MyLiveCV

Info Security Controls Specialist

94-1687665 bank of america national association

charlotte united statesPosted 14 tháng 9, 2026Source: workdayVerified · checked 11 giờ trước

Job Description

Job Description: At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits. We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve. Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us! Job Description: This job is responsible for developing and supporting enterprise-wide information security policies, procedures, and standards. Key responsibilities include applying knowledge of laws, rules, regulations, and information security concepts (e.g., NIST, COBIT, ISO) to establish and maintain policies, validate alignment of processes and controls to requirements, and report on adherence to policy requirements. Job expectations include using data analytics and partnering with internal teams to verify policy compliance, identify gaps in coverage, and support remediation activities. Position Summary: This role is responsible for completing and tracking compliance deliverables to ensure applications adhere to applicable policies and standards as well as local laws, rules and regulations (LRR). Key responsibilities include completing administrative and non-technical tasks related to compliance deliverables and infrastructure requests for the applications they support. They support vendors, development teams and technology managers to ensure technical security, risk, and other compliance activities are completed on time and per requirements. These individuals partner closely with control functions, risk management and Global Information Security (GIS) and are familiar with the applicable policies, standards, LRRs, contacts and procedures so that the compliance deliverables are completed effectively and efficiently. Responsibilities: Supports development of enterprise-wide information security policies, procedures, and standards and industry leading information security reporting, risk scoring, and governance standards Works with internal and external stakeholders including Line of Business delegates and regulators to mitigate and remediate information security risks Ensures Information Technology systems meet enterprise standards, adhere to applicable rules, laws, and regulations, and comply with appropriate treatment of risk Identifies information security gaps and remediation strategies Analyzes existing Information Technology systems and processes to identify areas of vulnerability, provide mitigation tactics, and design and implement improved systems and processes Ensure that risk, security, and other compliance deliverables are completed on time and per requirements for the applications they support. Complete administrative and non-technical tasks related to compliance deliverables (for example, access reviews, assessments, questionnaires, procedural requirements, and so on). Assist with audit exams and risk assessments for the applications. Track and support the technical security and risk activities performed by the development teams (for example, remediation of non-permitted technology or security vulnerabilities, technical recovery planning, disaster recovery exercises, and so on). Maintain data about the application in systems of record. Work closely with vendors for vendor applications to ensure the application meets bank requirements. Assist with ad hoc inquiries and questions about the application. Interface with technology infrastructure teams for infrastructure requirements like requests for additional storage. Required Qualifications Proven experience in Information Security, Technology Risk, Compliance, or Security Controls within a large enterprise environment. Strong understanding of information security policies, risk management, regulatory compliance, and control governance frameworks. Experience coordinating and tracking security, risk, audit, and compliance deliverables across multiple applications or technology platforms. Knowledge of vulnerability management, remediation tracking, access governance, disaster recovery, and operational resilience processes. Experience supporting internal audits, regulatory examinations, risk assessments, and control testing activities. Ability to partner effectively with Technology, Cybersecurity, Risk, Audit, and Infrastructure teams to drive compliance outcomes. Experience managing compliance activities for vendor-supported or third-party applications. Strong analytical, organizational, and problem-solving skills with attention to detail. Excellent communication and stakeholder management skills, including the ability to influence and coordinate across diverse teams. Ability to manage multiple priorities in a fast-paced, highly regulated environment while ensuring timely execution of control obligations. Preferred Qualifications Experience supporting enterprise payment, messaging, or critical financial infrastructure platforms. Familiarity with information security standards, technology risk frameworks, and regulatory requirements in the financial services industry. Professional certifications such as CISSP, CISM, CRISC, Security+, or equivalent. Experience working with application lifecycle governance, security assessments, and audit remediation programs. Skills: Customer and Client Focus Interpret Relevant Laws, Rules, and Regulations Policies, Procedures, and Guidelines Problem Solving Quality Assurance Business Acumen Controls Management Innovative Thinking Process Management Stakeholder Management Business Process Analysis Data Governance Data Privacy and Protection Data and Trend Analysis Risk Analytics Shift: 1st shift (United States of America) Hours Per Week: 40