Enable job alerts via email!

Assistant Vice President/ Vice President, Third Party Info Security...

Bank of America Singapore

Singapore

On-site

SGD 80,000 - 110,000

Full time

Today
Be an early applicant

Job summary

A major financial institution in Singapore is seeking a Cyber Security Assessor to manage assessments of third parties. The role requires 5-8 years in information security, CISSP/CISA certifications, and the ability to communicate clearly with various stakeholders. The successful candidate will drive remediation of security issues and contribute to the Cyber Assurance program.

Qualifications

  • 5-8 years of experience in information security or business continuity.
  • Previous information technology/security audit/assessment experience preferred.
  • Must be able to travel up to 25% of the time.

Responsibilities

  • Manage and execute assessments of third parties providing services.
  • Evaluate design and effectiveness of controls.
  • Drive remediation of identified issues.
  • Interface with external and internal stakeholders.
  • Contribute to the development of the Cyber Assurance program.

Skills

Information Security Controls (Cloud Security, Infrastructure Security, Access Management)
IT Compliance
Change Management
Enterprise Risk Management
Analytical skills
Communication skills
Attention to detail
Ability to multi-task

Education

CISSP certification
CISA certification
Bachelor's degree or equivalent experience

Tools

NIST standards
PCI standards
ISO standards
COBIT standards
ITIL standards
Job description

Job Description:

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.

Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates’ physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.

Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations.

At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

Overview

The Third Party Cyber Security Assessor will conduct information security and business continuity assessments of third parties providing services to Bank of America. The assessor will examine a third party\'s program to determine if they meet the Bank’s requirements, identifying control gaps that may expose the Bank to risks and subsequently work with the third party on all remediation activities.

To succeed in this role, you should be highly independent, motivated and possess strong, hands-on, technical knowledge of a wide range of information security and business continuity controls and the processes used for evaluating their design and effectiveness and possess strong written and verbal communication skills including ability to communicate clearly and concisely to various levels, up to and including executive level management, and explain the need for key controls to technical and non-technical resources.

There will be opportunities to be involved in projects to improve processes & transform the assessment program. This will enable you to leverage and grow your leadership skills as you\'ll be exposed to various internal stakeholders and industry partners.

Responsibilities
  • Manage and execute assessments of third parties providing services to Bank of America.
  • Evaluate design and effectiveness of controls implemented by third parties providing services to Bank of America.
  • Drive remediation of issues identified through the assessments and any subsequent risk conversations with the third parties and other internal stakeholders.
  • Interface with external third parties and internal line of business stakeholders to provide consultation on information security topics and build strong working relationships with these parties.
  • Partner with regional and global GIS teammates to collaborate on opportunities and to identify, analyze, and resolve complex problems or security gaps.
  • Contribute to the development and transformation of the Third Party Cyber Assurance program.
Required Skills
  • Previous information technology/security audit/assessment experience preferred.
  • Ability to leverage attention to detail and analytical skills.
  • Ability to multi-task and work both independently as well as part of an assessment team.
  • Ability to plan, execute and document assessment and remediation activities following established processes and procedures.
  • Must be comfortable in delivering messages across a wide spectrum of individuals having varying degrees of technical understanding.
  • Minimally, CISSP and/or CISA certifications are required as well as five to eight years of experience in information security or business continuity.
  • Technical skills include the domains of information security and business continuity including:
    • Information Security Controls (Cloud Security, Infrastructure Security, Access Management, Physical Security, Application Security, etc.),
    • IT Compliance, SOX Compliance
    • Change Management
    • Enterprise Risk Management
    • Solid grasp of NIST, PCI, ISO, SDLC, COBIT, and ITIL standards.
  • Ability to speak Mandarin and write in Simplified and Traditional Chinese due to interactions with 3rd parties in the Greater China region.
  • Must be able to travel up to 25% of the time.
  • Experience in Cloud technologies, OSINT and threat modeling will be advantageous.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.