Senior Security Controls & Governance Lead

Bank of America

United States

On-site

USD 78,000 - 136,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Discretionary incentive eligible
Benefits eligible

Job summary

Bank of America is seeking an information security professional to join the Controls Mapping Governance team in the United States. You will interpret laws, identify and map controls to requirements, and assess the coverage across security domains.

The role demands collaboration with process owners, auditors, and regulators to ensure defensible mappings and continuous improvement of governance processes. Responsibilities include reviewing procedures, evidentiary artifacts, and control

Qualifications

  • 3+ years of experience in information security, cybersecurity risk, technology risk, controls governance, policy governance, compliance, audit, or a related field within a regulated environment.
  • Working knowledge of cybersecurity concepts, technology infrastructure, and security domains such as IAM, network security, cloud security, application security, data protection, vulnerability management, monitoring, incident response, or configuration management.
  • Ability to understand how security processes and controls operate across systems, applications, infrastructure, data, users, and technologies, without needing to be an engineer or SME in every domain.
  • Experience reviewing technical procedures, process flows, control descriptions, system documentation, and evidence artifacts to identify incomplete responses, unsupported conclusions, exclusions, failure conditions, or gaps in coverage.
  • Strong analytical and communication skills, including the ability to question technical subject matter experts constructively, distinguish direct coverage from general alignment, and document clear, defensible mapping decisions for technical and senior audiences.
  • Ability to evaluate and independently validate data against authoritative requirements, approved inventories, owner responses, and supporting evidence rather than relying solely on owner conclusions.

Responsibilities

  • Interpret laws, rules, regulations, policies, and standards; break complex requirements into individual must statements; and define the required outcome, scope, accountable parties, and expected evidence.
  • Identify and assess candidate processes, controls; develop preliminary coverage recommendations; and determine whether coverage is direct, supporting, partial, or insufficient.
  • Review technical processes and challenge owner responses to determine whether the documented activity, scope, ownership, dependencies, limitations, and evidence support the proposed mapping.
  • Document clear, defensible mapping decisions and determine whether proposed coverage should be accepted, clarified, treated as partial or a gap, or escalated through established governance channels.
  • Use data and approved tools to support requirement interpretation, coverage identification, response review, reporting, and process improvement, while independently validating all outputs and maintaining decision accountability.

Skills

Information security
Cybersecurity risk
Analytical thinking

Education

Cybersecurity certification

Tools

SharePoint workflows

Job description

Bank of America is seeking an information security professional to join the Controls Mapping Governance team in the United States. You will interpret laws, identify and map controls to requirements, and assess the coverage across security domains.

The role demands collaboration with process owners, auditors, and regulators to ensure defensible mappings and continuous improvement of governance processes. Responsibilities include reviewing procedures, evidentiary artifacts, and control

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Security Controls Mapping Lead
Senior Information Security Controls Mapping Lead

Bank of America • Denver (CO)

On-site
USD 78,000 - 136,000
Discretionary incentive eligible
Benefits eligible
Paid time off
InfoSec Controls Mapping & Governance Lead
InfoSec Controls Mapping & Governance Lead

Bank of America • Chicago (IL)

On-site
USD 78,000 - 136,000
Benefits eligible
Paid time off
InfoSec Controls Mapping & Governance Lead
InfoSec Controls Mapping & Governance Lead

Koitecc Solutions • Denver (CO), Northern (KY)

Hybrid
USD 78,000 - 136,000
Discretionary incentive plan
Benefits eligible
InfoSec Controls Mapping Lead
InfoSec Controls Mapping Lead

Bank of America • Addison (TX)

On-site
USD 78,000 - 136,000
InfoSec Controls Mapping Lead
InfoSec Controls Mapping Lead

Bank of America • Washington

On-site
USD 78,000 - 136,000
InfoSec Controls Mapping & Governance Lead
InfoSec Controls Mapping & Governance Lead

Hobbsnews • Addison (TX), Northern (KY)

Hybrid
USD 78,000 - 136,000
Controls Mapping Governance Lead - Global Information Security
Controls Mapping Governance Lead - Global Information Security

Hobbsnews • Addison (TX), Northern (KY)

Hybrid
USD 78,000 - 136,000
Controls Mapping Governance Lead - Global Information Security
Controls Mapping Governance Lead - Global Information Security

Bank of America • Washington

On-site
USD 78,000 - 136,000
Controls Mapping Governance Lead - Global Information Security
Controls Mapping Governance Lead - Global Information Security

Bank of America • Addison (TX)

On-site
USD 78,000 - 136,000
Controls Mapping Governance Lead - Global Information Security
Controls Mapping Governance Lead - Global Information Security

Bank of America • Denver (CO)

On-site
USD 78,000 - 136,000
Discretionary incentive eligible
Benefits eligible
Paid time off