Expoint - all jobs in one place

המקום בו המומחים והחברות הטובות ביותר נפגשים

Limitless High-tech career opportunities - Expoint

Bank Of America PAM Analyst - Info Security Threat Mgmt Specialist 
United States, Colorado, Denver 
776267814

25.06.2024

Job Description:

Job Description:

This role is primarily responsible for ensuring that relevant Privileged Access Controls are adequately enforced across platforms and applications to comply with IAM Standard. This individual will partner with PAM Governance leads to ensure that Privileged Access Controls are appropriately measured, reported and governed.

Responsibilities:

  • Apply industry PAM best practices, templates, and documentation while also proposing improvements based on practical knowledge.
  • Document and convey PAM related requirements to technology partners to build/implement enhanced PAM solutions that are efficient, effective, and modern and able to result in material risk reduction in sustainable manner.
  • Collaborate with stakeholders to develop PAM requirements that iteratively support long term PAM modernization and transformation (covers Process, Data and Technology aspects).
  • Provide education to team members and technology partners regarding the proposed changes to PAM controls.
  • Partners with the policy governance team for socialization and publication of proposed changes to the PAM Standard
  • Takes accountability for addressing PAM risks. Proactively identify risk and ways to continuously enhance and improve BAC’s PAM controls. Implement and take decisive actions in finding solutions. Drives towards intended outcomes.
  • Engage senior management to provide factual, transparent, and timely reporting on existing and emerging PAM or information security risks.
  • Active participation in GIS IAM/PAM forums including but not limited to Monthly IAM Stakeholder Forum and Control Owner Forum for standard and Single Process Inventory (SPI) enhancements.
  • Supports audit issues for closure and sustainability

Required Skills and Qualifications:

  • Good knowledge and understanding of PAM-specific laws, rules, and regulations within the financial services sector.
  • Understanding and interpreting BAC’s established information security Policy, Standards, Procedure and Guides, and applying this knowledge to related PAM decisions and response. Serve as the Subject Matter Experts in advising BAC business and technology counterparts on effective ways to achieve or exceed compliance with applicable Policy, Standards, Procedures and Guides. Familiarity with security standards such as NIST, ISO/EC, FFIEC.
  • Possession of CISSP certification would be an advantage.
  • Expert level knowledge of privileged access management methodologies and techniques for on-prem and Cloud implementation.
  • Expert knowledge of PAM related tools which support session proxy, vaulting, just-in-time provision, integration with service management tool would be an advantage.
  • Bachelor’s Degree or equivalent work experience
  • 7 years relevant hands-on experience in PAM in complex and heterogenous technology environment.
  • Deep security knowledge which covers core technology infrastructure (network, storage, servers, databases, etc.) identity management and application security practice.
  • Deep experience with Linux, Windows, Cloud scale Identity, Access Management (Single Sign-On, Multi Factor Authentication), Authorization services or design and architecture of PAM services
  • Experience with CyberArk, PowerBroker, Hashi and/or other PAM solutions
  • Expert level knowledge of authentication platforms such as Active Directory, LDAP, Kerberos, LDAP, Radius.
  • Deep knowledge on Federation platforms or protocols such as Oauth, OpenID, SAML, WS-Fed, etc.
  • Working level experience with IAM platforms such as Ping Identity, Active Directory OpenLDAP, OpenDJ
  • Experience in consumption of Web Service APIs such as JSON / XML
  • Proficient in articulating facts and data-driven plans and to partner with stakeholders to implement intended solutions to drive risk reductions and adherence to PAM standards.
  • Strong attention to detail and advanced analytical skills.
  • Excellent communication and presentation skills. Able to effectively prioritize multiple tasks.
  • Hands on experience and involvement in large and complex projects.
  • Proven track record in delivering outcomes that result in sustainable risk reductions in PAM.
  • Proficient in Microsoft Office suite of products with ability to quickly analyze and synthesize large volumes of data.
  • Ability to work independently on initiatives with little oversight. Motivated and willing to learn.
  • Confident and effective in delivering messages across a wide spectrum of individuals with varying degrees of technical and business understanding
  • Deep knowledge of bank financial practices and policies and ability to adapt to fast changing environment
  • Knowledge of Compliance Certifications such as SOX, SOC, SOC2.

This job will be open and accepting applications for a minimum of seven days from the date it was posted.

Enterprise Role Overview:

This job is responsible for supporting evaluations of cyber security threats and updating defensive capabilities to reduce the bank's risk of exposure. Key responsibilities include conducting analyses of the threat environment and threats to the bank, including post incident analysis, applying a multi-faceted situational awareness of cyber security processes to protect against threats, and implementing proactive defensive actions for the security, continuity, and confidentiality of information.

1st shift (United States of America)