Info Security Controls Specialist

Bank of America

Town of Charlotte (NY)

On-site

USD 120,000 - 170,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Bank of America offers an opportunity to join a security and compliance team focused on enterprise-wide information security policies and standards. You will track deliverables, assess risks, and partner with stakeholders to ensure policy adherence across applications.

The role emphasizes collaboration with GIS, control functions, and risk management to close gaps and drive remediation in a regulated financial services environment. This position requires vigilance and strong communication skills.

Qualifications

  • Proven experience in Information Security, Technology Risk, Compliance, or Security Controls within a large enterprise environment.
  • Strong understanding of information security policies, risk management, regulatory compliance, and control governance frameworks.
  • Experience coordinating and tracking security, risk, audit, and compliance deliverables across multiple applications or technology platforms.
  • Knowledge of vulnerability management, remediation tracking, access governance, disaster recovery, and operational resilience processes.
  • Experience supporting internal audits, regulatory examinations, risk assessments, and control testing activities.
  • Ability to partner effectively with Technology, Cybersecurity, Risk, Audit, and Infrastructure teams to drive compliance outcomes.
  • Experience managing compliance activities for vendor-supported or third-party applications.
  • Strong analytical, organizational, and problem-solving skills with attention to detail.
  • Excellent communication and stakeholder management skills, including the ability to influence and coordinate across diverse teams.
  • Ability to manage multiple priorities in a fast-paced, highly regulated environment while ensuring timely execution of control obligations.

Responsibilities

  • Supports development of enterprise-wide information security policies, procedures, and standards and industry leading information security reporting, risk scoring, and governance standards.
  • Works with internal and external stakeholders including Line of Business delegates and regulators to mitigate and remediate information security risks.
  • Ensures Information Technology systems meet enterprise standards, adhere to applicable rules, laws, and regulations, and comply with appropriate treatment of risk.
  • Identifies information security gaps and remediation strategies.
  • Analyzes existing Information Technology systems and processes to identify areas of vulnerability, provide mitigation tactics, and design and implement improved systems and processes.
  • Ensure that risk, security, and other compliance deliverables are completed on time and per requirements for the applications they support.
  • Complete administrative and non-technical tasks related to compliance deliverables (for example, access reviews, assessments, questionnaires, procedural requirements, and so on).
  • Assist with audit exams and risk assessments for the applications.
  • Track and support the technical security and risk activities performed by the development teams (for example, remediation of non-permitted technology or security vulnerabilities, technical recovery planning, disaster recovery exercises, and so on).
  • Maintain data about the application in systems of record.
  • Work closely with vendors for vendor applications to ensure the application meets bank requirements.
  • Assist with ad hoc inquiries and questions about the application.
  • Interface with technology infrastructure teams for infrastructure requirements like requests for additional storage.

Skills

Customer focus
Policy interpretation
Regulatory compliance
Risk analytics
Stakeholder management
Data governance
Problem solving
Quality assurance
Controls management
Process management

Job description

Job Description:

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits. We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve. Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

This job is responsible for developing and supporting enterprise-wide information security policies, procedures, and standards.

Key responsibilities include applying knowledge of laws, rules, regulations, and information security concepts (e.g., NIST, COBIT, ISO) to establish and maintain policies, validate alignment of processes and controls to requirements, and report on adherence to policy requirements.

Job expectations include using data analytics and partnering with internal teams to verify policy compliance, identify gaps in coverage, and support remediation activities.

Position Summary:

This role is responsible for completing and tracking compliance deliverables to ensure applications adhere to applicable policies and standards as well as local laws, rules and regulations (LRR). Key responsibilities include completing administrative and non-technical tasks related to compliance deliverables and infrastructure requests for the applications they support. They support vendors, development teams and technology managers to ensure technical security, risk, and other compliance activities are completed on time and per requirements. These individuals partner closely with control functions, risk management and Global Information Security (GIS) and are familiar with the applicable policies, standards, LRRs, contacts and procedures so that the compliance deliverables are completed effectively and efficiently.

