Senior Active Directory - Cloud Identity Specialist

Bank of America Corporation
Boston, MA

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.

Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates’ physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.

Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations.

At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

Summary:

We are seeking a Senior Directory Services analyst to modernize our enterprise identity platform across on‑prem Active Directory, LDAP’s, and other cloud-based directories and stores. The role is focused on securing employee, partner, and application access in a highly-regulated financial services environment and will partner closely with security, infrastructure, and application teams. If you are passionate about identity security and thrive in high-stakes environments, this role offers the chance to make a measurable impact on the security posture of a global enterprise.

Key Responsibilities:

  • Lead architecture, engineering, and operations for Active Directory forests, domains, and Group Policy in a multi-site, highly regulated environment.

  • Design and drive adoption of hybrid identity solutions integrating on‑prem and cloud-based services.

  • Implement and optimize authentication and authorization controls: SSO, MFA, Conditional Access, identity protection, and modern protocols (SAML, OAuth2, OIDC).

  • Define and enforce standards for identity lifecycle : joiner/mover/leaver processes, automated provisioning/deprovisioning, access reviews, and role-based access control (RBAC).

  • Partner with stakeholders and business teams to implement least-privilege, privileged access management (PAM), and Zero Trust-aligned identity controls.

  • Lead and support AD and identity-related projects : domain/forest consolidation, mergers/acquisitions, cloud migrations, and re-platforming.

  • Enhance monitoring, alerting, and reporting for directory and identity health, security posture, and compliance (audit trails, SOX, GLBA, PCI, etc.)

  • Develop and maintain scripts and automation (primarily PowerShell) to drive consistency, efficiency, and security in identity operations.

  • Serve as a senior SME and escalation point for complex identity incidents, outages, and security events.

  • Produce and maintain technical documentation , runbooks, standards, and architecture diagrams for AD and cloud identity services.

  • Mentor and guide junior engineers, analysts, and admins and contribute to identity and access strategy and roadmap.

Required Qualifications:

  • 10+ years of hands-on experience administering and engineering enterprise Active Directory in a large, multi-site environment.

  • Strong expertise in: AD forest/domain design, trusts, DNS, Group Policy, replication, and AD security hardening.

  • 5+ years working with Azure AD/Entra ID and hybrid identity (synchronization, federation, ADFS or equivalent, cloud-only and hybrid scenarios).

  • Deep understanding of identity and access management concepts: authentication, authorization, RBAC, least privilege, PAM, Zero Trust.

  • Strong experience with MFA, Conditional Access, SSO, and identity federation using SAML, OAuth2, and OpenID Connect.

  • Proficiency with PowerShell for automation, reporting, and bulk operations in AD and Azure AD.

  • Experience operating in regulated environments (preferably banking/financial services) with audit, risk, and compliance requirements.

  • Solid understanding of networking and security fundamentals (TCP/IP, firewalls, TLS, certificates, PKI as it relates to identity).

  • Excellent communication skills and ability to translate technical identity risks and solutions for non-technical stakeholders.

Desired Qualifications:

  • Experience with IAM platforms such as Okta, Ping, ForgeRock, SailPoint, or similar.

  • Experience with AWS IAM and/or GCP IAM and integrating them with corporate identity.

  • Background with PAM solutions (CyberArk, Delinea/Thycotic, BeyondTrust, Hashi, etc.).

  • Relevant certifications: Microsoft Certified: Identity and Access Administrator Associate, Azure Administrator, Security Engineer, or equivalent.

Shift:

1st shift (United States of America)

Hours Per Week:

40

Posted 2026-02-20

Recommended Jobs

Travel Nurse - OR - Operating Room Job in Boston, MA - $11,565 per Month (2 Years Experience Needed)

Vetted Health
Boston, MA

Vetted is seeking a RN - OR - Operating Room for a travel job in Boston, Massachusetts . Must have 2+ years of experience. This contract pays approximately $11,565/month gross. Assignment…

View Details
Posted 2026-02-22

Travel Nurse - NICU - Neonatal Intensive Care Job in Quincy, MA - $13,072 per Month (2 Years Experience Needed)

Vetted Health
Quincy, MA

Vetted is seeking a RN - NICU - Neonatal Intensive Care for a travel job in Quincy, Massachusetts . Must have 2+ years of experience. This contract pays approximately $13,072/month gross. …

View Details
Posted 2026-02-22

Financial Reporting Associate $100,000/yr

ProPivotal Staffing
Boston, MA

Financial Reporting Associate $100,000/yr We’re looking for a Financial Reporting Associate to join our growing team. This is an exciting opportunity for someone with 3-5 years of experience in pu…

View Details
Posted 2026-02-16

Homemaker - Cape Cod

Attentive Home Care
Eastham, MA

At Attentive Home Care, we strive to make every employee feel like family. Happy employees make happy clients. We reward individuals who are ready to work hard and stay motivated. Every employee at At…

View Details
Posted 2025-08-28

Seasonal Historical Interpreter

The Trustees of Reservations
Ipswich, MA

Who We Are: Founded in 1891 by a group of visionary volunteers, The Trustees of Reservations (The Trustees) is the nation’s premier conservation and preservation organization. The Trustees’ preser…

View Details
Posted 2026-01-14

Sales Director

Cogent Communications, Inc
Boston, MA

Company: Cogent Communications is a global, Tier 1 facilities-based ISP, consistently ranked as one of the top five networks in the world and is publicly traded on the NASDAQ Stock Market under the t…

View Details
Posted 2026-01-28

Maintenance Technician

West Bridgewater, MA

Aerotek is Hiring for Maintenance Technicians Job Description We are hiring someone who has a great attitude and is able to be a team player. As a Maintenance Technician you will be responsib…

View Details
Posted 2026-01-26

Physical Therapy Assistant - Per Diem (Ware)

Visiting Rehab and Nursing Services
Ware, MA

Description: Physical Therapy Assistant (PTA) – Ware | $37–$40 per visit | Flexible Schedule |**Must have 1 year clinical experience** USA Today Top Workplaces Winner 2024 & 2025 — still no bribes …

View Details
Posted 2026-02-19

Part Time Assistant Manager

Holyoke, MA

Description: #JOINTHEOASIS Who we are: Windsor Fashions is a leading special occasion and fast fashion retailer founded and operated by generations of the Zekaria family. We are committed to pr…

View Details
Posted 2025-10-16

Host

Kennedy's Restaurant & Market
Marlborough, MA

About Us: Opened in 1981, Kennedy’s Restaurant is a family-owned establishment based in the city of Marlboro, MA. Our family and business pride ourselves on incredible meals, outstanding service and…

View Details
Posted 2025-08-27