Hiring.Camp

Info Security Manager

Ghr

·

Today

Location
Mumbai, India
Workplace
Onsite
Type
Full-time
Department
Security
Seniority
Manager
Experience
8+ years
Source
Workday

Description

Job Description:




About us

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.

Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.

We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.

Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.

At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

Global Business Services

Global Business Services delivers Technology and Operations capabilities to Lines of Business and Staff Support Functions of Bank of America through a centrally managed, globally integrated delivery model and globally resilient operations.

Global Business Services is recognized for flawless execution, sound risk management, operational resiliency, operational excellence and innovation.

In India, we are present in five locations and operate as BA Continuum India Private Limited (BACI), a non-banking subsidiary of Bank of America Corporation and the operating company for India operations of Global Business Services.


Process Overview

The Global Information Security (GIS) is responsible for protecting Bank information systems, confidential and proprietary data, and customer information. The team develops the Bank’s Information Security strategy and policy, manages the Information Security program, and identifies and addresses vulnerabilities, Develops, deploys and manages a risk-based controls portfolio, Manages and operates global security operations center that monitor, detects and responds to cybersecurity incidents.

GIS Identity & Access management (IAM) Access Control Team goal is to ensure that the control processes and effectiveness are within the identified risk tolerance.  Manage the performance and effectiveness of the working control through the establishment of metrics with thresholds. Validate the reasonability of Laws, Rules and Regulations mapping alignment to the controls, as aligned by the GIS Policy team.


Job Description

In support of the Cloud Security program and the delivery of an operational framework, the role requires hands-on knowledge and experience with the policies, tools, configurations, and rules needed to deploy solutions that manage the security of cloud platforms and reduce risk to bank workloads in the cloud.

 

The role supports the strategy, architecture, and roadmap for IAM controls in cloud environments and help drive implementation of the designed control environment. This includes developing cloud IAM requirements based on threat models, laws, rules, and regulations, driving related updates to Policy, Standards, and Baselines, and assessing operational readiness of process and technical capabilities to implement the required controls.

 

The successful analyst is result-oriented and business-focused, and succeeds at interfacing across multiple organizational units at various levels.


Responsibilities

  • Ensure IAM technology and controls for cloud are implemented, monitored, and adhered to established IAM standards.
  • Achieve intended cloud IAM outcomes through the development and enhancement of applicable standards, processes, data elements, oversight, and governance for the bank’s cloud infrastructure, systems, and applications.
  • Develop cloud IAM requirements based on threat models, laws, rules, and regulations, and drive related updates to Policy, Standards, and Baselines.
  • Assess operational readiness of process and technical capabilities to implement required controls; determine whether existing or proposed controls satisfy policy, regulatory, and control requirements.
  • Appropriately assess risk when business and technology decisions are made, demonstrating a risk management mindset to safeguard the bank’s reputation, clients, and assets by driving compliance with applicable laws, rules, and regulations and adhering to Policy and Standards.
  • Apply industry IAM best practices, templates, and documentation, while proposing improvements based on practical knowledge.
  • Influence technology and platform owners to build and implement necessary IAM controls into cloud environments to create a smooth and effective cloud IAM adoption experience.
  • Engage with Product Managers and Senior Architects to understand the strategic technology roadmap and the resulting need for modernized security principles.
  • Consult with the business to identify gaps and governance issues, leveraging domain expertise to find effective solutions.
  • Provide IAM subject matter expertise within the business and technical domain to support scope and requirement decisions.
  • Perform impact analysis of modifications or enhancements, working closely with development teams to refine requirements into implementable specifications.
  • Ensure solutions meet expectations through comprehensive UAT/QA testing of functionality and quality, and confirm the delivery timeline and adoption plan are fit for purpose.
  • Create required documentation, playbooks, job aides, workflows, and training material as part of deployment and adoption activities.
  • Support the design and update of new and existing controls, including the streamlining and automation of reporting.
  • Develop and maintain documentation that accurately describes the current cloud IAM control environment for review by oversight organizations (Audit, Compliance, Operational Risk, Regulators).

Requirements

  • Education

BE/BTECH/MCA/MSC (IT) equivalent (Any Technical Degree)


  • Certifications If Any

NA


  • Experience Range

10+ years of technology/information security experience


Foundational skills

  • 8+ years of experience in cyber security or a technology-related field.
  • Deep, applied knowledge of the IAM domain (business and technical) and of cloud IAM threat models and related security controls.
  • Experience designing and deploying cloud IAM technology and related business processes.
  • Experience evaluating threats and risks posed by new cloud technologies and deployment models, and determining best-fit mitigations for advanced cyber threats (attack tactics, techniques, and procedures).
  • Ability to understand the intent of policy, regulations, and control requirements and determine whether existing or proposed operational controls satisfy them.
  • Familiarity with common information security and data protection frameworks and standards (e.g., CIS, NIST, MITRE, ITIL, COBIT, HIPAA, GDPR, PCI DSS, ISO 27001).
  • Excellent written and verbal communication skills with strong attention to detail; able to communicate with business leaders, users, and tech-savvy stakeholders, and to tailor messages across audiences with varying technical understanding.
  • Strong ability to interact, communicate, and influence vertically and laterally, and to collaborate and influence across peer groups and various levels of management.
  • Excellent organizational skills; able to effectively prioritize multiple competing tasks in a dynamic environment.
  • Experience participating in large or complex projects; strong project management skills.
  • Proactive self-starter able to drive direction and work independently on initiatives with minimal oversight.
  • Ability to coordinate and facilitate delivery routines (kick-offs, status reviews, stakeholder meetings, change controls, tollgates).
  • Ability to create management-level reporting using aggregated data.
  • Experience working in Agile methodology with a deep understanding of all phases of the SDLC.
  • Strong analytical, problem-solving, and conceptual-thinking skills.
  • Proficiency in Microsoft Office tools (Excel, PowerPoint, Word, SharePoint), with the ability to analyze data, distill key data points, and present information effectively.
  • A broad knowledge of information security principles and security capabilities

Desired skills

  • Hands-on experience with Azure Security Center, AWS Security Hub, or Google Cloud Security.
  • Detailed, bank-specific knowledge across Identity & Access Management, application security, risk assessments, cloud technologies, and GRC (Governance, Risk, and Compliance) with emphasis on security processes and controls.
  • Familiarity with financial industry laws, rules, regulations, and guidance documents.
  • Experience within, or interacting with examiners and partners across, control oversight organizations such as Audit, Compliance, Operational Risk, Regulators, and independent assessment organizations.
  • Experience implementing information security strategy, including compliance with industry best practices and regulatory requirements.
  • Ability to work with both technical and non-technical business owners.
  • Highly organized, motivated self-starter who excels at adapting to changing business needs, anticipating problems, and executing solutions while balancing multiple competing priorities.

Work Timings: 12:30 to 21:30 (IST) or 14:30 to 23:30 (IST)

Job Location: Mumbai


Skills

AWSAzureExcelCybersecurityAgileRisk ManagementComplianceProject ManagementITILHIPAAGDPRISO 27001

Similar Jobs

1

1000000558.SECURITY OPERATIONS MANAGER.INFO TECH - SECURITY

Dallas County·Dallas, TX

3mo ago