Bank of America Logo

Bank of America

Information Security Officer

Posted 27 Days Ago
Be an Early Applicant
In-Office
Denver, CO, USA
99K-145K Annually
Senior level
In-Office
Denver, CO, USA
99K-145K Annually
Senior level
Partner with LOB and technology leaders to identify and prioritize information security risks, provide guidance on policies and controls, support application security and cloud security initiatives, conduct risk and control assessments, monitor security trends, advise on remediation and compliance, and participate in risk management and business continuity routines.
The summary above was generated by AI

Job Description:

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

The Information Security Officer will be a member of the Business Information Security Officer's (BISO) organization and partners with the Global Business Services (GBS) Line of Business and Technology Leaders (GDLs). In this role, you will support a group/team in developing business insight for focused information security risk discussions. This relationship will ensure a focus on the right risk priorities. You will also provide guidance on information security topics, policies and controls.

Required Qualifications:
•    2-5 years of experience in technology and 5+ years in information security
•    2-5 years of experience in application development or application security
•    Experience working on cloud implementations in Microsoft Azure, Amazon Web Services and Google Cloud Platform environments
•    Must display subject matter experience in application security, vulnerability testing, system testing, and/or Agile lifecycle management
•    Strong LOB knowledge/experience for the type of business they are aligned to (e.g..CSBB/GBM)
•    1-2 years of risk management experience or direct participation in risk management processes, including application risk classification and application control assessments.
•    Experience giving presentations and superb communication skills

Desired Qualifications:
•    Bachelor's and/or Master’s degree in Computer Science, Information Technology or related field

Scale/Scope
•    Contribute to the ongoing information security initiatives and improvements development, implementation and maintenance of information security for the line of business (LOB)
•    Possess strong / experienced application development and/or application security background; with solid knowledge of SDLC from design, testing, deployment to post-production and the different risk elements associated with each step.
•    Serves as an Information Security subject matter expert and participates in the development, implementation and maintenance of information security for the line of business (LOB)
•    Provides guidance and advocacy regarding the prioritization of LOB investments that impact information security
•    Advises LOB management on risk issues related to information security and recommends actions in support of the bank's wider risk management and compliance programs
•    Monitors information security trends internal and external to the bank and keeps LOB/CIO Partners informed about information security-related issues
•    Manages quality control and reporting
•    Ensures compliance with policies and laws

Risk Management 
•    Drives GIS/LOB risk deliverables
•    Collaborates with risk partners on info security critical priorities
•    Participates in senior LOB specific Risk Management & Business Continuity Routines
•    Identifies and measures global information security (GIS) controls on most critical business processes or channels

Leadership/Strategy
•    Has a working knowledge of security for computing platforms (PaaS)
•    Has a solid grasp of security in big data and other instructed large data structures
•    Ability to build strong Partner relationships with peer technology groups and supported LOB
•    Supports the triage process with the client and helps them understand the GIS support structure
•    Drives required risk culture and partnership with peer technology teams and supported LOB
•    Participates in key CIO/COO operating routines to drive information security risk strategy
 

Required Skills:

1. Controls Management
2. Cyber Security
3. Data Governance
4. Information Systems Management
5. Risk Management
6. Architecture
7. Customer and Client Focus
8. Executive Presence
9. Threat Analysis
10. Vendor Management
11. Self- Starter 
12. Emotional Intelligence
 

Shift:

1st shift (United States of America)

Hours Per Week: 

40

Pay Transparency details

US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540)

Pay and benefits information

Pay range$99,200.00 - $145,000.00 annualized salary, offers to be determined based on experience, education and skill set.

Discretionary incentive eligible

This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.

Benefits

This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.

Similar Jobs

12 Days Ago
Remote or Hybrid
US
140K-175K Annually
Mid level
140K-175K Annually
Mid level
Information Technology
Performs IT audits and cybersecurity control validation for complex systems, applications, enclaves, and classified or unclassified networks. Assesses vulnerabilities, risks, security requirements, and mitigation effectiveness against Federal and DoD standards. Provides technical evaluations and recommends security improvements while balancing business needs with security concerns. Requires experience with RMF, DODI 8500.2 or NIST SP 800-53, eMASS, network implementation, and an active DoD Secret clearance.
Top Skills: Dodi 8500.2EmassMicrosoft AccessExcelMS OfficeMicrosoft PowerpointMicrosoft WordNetwork SecurityNist Sp 800-53Risk Management Framework (Rmf)
2 Days Ago
In-Office
Aurora, CO, USA
87K-165K Annually
Senior level
87K-165K Annually
Senior level
Aerospace • Defense
The Senior ISSO monitors and assesses information-system compliance, conducts audits and technical assessments, develops security plans, investigates violations, reviews configuration changes, implements cybersecurity processes and tools, and maintains security documentation. The role supports NIST, NISPOM, DAAPM, JSIG, and RMF compliance in a classified defense environment. It requires onsite work in Aurora, Colorado, an active TS/SCI clearance, U.S. citizenship, and a Security+ or equivalent IAM Level I certification within six months if not already held.
Top Skills: AcasDaapmDcsa Assessment And Authorization Process ManualDisa StigsForcepointHbssIvantiJsigLinuxNispomNist Special PublicationsRisk Management Framework (Rmf)Security+SplunkTenableWindows
2 Days Ago
In-Office
Colorado Springs, CO, USA
Senior level
Senior level
Security
Supports information system security for secure defense facilities by conducting vulnerability and risk assessments, preparing RMF and authorization documentation, coordinating security assessments, managing security configurations, reviewing policies, processing system changes, and responding to incidents. The role requires expertise in cybersecurity, information assurance, Windows and Linux environments, DoD security frameworks, classified systems, and SCI/SAP program security.
Top Skills: AcasCisspCnssi 1253Comptia Security+EmassIcd 503JsigLinuxNessusNist Risk Management FrameworkNist Sp 800-53/53AScapSplunkStigsVMwareWindowsXacta

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account