IAM and Physical Security Senior Vice President
14 hours ago
New York
Role Overview This dual role is based in CIB US and reports to the Head of Corporate Security in the US. It combines leadership of Identity and Access Management (IAM) with oversight of Physical Security strategy across BBVA CIB USA operations. Identity and Access Management (IAM) The IAM Senior Manager is responsible for defining, establishing, maintaining, and governing identities and access across the organization. This includes assessing business access requirements and ensuring that access to systems and applications is provisioned, maintained, and revoked in accordance with robust security principles, engineering standards, and corporate governance frameworks. The role works closely with IT, cybersecurity operations and incident response, business units, and third-party partners. It drives identity provisioning, access governance, and the implementation of Single Sign-On (SSO) and Multi-Factor Authentication (MFA), ensuring alignment with corporate standards for user and privileged access. Physical Security In parallel, the role sets the strategy and drives execution of a risk-based physical security program for BBVA CIB USA across offices in New York, Houston, and Miami. As BBVA operates as a tenant, this responsibility is delivered through strong coordination with building management and external security providers, ensuring the protection of people, facilities, and material nonpublic information (MNPI), while supporting business operations in trading floors and other mission-critical environments. Responsibilities include defining policies, governance, and technology decisions; leading incident preparedness and response; and overseeing coordination with landlord-managed guard services and other third-party providers. The role ensures transparent reporting to senior management and relevant Security and Risk Committees. Performance will be measured through risk reduction, system reliability, operational excellence, and regulatory readiness, including: • Incident rate reduction, • Effective security coverage through third-party providers, • Premises and building uptime, • Credential issuance SLAs, • Audit action closure Leadership & Strategic Alignment This role requires a strong risk management strategist profile, with a deep understanding of physical security, identity security, business operations, and the evolving threat landscape across both physical and digital domains. It acts as a key liaison across identity security, physical security, business continuity, and regulatory compliance, in close coordination with cybersecurity, IT, risk management, and external stakeholders such as building management. Identity and Access Management Duties • Lead the implementation of Corporate Governance for User Access Management across all business systems within the scope of BBVA CIB US., • Drive the implementation of the Privileged Access Management (PAM) program, ensuring full alignment with corporate governance standards for the management of privileged access., • Act as a key liaison between local engineering teams and the CIB Corporate Identity Security function, including the Profiling Office, RPA, and Authorizations units., • Lead and develop the IAM function across governance, policies, and technology solutions, including Single Sign-On (SSO), directories, certificates, Multi-Factor Authentication (MFA), and privileged account management., • Oversee periodic access reviews and certification processes to ensure appropriate access to business systems and unstructured data., • Manage user access across internal systems and external entities, coordinating with local and global security and IT operations to ensure effective end-to-end access lifecycle management (provisioning, modification, and deprovisioning)., • Deliver IAM projects on time and within budget, ensuring alignment with business and security objectives., • Implement authentication, authorization, and federation capabilities with the BBVA Identity Provider to enable seamless SSO and MFA across business systems., • Partner with business units to understand access requirements and provide IAM solutions that align with operational needs and security standards., • Lead the adoption and implementation of BBVA corporate Key Management policies, procedures, and governance frameworks across BBVA CIB US., • Define and enforce roles, responsibilities, and separation of duties for key custodians, approvers, and operational teams consistent with corporate governance., • Establish and maintain formal key lifecycle processes (generation, distribution, storage, rotation, revocation, backup/escrow, compromise handling, and secure destruction) that adhere to corporate requirements., • Maintain an authoritative inventory and classification of cryptographic keys and certificates for CIB US, applying corporate classification, retention and protection rules. Strategy & Governance • Define the enterprise physical security strategy, standards, and policies aligned to business risk, • Maintain a multi-year maturity roadmap, KPIs, and quarterly reporting to leadership and the Risk Committee., • Develop and maintain comprehensive emergency response plans for a wide range of scenarios. This includes conducting regular drills and training staff to ensure a quick and orderly response. Establish emergency response protocols for fires, evacuations, physical threats, or violent attacks. Incident Response & Resilience • Perform site risk assessments and reviews; prioritize mitigations., • Work with HR and Legal to run threat intel, workplace violence, and insider risk playbooks., • Guaranty the protection of MNPI in restricted areas via zoning and enhanced controls., • Lead 24×7 operations control; oversee CCTV/VMS, alarms, visitor management, badging and keys/locks., • Implement and oversee access control systems, including biometric technology and the CCTV surveillance network.. Supervise the protection of critical facilities, including server rooms, sensitive records, and restricted areas. Design and implement office security plans covering access controls, CCTV surveillance, visitor management, and intrusion prevention measures., • Implement mailroom screening, restricted areas, event security, executive protection by risk, and travel security., • Coordinate with landlords to enforce building standards and post orders. Work closely with building administration to align the firm’s security protocols with those of the property, including evacuation plans, fire drills, and response to external threats., • Train employees in basic protocols: access control, physical data security, emergency response behavior, and conduct regular evacuation drills and response plan trainings, • Integrate with BCP/DR; conduct after-action reviews and remediate findings. Audit • Ensure adherence to the BBVA Security guidelines, and applicable building/occupancy codes., • Coordinate internal/external audits and address sector-specific regulatory expectations. Investigation and Liaison with Law Enforcement • Stay ahead of potential threats by actively monitoring criminal, terrorist, or activist risks that could impact the firm. Provide periodic reports to the Risk Committee or senior management on incidents, vulnerabilities, and required improvements., • Internal Investigations: Coordinate with the compliance function to ensure that security measures align with international and regulatory standards, and lead or supervise investigations into security incidents such as thefts, threats, or policy violations., • Liaison with Security Agencies: Serve as the primary point of contact with local, state, and federal security agencies, including the New York Police Department (NYPD) and the FBI. This relationship is critical for information sharing and coordinated response during emergencies. Coordinate as well with private security vendors and local authorities (NYPD, FBI in the case of major risks). Qualifications and Experience • 7+ years related experience, • 3+ leading multi-site programs in the U.S., • Experience in security administration, with 3-plus years’ technical hands-on IAM practitioner., • Experience administering IAM systems and access controls aligning with security governance fundamentals, • Financial services or mission-critical environment experience., • Proficiency with Security system design, business continuity, vendor management, and metrics., • Strong written and oral communication skills across varying levels of the organization., • Demonstrated experience in analysis of risks/intelligence/threats, • Demonstrated experience in coordinating operations and interchange of information with public institutions, such Police, Defense, international Intelligence Agencies, • Familiar with one or more regulatory requirements and laws such as, but not limited to, 23 NYCRR part 500, FFIEC, SOX, GDPR, CCPA, Regulation S-P, GLBA . Additionally, experience in one or more of the following is required: ISO 27001, NIST CSF, or the AI Risk Management Framework., • Languages : English , Spanish a plus Certification Requirements • Preferred certifications as Director/Deputy/Responsible of Security or equivalent certifications, • One or more of the following is preferred but not required : CPP , CISSP , CISM All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. With respect to this position in our New York Office, the expected base salary ranges from $180,000 to $195,000. It is not typical for offers to be made at or near the top of the range. Salary offers are based on a wide range of factors including relevant skills, training, experience, education, and, where applicable, certifications obtained. Market and organizational factors are also considered. In addition to salary and a generous employee benefits package, successful candidates are eligible to receive a discretionary bonus. *Employment eligibility to work with BBVA in the U.S. is required as the company will not pursue visa sponsorship for these positions