Senior Information Security Officer - GEM (GIS Exception Management)
Bank Of America
·4 days ago
- Salary
- $142k – $203k
- Location
- Washington, United States of America · Chicago · Denver
- Workplace
- Onsite
- Type
- Full-time
- Department
- Management
- Seniority
- Senior
- Education
- Bachelor
- Source
- Workday
Description
Job Description:
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
The Senior Information Security Officer will be a key member of the GIS Exception Management team within the Business Information Security Office (BISO) organization. In this role, you will serve as a technical lead for the GIS Policy Exceptions and Secure Internet Browsing programs, providing oversight of operational execution, governance and reporting routines, risk management, and continuous improvement initiatives. You will continuously collaborate with IT, business technology groups, risk partners, GIS teams across their respective LOB and Third-party vendor.
Required Qualifications:
• Information Security & Technology professional with 10+ years’ experience
• 5+ years of risk management experience with proven ability to effectively apply risk principles to challenging business situations
• Provides subject matter expertise in Web, Network, and Application security, vulnerability assessment and testing, and the establishment of risk appetite and risk management strategies
• Strong experience with Insider Threat and Web Proxy Infrastructure as a focus area within Information Security
• Experience and hands on knowledge with Data Loss Prevention and Malware security controls
• Experience evaluating cyber security controls and providing guidance for computing & network platforms (Cloud, PaaS, SaaS)
• Strong experience with information security for Network & DMZ Infrastructure and third-party connectivity including exposure to various security frameworks (ISO, NIST, PCI etc.)
• Experience leading complex technical initiatives, driving projects to meet target timelines, facilitating stakeholder meetings, developing project documentation, resolving issues, and coordinating resource planning.
• Exceptional executive presentation and communication skills
• Strong interpersonal and leadership skills with the ability to build consensus, promote cooperation, and effectively influence, negotiate, and collaborate with senior leaders and stakeholders at all levels of the organization
• Ability to independently lead projects and deliver desired outcomes with minimal supervision while meeting program goals
• Strong knowledge of change and project management methodologies, with the ability to effectively incorporate these principles into project planning, design, and execution
Scale/Scope
• Possess strong Network, Web and Application security background; with solid knowledge of SDLC from design, testing, deployment to post-production and the different risk elements associated with each step.
• Serves as an Information Security subject matter expert, driving the implementation and support of secure web access solutions for enterprise users
• Partners with Information Security DLP and Malware Control teams, Proxy/Network Engineering and business stakeholders to balance security and usability
• Evaluates risk and provides expert guidance on web access, URL onboarding, and proxy change requests to ensure appropriate prioritization and alignment with Line of Business (LOB) objectives
• Monitors information security trends internal and external to the bank and keeps LOB leadership informed about information security-related issues
• Manages quality control and reporting
• Ensures compliance with policies and laws
Risk Management
• Manage and oversee the documentation, assessment, and remediation of risk issues, governance decisions, policy exceptions, and audit-related action
• Collaborates with risk partners on info security critical priorities
• Participates in senior LOB specific Risk Management & Business Continuity Routines
• Identifies and measures global information security (GIS) controls on most critical business processes or channels
Leadership/Strategy
• Has a deep understanding of Network and Web Security principles and emerging technologies
• Identify and implement opportunities for automation, tooling enhancements and process optimization to improve efficiency and reduce operational risks
• Ability to build strong Partner relationships with peer technology groups and supported LOB
• Identify and implement opportunities for automation, tooling enhancements and process optimization to improve efficiency and reduce operational risks
• Drives required risk culture and partnership with peer technology teams and supported LOB
• Participates in key CIO operating routines to drive information security risk strategy
Desired Qualifications:
• Bachelor's and/or Master’s degree in Computer Science, Information Technology or related field
Skills:
1. Customer and Client Focus
2. Cyber Security
3. Data Governance
4. Executive Presence
5. Information Systems Management
6. Architecture
7. Business Intelligence
8. Risk Management
9. Threat Analysis
10. Vendor Management
Shift:
1st shift (United States of America)Hours Per Week:
40Pay Transparency details
US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540)Pay and benefits informationPay range$141,700.00 - $202,700.00 annualized salary, offers to be determined based on experience, education and skill set.Discretionary incentive eligibleThis role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.BenefitsThis role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.