Bank of America
Sr. Business Information Security Officer
Bank of America, Charlotte, North Carolina, United States, 28245
Sr. Business Information Security Officer
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work is core to how we drive Responsible Growth, including our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates’ physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve. Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
The Information Security Officer will be a member of the Business Information Security Officer (BISO) organization and work closely with the line of business Front Line Units (FLU) / CIO executives. In this role, you will support a group/team to develop a deep understanding of the business in order to have specialized information security risk-based discussions. This relationship will ensure a focus on the right risk priorities. You will also provide guidance on information security topics, policies and controls.
Scale/Scope
Contribute to ongoing information security initiatives and improvements; development, implementation and maintenance of information security for FLU/Ops
Serve as an Information Security subject matter expert and participate in the development, implementation and maintenance of information security for FLU/Ops
Align to Fraud Authentication, Financial Center, and Automated Teller Machines channel segments to drive a security strategy and ensure appropriate security-by-design requirements execution
Provide guidance and advocacy regarding the prioritization of investments that impact information security
Advise management on risk issues related to information security and recommend actions in support of the bank's wider risk management and compliance programs
Monitor information security trends internal and external to the bank and keep leadership informed
Manage quality control and reporting
Ensure compliance with policies and laws
Required Skills
Information Security & Technology professional with 10+ years’ experience
7+ years of risk management experience with proven ability to effectively apply risk principles to challenging business situations
Subject matter expert in application security, vulnerability testing and development of risk appetite
Experience evaluating cyber security controls and providing guidance for platform or distributed computing platforms (Cloud, PaaS)
Experience evaluating third-party information security controls and providing guidance to reduce risk on identify observations
Experience with information security for NoSQL, Big Data, and unstructured data stores (Cassandra, Hadoop, and/or Teradata)
Knowledge in Windows, Midrange and Mainframe Platforms with emphasis on security application security controls
Exceptional executive presentation and communication skills
Excellent influencing and problem resolution skills
Advises LOB management on risk issues related to information security and recommends actions in support of the bank's wider risk management and compliance programs
Ability to deliver messages across a wide spectrum of individuals with varying degrees of technical understanding
Strong leadership skills to work with peers and various levels of management
Desired Skills
Bachelors and/or Master’s degree in Computer Science, Information Technology or related field
Experience working on cloud control assessment in Microsoft Azure, Amazon Web Services and Google Cloud Platform environments
Risk Management
Drives GIS/FLU/Ops risk deliverables
Collaborates with risk partners on information security critical priorities
Participates in senior FLU/Ops specific Risk Management & Business Continuity routines
Identifies and measures global information security (GIS) controls on the most critical business processes or channels
Leadership/Strategy
Build strong partner relationships with peer technology groups and supported FLU/Ops
Support the triage process with the client and help them understand the GIS support structure
Drive required risk culture and partnership with peer technology teams and supported FLU/Ops
Participate in key operating routines to drive information security risk strategy
Shift 1st shift (United States of America)
Hours Per Week 40
Seniority level
Executive
Employment type
Full-time
Job function
Other, Information Technology, and Management
Industries
Banking
#J-18808-Ljbffr
The Information Security Officer will be a member of the Business Information Security Officer (BISO) organization and work closely with the line of business Front Line Units (FLU) / CIO executives. In this role, you will support a group/team to develop a deep understanding of the business in order to have specialized information security risk-based discussions. This relationship will ensure a focus on the right risk priorities. You will also provide guidance on information security topics, policies and controls.
Scale/Scope
Contribute to ongoing information security initiatives and improvements; development, implementation and maintenance of information security for FLU/Ops
Serve as an Information Security subject matter expert and participate in the development, implementation and maintenance of information security for FLU/Ops
Align to Fraud Authentication, Financial Center, and Automated Teller Machines channel segments to drive a security strategy and ensure appropriate security-by-design requirements execution
Provide guidance and advocacy regarding the prioritization of investments that impact information security
Advise management on risk issues related to information security and recommend actions in support of the bank's wider risk management and compliance programs
Monitor information security trends internal and external to the bank and keep leadership informed
Manage quality control and reporting
Ensure compliance with policies and laws
Required Skills
Information Security & Technology professional with 10+ years’ experience
7+ years of risk management experience with proven ability to effectively apply risk principles to challenging business situations
Subject matter expert in application security, vulnerability testing and development of risk appetite
Experience evaluating cyber security controls and providing guidance for platform or distributed computing platforms (Cloud, PaaS)
Experience evaluating third-party information security controls and providing guidance to reduce risk on identify observations
Experience with information security for NoSQL, Big Data, and unstructured data stores (Cassandra, Hadoop, and/or Teradata)
Knowledge in Windows, Midrange and Mainframe Platforms with emphasis on security application security controls
Exceptional executive presentation and communication skills
Excellent influencing and problem resolution skills
Advises LOB management on risk issues related to information security and recommends actions in support of the bank's wider risk management and compliance programs
Ability to deliver messages across a wide spectrum of individuals with varying degrees of technical understanding
Strong leadership skills to work with peers and various levels of management
Desired Skills
Bachelors and/or Master’s degree in Computer Science, Information Technology or related field
Experience working on cloud control assessment in Microsoft Azure, Amazon Web Services and Google Cloud Platform environments
Risk Management
Drives GIS/FLU/Ops risk deliverables
Collaborates with risk partners on information security critical priorities
Participates in senior FLU/Ops specific Risk Management & Business Continuity routines
Identifies and measures global information security (GIS) controls on the most critical business processes or channels
Leadership/Strategy
Build strong partner relationships with peer technology groups and supported FLU/Ops
Support the triage process with the client and help them understand the GIS support structure
Drive required risk culture and partnership with peer technology teams and supported FLU/Ops
Participate in key operating routines to drive information security risk strategy
Shift 1st shift (United States of America)
Hours Per Week 40
Seniority level
Executive
Employment type
Full-time
Job function
Other, Information Technology, and Management
Industries
Banking
#J-18808-Ljbffr