical need to ensure appropriate access to the resources across increasingly heterogeneous technology environments, and to meet increasingly rigorous compliance requirements

Role Description:

Experienced Identity and Access Management (IAM) Architect will drive the strategy, planning, design, communication, and execution for the organization. The initiatives in the IAM space are large projects focused on the transformation of IAM as a business and the reduction of identity and access risk for the Bank. The person in this role will provide leadership by working closely with the operations, product, architecture and engineering teams, project managers, and analysts, partnering with stakeholders across the LOBs, and GIS leadership. The candidate for this role possesses in-depth identity management subject matter expertise and provides operational, technical, and project leadership. Overall, the individual in this role will provide direction to support the planning, development, organization, monitoring, and delivery of the IAM solutions and services.

  • Create and continuously curate the IAM strategic roadmap by ensuring that small, medium, and large projects align to the vision of how IAM should enforce enterprise controls that combine good user experience and outstanding security.

  • Assist with the requirements, development, and maintenance of the entire IAM platform solution. Oversee and provide architecture requirements for all aspects of the SDLC and drive the strategic roadmap by articulating both business and technical requirements.

  • Provide technical expertise covering the various Identity, Authentication, and Governance components across the enterprise solution.

  • Serve as Subject Matter Expert for the operational requirements, products, solutions, and capabilities that comprise our capability model.

  • Support the team members by providing technical guidance on architecture decisions as well as assist other on-going engagements for resolving critical issues.

  • Lead design and implementation of complex enhancements or onboard/integrate new applications

  • Work with technology vendors on strategic road mapping, resolving product issues, technology evaluations, and design reviews

  • Capture and translate new requirements into operational and engineering goals.

  • Lead and participate in continuous improvement initiatives, identify ways to improve delivery by introducing technology innovations or processes or re-engineering to increase efficiencies of the team

  • Meet demands of managing multiple work streams, communicating effectively with senior technology and business leadership, and demonstrate experience leading large and complex projects and global programs.

  • Assess and advise on modernizing IAM capabilities and methodologies and project management implications throughout projects' timelines, including development of strategies, readiness assessment, development of training and communications.

  • Operate as an advisor for our distributed IAM teams to help them to elect the best solution for resolving the identified / possible technical issues or security threats in the system / infrastructure.

  • Harness familiarity with IT security and risk management practices to solve IAM problems.

  • Articulate technical and business issues and solutions effectively to business or technical staff across organizational layers

Required Qualifications

  • 10+ years experience in IAM working on complex projects and programs

  • Strong interpersonal and influencing skills

  • Excellent organizational skills, able to manage multiple work streams simultaneously and respond to rapidly changing demands

  • Demonstrated experience working with frequently-utilized IAM vendor solutions such as SailPoint, Savyint, ForgeRock, Ping, Okta, Varonis, and CyberArk in large enterprises for the purpose of governing security.

  • Experience in configuring and deployment of Single Sign On and MFA solutions, IGA solutions, and PAM Solutions

  • Hands-on on WAM products and particularly on Ping suite of products (Ping Access, Ping Federate and PingID) and federation concepts

Desired Qualifications

  • Good knowledge of Web / Application servers (e.g. IIS, WebSphere, WebLogic, JBoss, and Apache etc.)

  • Strong technical knowledge of authentication and authorization including Authz and Authn, OIDC, SAML, XACML, LDAP, OAuth, OpenID

  • Experience working on various operating systems such as Windows, Linux, Solaris etc.

  • Working knowledge on Databases such as MS SQL, Oracle, mySQL

  • Good understanding or hands-on experience on JSON, REST and SOAP

  • Advanced knowledge of cloud platforms (AWS, Azure, GCP etc.) experience in deploying and managing AM solutions on cloud platforms. AWS is preferred

  • Deep knowledge and experience working with technology infrastructure including Windows, Active Directory, LDAP, Unix/Linux, databases, authentication protocols, and containers

This job will be open and accepting applications for a minimum of seven days from the date it was posted.


1st shift (United States of America)

Hours Per Week: 


Learn more about this role

Full time


Manages People: No

Travel: No

Colorado pay and benefits information

Colorado pay range:

$134,500 - $200,000 annualized salary, offers to be determined based on experience, education and skill set.

Discretionary incentive eligible

This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.


This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.