Logo
Bank of America

Information Security Officer

Bank of America, Chicago, Illinois, United States, 60290

Save Job

Overview

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. Join us to build a successful career with opportunities to learn, grow, and make an impact. Position Summary

The Business Information Security Officer (BISO) will be a functional member of the Business Information Security Officer’s (BISO) organization and work closely with the Consumer, Small Business and Wealth Technology (CBWT) Chief Information Officers (CIOs)/Technology teams to develop a strong understanding of the business in order to have specialized information security risk-based discussions. This relationship will ensure a focus on the right risk priorities. The BISO will also act as the day-to-day point of contact providing guidance on information security topics, policies, and controls; ultimately, the BISO will become a trusted advisor to our stakeholders. The role serves as a subject matter expert on the development, implementation, and maintenance of information security for the line of business (LOB). The BISO provides guidance and advocacy regarding the prioritization of LOB investments and the impact on information security. The BISO advises LOB management on risk issues related to information security and recommends actions in support of the bank’s wider risk management and compliance programs. Minimum Experience

Minimum Years of Experience - 5 Required Qualifications

Experience within an information security technology operational, engineering or consulting team with good knowledge of the security controls and processes required within systems and networks Strong interpersonal skills to be able to communicate, influence and negotiate with senior stakeholders to obtain or leverage necessary resources Desired Qualifications

Bank Operations experience helpful, but not required Experience within a technology and financial organization at a mid-level to senior level with good knowledge of Application Security controls and risks Understanding of the concepts of vulnerability management and associated monitoring solutions and practices Experience of formal security risk assessment methodologies In depth technical level of understanding of Technology Infrastructure operations, showing a strong understanding of relevant subject matters Previous experience working within a financial institution Ability to initiate own work priorities and manage a portfolio independently Good communicator able to deliver difficult messages and resolve issues with stakeholders Show ability to work as part of integral team Excellent oral and written briefing skills with the ability to produce and present management progress and status reports Job Description

This job is responsible for supporting Line of Business leaders by balancing the needs of the business while ensuring information security risk is appropriately identified and managed to drive uncompromising cyber security protection. Key responsibilities include applying an understanding of the business and engaging with technology partners, business partners, and Global Information Security teams to provide blended security and business expertise to ensure appropriate management of information security risks. Responsibilities

Assists business leaders and technology teams by supporting initiatives requiring Global Information Security (GIS) engagement and facilitating problem resolution for cyber security related issues Serves as a common risk control partner in order to identify emerging security risks in the portfolio Drives adherence to appropriate risk tolerance levels, operating in accordance with defined information security policies to protect against threats to data confidentiality, integrity, and availability Promotes awareness of current and emerging cybersecurity threats and advises on potential information security exposure Assesses and mitigates cyber security risks related to application, network, infrastructure, and public cloud Interprets the information security requirements outlined in policies, standards, and procedures and reinforces requirements through education and awareness Supports teammates who serve as “security ambassadors” in order to help partners drive strategic and innovative risk mitigation priorities and navigate the GIS organization Skills

Controls Management Cyber Security Data Governance Information Systems Management Risk Management Architecture Customer and Client Focus Executive Presence Threat Analysis Vendor Management Advisory Business Acumen Business Intelligence Cloud Solutions Technology System Assessment Shift

1st shift (United States of America) Hours Per Week

40 Pay Transparency details

US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540), US - NJ - Jersey City - 101 Hudson St - 101 Hudson (NJ2101) Pay and benefits information: Pay range $99,200.00 - $145,100.00 annualized salary, offers to be determined based on experience, education and skill set. Discretionary incentive eligible. This role is eligible to participate in the annual discretionary plan. Benefits: This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.

#J-18808-Ljbffr