Responsibilities:
  • Supports development of enterprise-wide information security policies, procedures, and standards and industry leading information security reporting, risk scoring, and governance standards
  • Works with internal and external stakeholders including Line of Business delegates and regulators to mitigate and remediate information security risks
  • Ensures Information Technology systems meet enterprise standards, adhere to applicable rules, laws, and regulations, and comply with appropriate treatment of risk
  • Identifies information security gaps and remediation strategies
  • Analyzes existing Information Technology systems and processes to identify areas of vulnerability, provide mitigation tactics, and design and implement improved systems and processes
  • Ensure that risk, security, and other compliance deliverables are completed on time and per requirements for the applications they support.
  • Complete administrative and non-technical tasks related to compliance deliverables (for example, access reviews, assessments, questionnaires, procedural requirements, and so on).
  • Assist with audit exams and risk assessments for the applications.
  • Track and support the technical security and risk activities performed by the development teams (for example, remediation of non-permitted technology or security vulnerabilities, technical recovery planning, disaster recovery exercises, and so on).
  • Maintain data about the application in systems of record.
  • Work closely with vendors for vendor applications to ensure the application meets bank requirements.
  • Assist with ad hoc inquiries and questions about the application.
  • Interface with technology infrastructure teams for infrastructure requirements like requests for additional storage.
Required Qualifications
  • Proven experience in Information Security, Technology Risk, Compliance, or Security Controls within a large enterprise environment.
  • Strong understanding of information security policies, risk management, regulatory compliance, and control governance frameworks.
  • Experience coordinating and tracking security, risk, audit, and compliance deliverables across multiple applications or technology platforms.
  • Knowledge of vulnerability management, remediation tracking, access governance, disaster recovery, and operational resilience processes.
  • Experience supporting internal audits, regulatory examinations, risk assessments, and control testing activities.
  • Ability to partner effectively with Technology, Cybersecurity, Risk, Audit, and Infrastructure teams to drive compliance outcomes.
  • Experience managing compliance activities for vendor-supported or third-party applications.
  • Strong analytical, organizational, and problem-solving skills with attention to detail.
  • Excellent communication and stakeholder management skills, including the ability to influence and coordinate across diverse teams.
  • Ability to manage multiple priorities in a fast-paced, highly regulated environment while ensuring timely execution of control obligations.
Preferred Qualifications
  • Experience supporting enterprise payment, messaging, or critical financial infrastructure platforms.
  • Familiarity with information security standards, technology risk frameworks, and regulatory requirements in the financial services industry.
  • Professional certifications such as CISSP, CISM, CRISC, Security+, or equivalent.
  • Experience working with application lifecycle governance, security assessments, and audit remediation programs.
Skills:

Customer and Client Focus Interpret Relevant Laws, Rules, and Regulations Policies, Procedures, and Guidelines Problem Solving Quality Assurance Business Acumen Controls Management Innovative Thinking Process Management Stakeholder Management Business Process Analysis Data Governance Data Privacy and Protection Data and Trend Analysis Risk Analytics

Shift: 1st shift (United States of America)

Hours Per Week: 40

Privacy Statement: https://careers.bankofamerica.com/en-us/privacy-notice

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection.

Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day. One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world. We’re devoted to being a diverse and inclusive workplace for everyone. We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well-being. Bank of America believes both in the importance of working together and offering flexibility to our employees. We use a multi-faceted approach for flexibility, depending on the various roles in our organization. Working at Bank of America will give you a great career with opportunities to learn, grow and make an impact, along with the power to make a difference. Join us! Partnering Locally Learn about some of the ways Bank of America is making a difference in the communities we serve. Global Impact Learn about the six areas that guide Bank of America’s efforts to help make financial lives better for customers, clients, communities and our teammates. Opportunity and Inclusion Each employee brings unique skills, background and opinions. We see opportunity and inclusion as our platform for innovation and a key component in our success. Our Values Learn about our four values that represent what we believe.

Pay Transparency: https://careers.bankofamerica.com/en-us/pay-transparency

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Controls Mapping Governance Lead - Global Information Security
Controls Mapping Governance Lead - Global Information Security

Bank of America • United States

On-site
USD 78,000 - 136,000
Discretionary incentive eligible
Benefits eligible
Business Information Security Officer (BISO) - CFO and GRM
Business Information Security Officer (BISO) - CFO and GRM

Bank of America • Washington

On-site
USD 99,000 - 145,000
Information Security Officer
Information Security Officer

Bank of America • Washington

On-site
USD 99,000 - 145,000
Benefits eligible
Discretionary incentive
Information Security Officer
Information Security Officer

Bank of America • Denver (CO)

Hybrid
USD 99,000 - 145,000
Product Manager – Tech Delivery - Application Security Adjudication & Risk Management
Product Manager – Tech Delivery - Application Security Adjudication & Risk Management

Bank of America • Washington

On-site
USD 135,000 - 217,000
Information Security Officer
Information Security Officer

Hobbsnews • Chicago (IL)

On-site
USD 99,000 - 145,000
Discretionary incentive
Benefits eligibility
Senior Cloud Security Analyst
Senior Cloud Security Analyst

Bank of America • Washington

On-site
USD 145,000 - 193,000
Identity & Access Management (IAM) Info Security Controls Specialist
Identity & Access Management (IAM) Info Security Controls Specialist

Bank of America • Boston (MA)

On-site
USD 78,000 - 136,000
Benefits eligible
Discretionary incentive
Paid time off
Information Management Consultant - Securities, Settlements, and Custody Operations
Information Management Consultant - Securities, Settlements, and Custody Operations

Bank of America • South Dakota

On-site
USD 68,000 - 106,000
Information Security Officer - Global Banking & Markets (GBAM)
Information Security Officer - Global Banking & Markets (GBAM)

Bank of America • Denver (CO)

On-site
USD 99,000 - 145,000
Benefits eligible
Annual discretionary plan