Product Manager – Tech Delivery - Application Security Adjudication & Risk Management

Bank of America

Denver (CO)

On-site

USD 135,000 - 217,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Benefits eligible

Job summary

Bank of America in Denver, CO seeks a Product Manager – Tech Delivery to partner with BISO and CIOs to ensure secure software delivery across the SDLC. You will analyze, validate, and adjudicate findings, guiding risk-based security decisions across enterprise systems.

The role requires deep application security expertise, collaboration with development teams, architects, and risk partners, and the ability to communicate complex findings to technical and non-technical stakeholders.

Qualifications

  • 10+ years of Information Security, Application Security, Secure Software Development, or Technology Risk Management experience.
  • 5+ years of experience in Application Security, Secure Software Development, Vulnerability Management, Security Architecture, or Information Security Risk Management.
  • Strong experience performing source code analysis, vulnerability validation, application security assessments, and security testing.
  • Subject matter expertise in Application Security, Secure SDLC, Vulnerability Management, Threat Modeling, Secure Coding Practices, OWASP Top 10, and Common Weakness Enumerations (CWE).

Responsibilities

  • Possess a strong application security background with extensive knowledge of software development methodologies, SDLC processes, software architecture, and secure coding practices.
  • Serve as the primary technical reviewer and adjudicator for application security findings generated through Checkmarx One and other approved security testing technologies.
  • Review, analyze, validate, and disposition application security findings using evidence-based technical analysis.
  • Independently validate vulnerability findings rather than relying solely on automated scanner results, developer rationale, AI-generated recommendations, or previous dispositions.
  • Analyze source code, application architecture, APIs, business logic, trust boundaries, data flows, and software design patterns to assess vulnerability validity and security impact.
  • Evaluate exploitability, reachability, attack paths, compensating controls, exposure conditions, and real-world security risk.
  • Review and validate developer-submitted adjudication requests, including Proposed Not Exploitable determinations and supporting evidence packages.

Skills

Influence
Solution Delivery Process
Stakeholder Management
Technical Strategy
Development Agile Practices
Analytical Thinking
Collaboration
Result Orientation
Risk Management
Business Acumen
Business Case Analysis
Data Management

Education

Bachelor’s and/or Master’s degree in Computer Science, Information Technology, Cybersecurity, Software Engineering, or a related field

Tools

Checkmarx One

Job description

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits. We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve. Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

The Product Manager – Tech Delivery will be a member of the Business Information Security Officer’s (BISO) organization and work closely with Line of Business (LOB) Chief Information Officers (CIOs), Chief Technology Officers (CTOs), application development teams, architects, and technology partners. In this role, you will develop a deep understanding of business applications, technology platforms, and software delivery processes to support specialized information security and application security risk discussions. This partnership helps ensure focus on the most critical security priorities while enabling secure software delivery across the Software Development Lifecycle (SDLC). The role serves as a technical Application Security subject matter expert responsible for reviewing, validating, analyzing, and adjudicating application security findings identified through enterprise security testing platforms, including Checkmarx One. This includes performing detailed source code analysis, vulnerability validation, exploitability assessments, risk evaluations, and disposition decisions to ensure security findings are accurately assessed, consistently governed, and aligned with enterprise security standards and risk-management objectives. The successful candidate will partner closely with development teams, architects, security engineers, product owners, and risk partners to drive secure development practices, vulnerability remediation, and risk-based security decision making across the enterprise.

Responsibilities
  • Possess a strong application security background with extensive knowledge of software development methodologies, SDLC processes, software architecture, and secure coding practices.
  • Serve as the primary technical reviewer and adjudicator for application security findings generated through Checkmarx One and other approved security testing technologies.
  • Review, analyze, validate, and disposition application security findings using evidence-based technical analysis.
  • Independently validate vulnerability findings rather than relying solely on automated scanner results, developer rationale, AI-generated recommendations, or previous dispositions.
  • Analyze source code, application architecture, APIs, business logic, trust boundaries, data flows, and software design patterns to assess vulnerability validity and security impact.
  • Evaluate exploitability, reachability, attack paths, compensating controls, exposure conditions, and real-world security risk.
  • Review and validate developer-submitted adjudication requests, including Proposed Not Exploitable determinations and supporting evidence packages.
Required Qualifications
  • 10+ years of Information Security, Application Security, Secure Software Development, or Technology Risk Management experience.
  • 5+ years of experience in Application Security, Secure Software Development, Vulnerability Management, Security Architecture, or Information Security Risk Management.
  • Strong experience performing source code analysis, vulnerability validation, application security assessments, and security testing.
  • Subject matter expertise in Application Security, Secure SDLC, Vulnerability Management, Threat Modeling, Secure Coding Practices, OWASP Top 10, and Common Weakness Enumerations (CWE).
  • Experience with Checkmarx One or comparable enterprise application security testing platforms.
  • Ability to evaluate, validate, and adjudicate complex SAST, SCA, API Security, and related application security findings using risk-based analysis.
  • Experience identifying false positives, exploitability constraints, compensating controls, and appropriate risk treatment strategies.
  • Strong understanding of modern application architectures, APIs, microservices, cloud-native technologies, and DevSecOps practices.
  • Experience evaluating application security controls across cloud, SaaS, PaaS, distributed, and on-premises environments.
  • Strong knowledge of NIST, ISO, PCI DSS, and related security frameworks.
  • Ability to communicate technical security findings, risk decisions, and remediation guidance to both technical and non-technical stakeholders.
  • Strong analytical, problem-solving, stakeholder management, and risk assessment skills.
Desired Qualifications
  • Bachelor’s and/or Master’s degree in Computer Science, Information Technology, Cybersecurity, Software Engineering, or a related field.
  • CISSP, CSSLP, CISM, CRISC, GIAC, OSCP, or equivalent industry certifications.
  • Experience supporting enterprise application security programs and secure software development initiatives.
  • Experience with AI-assisted development and code-analysis tools such as GitHub Copilot.
Skills
  • Financial Management
  • Influence
  • Solution Delivery Process
  • Stakeholder Management
  • Technical Strategy
  • Development Agile Practices
  • Analytical Thinking
  • Collaboration
  • Result Orientation
  • Risk Management
  • Business Acumen
  • Business Case Analysis
  • Data Management
  • Solution Design
  • Vendor Management

