Cyber Security Application Remediation Governance Analyst

Fashion Studio Magazine

Denver (CO)

On-site

USD 99,000 - 145,000

Full time

9 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Discretionary incentive eligible
Benefits package

Job summary

Bank of America is seeking an Application Remediation Governance professional in Denver to reduce technology risk by speeding remediation of vulnerabilities across applications. You will work with application managers and risk partners, and address AI‑identified vulnerabilities with urgency and rigor.

The role tracks vulnerabilities, coordinates with vendors, and reports metrics to leadership while ensuring timely remediation in line with risk appetite.

Qualifications

  • 3+ years cyber security experience.
  • Vulnerability and remediation experience.
  • Ability to improve team processes to increase efficiency and coverage.
  • Understanding of novel vulnerability vectors, primarily those aligned to AI capabilities.

Responsibilities

  • Creates and maintains the team's application vulnerability portfolio.
  • Lead the Bank's response to AI‑identified vulnerabilities and minimize cyber risk.
  • Oversee ARG daily BAU activities; act as proxy manager when required.
  • Lead ARG team and ensure balanced workload distribution.
  • Configure the SOR for team visibility and timely action on vulnerabilities.
  • Escalate and represent ARG on incident calls related to application vulnerabilities, especially P1s.
  • Owns ARG actions and collaboration; coordinates with CST on SOR upkeep and enhancements.
  • Represent ARG on tech calls for SOR end-user input and break/fix validation.
  • Manage ARG BAU process for unmasked corporate account details.
  • Create and maintain ARG process and procedure documentation and training materials.
  • Configure application access for new ARG team members in ARM.
  • Create and QA monthly risk metrics at manager and board level.
  • Train and onboard new ARG team members.

Skills

Cyber security experience
Vulnerability remediation
Process improvement
AI vulnerability basics

Job description

Job Description:

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.

Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates' physical, emotional, and financial wellness through affordable, competitive and flexible benefits.

We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.

Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

Position Summary:

The Application Remediation Governance candidate will contribute to reduction of technology risk in the bank by driving down the time taken to remediate identified application vulnerabilities, working with application managers and risk partners to resolve vulnerabilities in a time frame aligned to the Bank's risk appetite.The candidate will be at the forefront of the Bank's response to the new AI- identified application vulnerabilities, working with application teams and driving remediation in a timely manner.

The candidate will attend report out calls following a security assessment of a particular application aligned with an assigned 4 dot hierarchy. Candidate will track the identified vulnerabilities in the system of record and work with the application or vendor manager until resolution. Candidate will update status of vulnerabilities as required in the system of record and will aid the application and/or vendor manager with any technical or process related queries during resolution of the identified vulnerabilities. Additionally the candidate will be expected to aid with creation of periodic risk metrics relating to the role.

Responsibilities:
  • Creates and maintains the team's application vulnerability portfolio.
  • Responsible for being at the forefront of the Bank's response to the novel threat of AI identified vulnerabilities, possession of a good understand of LLM based vulnerabilities and the most effective and timely actions the team can take to minimize cyber risk to the Bank.
  • Oversight and leadership responsibilities for ARG daily BAU activities.
  • Leadership of the ARG team, including being proxy manager when required.
  • Responsible for maintaining a balanced distribution of vulnerabilities between ARG team members to ensure workload balance.
  • Work includes configuration of the SOR for all team members to view their portfolio, specifically alerting them to any items that require timely action (e.g. self assignment of new vulnerabilities).
  • Responsible for escalation and representation of the ARG on Incident calls related application vulnerabilities, specifically P1s.
  • The candidate will be expected to take responsibility for any ARG actions or collaboration, "owning" the issue for ARG.
  • Works with CST tech teams to ensure that the SOR remains up to date and functioning correctly.
  • Works with CST on enhancements to the SOR.
  • Represents ARG on tech calls relating to SOR, providing end user input and validation of break/fix activities.
  • Responsible for management of the ARG BAU process for unmasked corporate account details.
  • Responsible for creation and maintenance of ARG team official process and procedure documentation, and training documentation.
  • Responsible for configuration of the application access package for all new ARG team members in ARM.
  • Responsible for creation and QA for monthly risk metrics at manager and board level.
  • Responsible for training and onboarding any new members of the ARG team.
Required Qualifications:
  • 3+ years cyber security experience.
  • Vulnerability and remediation experience.
  • Ability to improve team processes to increase efficiency and coverage. This would include maintenance of team documentation and optimising alignment of vulnerabilities among the team.
  • Understanding of novel vulnerability vectors, primarily those aligned to AI capabilities.

This job will be open and accepting applications for a minimum of seven days from the date it was posted.

Shift:

1st shift (United States of America)

Hours Per Week:

40

Pay Transparency details

US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540)

Pay and benefits information
Pay range

$99,200.00 - $145,000.00 annualized salary, offers to be determined based on experience, education and skill set.

Discretionary incentive eligible

This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.

Benefits

This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Application Remediation Governance Analyst
Cyber Security Application Remediation Governance Analyst

Bank of America • Washington

On-site
USD 99,000 - 145,000
Annual discretionary plan
Industry-leading benefits
Cyber Security Application Remediation Governance Analyst
Cyber Security Application Remediation Governance Analyst

Bank of America • Chicago (IL)

On-site
USD 99,000 - 145,000
Benefits eligible
Industry-leading benefits
Paid time off
Cyber Security Application Remediation Governance Analyst
Cyber Security Application Remediation Governance Analyst

Bank of America • Denver (CO)

On-site
USD 99,000 - 145,000
Health benefits
Paid time off
Cyber Security Application Remediation Governance Analyst
Cyber Security Application Remediation Governance Analyst

Bank of America • Washington

On-site
USD 90,000 - 130,000
Product Manager - Application Security & Risk Management - Tech Delivery
Product Manager - Application Security & Risk Management - Tech Delivery

Bank of America • Chicago (IL)

On-site
USD 135,000 - 217,000
Industry-leading benefits
Discretionary incentive eligibility
Cyber Threat Defense Sr AI/ML Engineer
Cyber Threat Defense Sr AI/ML Engineer

Bank of America • Jersey City (NJ)

On-site
USD 145,000 - 193,000
Discretionary incentive eligible
Benefits eligible
Paid time off
Cyber Threat Defense Sr AI/ML Engineer
Cyber Threat Defense Sr AI/ML Engineer

Koitecc Solutions • Denver (CO), Northern (KY)

On-site
USD 145,000 - 193,000
Discretionary incentive eligibility
Product Manager - Application Security & Risk Management - Tech Delivery
Product Manager - Application Security & Risk Management - Tech Delivery

Bank of America • Denver (CO)

On-site
USD 135,000 - 217,000
Cyber Threat Defense Sr AI/ML Engineer
Cyber Threat Defense Sr AI/ML Engineer

NCSL International • Washington, Northern (KY)

On-site
USD 145,000 - 193,000
Discretionary incentive plan
Industry-leading benefits
Cyber Threat Defense Sr AI/ML Engineer
Cyber Threat Defense Sr AI/ML Engineer

NCSL International • Jersey City (NJ)

On-site
USD 145,000 - 193,000
Benefits eligible
Paid time off