Controls Mapping Governance Lead - Global Information Security

Bank of America

Washington (District of Columbia)

On-site

USD 110,000 - 135,000

Full time

29 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Bank of America is seeking an information security professional to interpret governance requirements, map controls across enterprise processes, and validate evidence to meet regulatory expectations. The role involves evaluating must statements, engaging control owners, and ensuring coverage is complete and defensible.

The candidate will demonstrate strong analytical and communication skills, ability to challenge SMEs, and experience in cybersecurity risk, policy governance, or related fields in

Qualifications

  • 3+ years of information security, cybersecurity risk, policy governance, or related field in regulated environments.
  • Knowledge of cybersecurity concepts and at least one domain (IAM, network, cloud, data protection, etc.).
  • Ability to interpret complex requirements and map to processes and evidence.
  • Experience reviewing procedures and control descriptions to identify gaps, exclusions, or incomplete responses.
  • Strong analytical and communication skills to discuss with subject matter experts and document mapping decisions for leadership.

Responsibilities

  • Interpret laws, rules, regulations, policies, procedures, and guidelines; break complex requirements into must statements and define outcome, scope, and evidence.
  • Identify and assess candidate processes and controls; develop coverage recommendations and determine coverage status.
  • Review technical processes and challenge owner responses to ensure activity, ownership, scope, dependencies, and evidence support mappings.
  • Document clear, defensible mapping decisions and determine acceptance, gaps, or escalation through governance channels.
  • Use data and approved tools to support interpretation, coverage identification, response review, reporting, and process improvement, while validating all outputs and maintaining accountability.

Skills

Customer and Client Focus
Interpret Relevant Laws
Rules and Regulations
Policies
Procedures and Guidelines
Problem Solving
Quality Assurance
Business Acumen

Job description

Job Description

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.

Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.

We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.

Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.

At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

The Controls Mapping Governance team is seeking an information security professional with experience in cybersecurity, technology infrastructure, audit, or regulatory or policy requirements.

This role supports the enterprise policy governance lifecycle by interpreting information security requirements, identifying the processes and controls that may address those requirements, and determining whether the proposed coverage is sufficiently supported.

The successful candidate will evaluate requirements at the individual must-statement level, develop preliminary coverage recommendations, engage process and control owners, and assess supporting evidence. The candidate must be comfortable discussing technical concepts with subject matter experts and determining whether a documented process or control logically addresses the requirement’s intent, scope, and expected outcome.

Responsibilities
  • Interpret laws, rules, regulations, policies, and standards; break complex requirements into individual must statements; and define the required outcome, scope, accountable parties, and expected evidence.
  • Identify and assess candidate processes, controls; develop preliminary coverage recommendations; and determine whether coverage is direct, supporting, partial, or insufficient.
  • Review technical processes and challenge owner responses to determine whether the documented activity, scope, ownership, dependencies, limitations, and evidence support the proposed mapping.
  • Document clear, defensible mapping decisions and determine whether proposed coverage should be accepted, clarified, treated as partial or a gap, or escalated through established governance channels.
  • Use data and approved tools to support requirement interpretation, coverage identification, response review, reporting, and process improvement, while independently validating all outputs and maintaining decision accountability.
Required Qualifications
  • 3+ years of experience in information security, cybersecurity risk, technology risk, controls governance, policy governance, compliance, audit, or a related field within a regulated environment.
  • Working knowledge of cybersecurity concepts, technology infrastructure, and security domains such as identity and access management, network security, cloud security, application security, data protection, vulnerability management, monitoring, incident response, or configuration management.
  • Ability to understand how security processes and controls operate across systems, applications, infrastructure, data, users, and technologies, without needing to be an engineer or subject matter expert in every domain.
  • Experience reviewing technical procedures, process flows, control descriptions, system documentation, and evidence artifacts to identify incomplete responses, unsupported conclusions, exclusions, failure conditions, or gaps in coverage.
  • Strong analytical and communication skills, including the ability to question technical subject matter experts constructively, distinguish direct coverage from general alignment, and document clear, defensible mapping decisions for technical and senior audiences.
  • Ability to evaluate and independently validate data against authoritative requirements, approved inventories, owner responses, and supporting evidence rather than relying solely on owner conclusions.
Desired Qualifications
  • Knowledge of cybersecurity frameworks and standards, such as NIST, ISO/IEC 27001, COBIT, CIS Controls, or comparable frameworks.
  • Experience mapping requirements to processes, controls, control objectives, assessments, or other governance mechanisms.
  • Familiarity with governance, risk, and compliance platforms, and SharePoint workflows.
  • Experience working with technology teams, policy or standard owners, control owners, risk partners, auditors, compliance functions, or regulators.
  • Relevant cybersecurity, risk, audit, cloud, or controls certification.
Required Skills
  • Customer and Client Focus
  • Interpret Relevant Laws
  • Rules
  • and Regulations
  • Policies
  • Procedures
  • and Guidelines
  • Problem Solving
  • Quality Assurance
  • Business Acumen
Shift

1st shift (United States of America)

Hours Per Week

40

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Controls Mapping Governance Lead - Global Information Security
Controls Mapping Governance Lead - Global Information Security

Bank of America • Denver (CO)

On-site
USD 90,000 - 130,000
Controls Mapping Governance Lead - Global Information Security
Controls Mapping Governance Lead - Global Information Security

Bank of America • Addison (TX)

On-site
USD 78,000 - 136,000
Benefits eligible
Controls Mapping Governance Lead - Global Information Security
Controls Mapping Governance Lead - Global Information Security

Hobbsnews • Addison (TX), Northern (KY)

Hybrid
USD 78,000 - 136,000
Controls Mapping Governance Lead - Global Information Security
Controls Mapping Governance Lead - Global Information Security

Koitecc Solutions • Denver (CO), Northern (KY)

Hybrid
USD 78,000 - 136,000
Discretionary incentive plan
Benefits eligible
Information Security Officer – Global Banking & Markets (GBAM)
Information Security Officer – Global Banking & Markets (GBAM)

Bank of America • Denver (CO)

On-site
USD 130,000 - 180,000
Information Security Officer – Global Banking & Markets (GBAM)
Information Security Officer – Global Banking & Markets (GBAM)

Bank of America • Chicago (IL)

On-site
USD 120,000 - 170,000
Cloud Security Application Control Owner
Cloud Security Application Control Owner

Bank of America • Chicago (IL)

On-site
USD 130,000 - 210,000
Senior Controls Mapping & Governance Lead
Senior Controls Mapping & Governance Lead

Bank of America • Denver (CO)

On-site
USD 90,000 - 130,000
InfoSec Controls Mapping Lead
InfoSec Controls Mapping Lead

Bank of America • Addison (TX)

On-site
USD 78,000 - 136,000
Benefits eligible
Security Controls Mapping & Governance Lead
Security Controls Mapping & Governance Lead

Bank of America • Washington

On-site
USD 110,000 - 135,000