Shift: 1st shift (United States of America) Hours Per Week: 40

Pay

Pay Transparency details US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540)

Pay range $135,000.00 - $217,100.00 annualized salary, offers to be determined based on experience, education and skill set. Discretionary incentive eligible. This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.

Benefits

This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve. Bank of America is committed to help employees through the transition period when they’re displaced as a result of a workforce reduction, realignment or similar measure.

Resume Writing Tips

Please review the resume writing and interviewing tips provided below to help prepare you for your next career opportunity.

Getting started: Regardless of the position you are interested in, the starting points to building your resume are the same:

  1. Determine the job or types of jobs you want to do and research their responsibilities and qualifications.
  2. Think about why you can do the job and make a list of your skills that are relative to the job.
  3. Identify experiences or accomplishments that show your proficiency in the skills required for the job.
  4. Summarize your abilities, accomplishments and skills into a brief, concise document.

Considerations when writing a resume

  • Do be brief. Resumes should be 1-2 pages in length.
  • Do be upbeat and active in your wording.
  • Do emphasize what you have done clearly and concretely.
  • Do be neat and well organized.
  • Do have others proofread and critique your resume.
  • Spell check. Make it error free.
  • Do use high quality, white or light colored 8½ x 11 paper. Use a laser printer if possible.
  • Don’t be dishonest, always tell the truth about yourself in the most flattering light.
  • Don’t include salary history or requirements.
  • Don’t include references.
  • Don’t include accomplishments that do not support your professional goals.
  • Don’t include anything that isn’t relevant. (For example, don’t mention your fondness for swimming unless you want to work on the water.)
  • Don’t use italics, underlining, shadows or other fancy treatments.

Seven steps to a successful interview

  1. Anticipate –Put yourself in the interviewer's position. What do you believe the interviewer is most interested in? Why do you think you have been invited to interview?
  2. Research –What are the primary functions of the line of business? What are the success factors for the job? Is there a job description available?
  3. Assess –Think about your skills, abilities, knowledge, interests, traits, values and accomplishments. Match them to what you know about the job. Consider which ones you should highlight.
  4. Prepare Answers –Think about what the interviewer may ask, determine what the best answer is and write it down.
  5. Prepare Questions – Interviewing is a two-way street. By asking thoughtful questions, you communicate your interest and learn a lot about the job. Choose two or three questions to ask your interviewer. Avoid asking a lot of questions about vacation time or breaks.
  6. Practice – It may seem awkward, but it is the best way to come across well in an interview. Practice your own "great responses" with others or in front of a mirror until you appear relaxed and at ease.
  7. Follow-up – Send a brief follow-up letter to the interviewer. Keep in mind that the many job searchers will not send a follow-up letter. Sending one can become a competitive advantage.
Pay Transparency & Privacy

Pay Transparency - https://careers.bankofamerica.com/en-us/pay-transparency

Privacy Statement - https://careers.bankofamerica.com/en-us/privacy-notice

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Manager – Tech Delivery - Application Security Adjudication & Risk Management
Product Manager – Tech Delivery - Application Security Adjudication & Risk Management

Bank of America • Chicago (IL)

On-site
USD 135,000 - 217,000
Discretionary incentive eligible
Industry-leading benefits
Product Manager – Tech Delivery - Application Security Adjudication & Risk Management
Product Manager – Tech Delivery - Application Security Adjudication & Risk Management

Bank of America • Washington

On-site
USD 135,000 - 217,000
Product Manager – Tech Delivery - Application Security Adjudication & Risk Management
Product Manager – Tech Delivery - Application Security Adjudication & Risk Management

Socket.dev • Washington

On-site
USD 135,000 - 217,000
Product Manager - Tech Delivery - Application Security Adjudication & Risk Management
Product Manager - Tech Delivery - Application Security Adjudication & Risk Management

Koitecc Solutions • Chicago (IL), Northern (KY)

Hybrid
USD 135,000 - 217,000
Business Information Security Officer (BISO) - CFO and GRM
Business Information Security Officer (BISO) - CFO and GRM

Bank of America • Washington

On-site
USD 99,000 - 145,000
Product Manager – Tech Delivery - Application Security Adjudication & Risk Management
Product Manager – Tech Delivery - Application Security Adjudication & Risk Management

Bank of America • Washington

On-site
USD 170,000 - 210,000
TA086 - Feature Lead - Technology
TA086 - Feature Lead - Technology

Bank of America • Jersey City (NJ)

On-site
USD 107,000 - 174,000
Product Manager - Identity and Access Management (IAM) Identity/Access Lead
Product Manager - Identity and Access Management (IAM) Identity/Access Lead

Bank of America • Chicago (IL)

On-site
USD 135,000 - 217,100
Information Security Officer
Information Security Officer

Bank of America • Washington

On-site
USD 99,000 - 145,000
Benefits eligible
Discretionary incentive
Senior Cloud Security Analyst
Senior Cloud Security Analyst

Bank of America • Washington

On-site
USD 145,000 - 193,000