Policy-Driven Info Security Controls Specialist

Bank of America

Town of Charlotte (NY)

On-site

USD 120,000 - 170,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Bank of America offers an opportunity to join a security and compliance team focused on enterprise-wide information security policies and standards. You will track deliverables, assess risks, and partner with stakeholders to ensure policy adherence across applications.

The role emphasizes collaboration with GIS, control functions, and risk management to close gaps and drive remediation in a regulated financial services environment. This position requires vigilance and strong communication skills.

Qualifications

  • Proven experience in Information Security, Technology Risk, Compliance, or Security Controls within a large enterprise environment.
  • Strong understanding of information security policies, risk management, regulatory compliance, and control governance frameworks.
  • Experience coordinating and tracking security, risk, audit, and compliance deliverables across multiple applications or technology platforms.
  • Knowledge of vulnerability management, remediation tracking, access governance, disaster recovery, and operational resilience processes.
  • Experience supporting internal audits, regulatory examinations, risk assessments, and control testing activities.
  • Ability to partner effectively with Technology, Cybersecurity, Risk, Audit, and Infrastructure teams to drive compliance outcomes.
  • Experience managing compliance activities for vendor-supported or third-party applications.
  • Strong analytical, organizational, and problem-solving skills with attention to detail.
  • Excellent communication and stakeholder management skills, including the ability to influence and coordinate across diverse teams.
  • Ability to manage multiple priorities in a fast-paced, highly regulated environment while ensuring timely execution of control obligations.

Responsibilities

  • Supports development of enterprise-wide information security policies, procedures, and standards and industry leading information security reporting, risk scoring, and governance standards.
  • Works with internal and external stakeholders including Line of Business delegates and regulators to mitigate and remediate information security risks.
  • Ensures Information Technology systems meet enterprise standards, adhere to applicable rules, laws, and regulations, and comply with appropriate treatment of risk.
  • Identifies information security gaps and remediation strategies.
  • Analyzes existing Information Technology systems and processes to identify areas of vulnerability, provide mitigation tactics, and design and implement improved systems and processes.
  • Ensure that risk, security, and other compliance deliverables are completed on time and per requirements for the applications they support.
  • Complete administrative and non-technical tasks related to compliance deliverables (for example, access reviews, assessments, questionnaires, procedural requirements, and so on).
  • Assist with audit exams and risk assessments for the applications.
  • Track and support the technical security and risk activities performed by the development teams (for example, remediation of non-permitted technology or security vulnerabilities, technical recovery planning, disaster recovery exercises, and so on).
  • Maintain data about the application in systems of record.
  • Work closely with vendors for vendor applications to ensure the application meets bank requirements.
  • Assist with ad hoc inquiries and questions about the application.
  • Interface with technology infrastructure teams for infrastructure requirements like requests for additional storage.

Skills

Customer focus
Policy interpretation
Regulatory compliance
Risk analytics
Stakeholder management
Data governance
Problem solving
Quality assurance
Controls management
Process management

Job description

Bank of America offers an opportunity to join a security and compliance team focused on enterprise-wide information security policies and standards. You will track deliverables, assess risks, and partner with stakeholders to ensure policy adherence across applications.

The role emphasizes collaboration with GIS, control functions, and risk management to close gaps and drive remediation in a regulated financial services environment. This position requires vigilance and strong communication skills.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Info Security Controls Specialist
Info Security Controls Specialist

Bank of America • Town of Charlotte (NY)

On-site
USD 120,000 - 170,000
InfoSec Controls Mapping & Governance Lead
InfoSec Controls Mapping & Governance Lead

Bank of America • Chicago (IL)

On-site
USD 78,000 - 136,000
Benefits eligible
Paid time off
Senior Information Security Controls Mapping Lead
Senior Information Security Controls Mapping Lead

Bank of America • Denver (CO)

On-site
USD 78,000 - 136,000
Discretionary incentive eligible
Benefits eligible
Paid time off
IAM Controls Specialist: Governance, QA & Access Security
IAM Controls Specialist: Governance, QA & Access Security

Bank of America • Washington

On-site
USD 78,000 - 136,000
Competitive benefits
Paid time off
Senior Security Controls & Governance Lead
Senior Security Controls & Governance Lead

Bank of America • United States

On-site
USD 78,000 - 136,000
Discretionary incentive eligible
Benefits eligible
Information Security Officer - Cloud & Risk Steward
Information Security Officer - Cloud & Risk Steward

Bank of America • Washington

On-site
USD 99,000 - 145,000
Benefits eligible
Discretionary incentive
Strategic Business Information Security Officer
Strategic Business Information Security Officer

Bank of America • Washington

On-site
USD 99,000 - 145,000
Benefits eligible
InfoSec Controls Mapping & Governance Lead
InfoSec Controls Mapping & Governance Lead

Hobbsnews • Addison (TX), Northern (KY)

Hybrid
USD 78,000 - 136,000
Information Security Officer: Cloud Security & Risk Lead
Information Security Officer: Cloud Security & Risk Lead

Hobbsnews • Chicago (IL)

On-site
USD 99,000 - 145,000
Discretionary incentive
Benefits eligibility
InfoSec Controls Mapping & Governance Lead
InfoSec Controls Mapping & Governance Lead

Koitecc Solutions • Denver (CO), Northern (KY)

Hybrid
USD 78,000 - 136,000
Discretionary incentive plan
Benefits eligible