Third Party Cyber Security Assessor

Bank of America

Denver (CO)

On-site

USD 90,000 - 130,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Bank of America is seeking an information security professional to perform third-party security assessments, traveling to sites to review documentation such as playbooks and evidence, and documenting controls in assessment workpapers. The role requires evaluating third-party risk and communicating findings to relevant stakeholders.

Responsibilities include partnering with vendors, identifying gaps, and managing relationships with Enterprise Vendor Managers; travel up to 10–15% as needed to

Qualifications

  • 2+ years of experience in information security and/or IT audit.
  • Strong written and verbal communication skills.
  • Ability to work with partners at varying knowledge levels.
  • Ability to translate technical concepts for business partners.
  • Familiarity with information security controls and standards.

Responsibilities

  • Perform information security reviews of third parties providing services to the bank.
  • Travel onsite with third parties to collect and review documentation.
  • Assess security controls and document findings in workpapers.
  • Escalate issues or risks identified during assessments.
  • Manage relationships with vendors and Enterprise Vendor Managers.

Skills

InfoSec & IT Audit
Technical writing
Verbal communication
Stakeholder communication
Risk assessment

Job description

Job Description: At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.

Job Description: At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.

Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.

We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.

Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.

At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

Position Summary

This job is responsible for performing information security reviews of third parties that provide services to the bank. Key responsibilities include travelling to work onsite with third parties to collect and review documentation including playbooks and evidence during an assessment to determine if information security controls are in place and documenting the controls in place in assessment workpapers. Key responsibilities span pre-assessment, assessment, and/or remediation activities.

Responsibilities
  • Partners with third parties to ensure they are prepared for information security assessments including answering detailed questions
  • Evaluates a third parties information security risk with a holistic lens to determine if they meet Bank of America requirements
  • Discusses any information security gaps in the service provider's program with the third party
  • Escalates issues or risks identified during the assessment
  • Manage relationships with third parties and Enterprise Vendor Managers
  • Must be able to travel up to 10-15% (i.e. once every other month)
  • The ability to interact with internal or external stakeholders including business partners and/or external parties to identify, analyze, and resolve complex problems or security gaps.
  • The ability to objectively assess information from various sources and synthesize it towards making a reasoned judgment
  • The ability to assess the security, effectiveness, and practicality of technology systems.
Required Qualifications
  • 2+ years Experience in Information Security and/or IT Audit
  • Technical writing and verbal communication skills
  • Ability to effectively work with partners at varying knowledge and organization levels.
  • Ability to communicate clearly and effectively with both technology/development and business partners – ability to translate between these two constituencies.
  • Technical skills include the domains of information security and business continuity including:
  • Information Security Controls (Infrastructure Security, Access Management, Physical Security, Application Security, etc.)
  • IT Compliance, SOX Compliance
  • Change Management
  • Enterprise Risk Management
  • Solid grasp of NIST, PCI, ISO, SDLC, COBIT, and ITIL standards.
Desired Qualifications
  • Information Security certifications, including ISO27002 / CISSP / CEH / CISM / CISA
  • Knowledge of NIST guidelines

This job will be open and accepting applications for a minimum of seven days from the date it was posted

Shift: 1st shift (United States of America)

Hours Per Week: 40

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Third Party Cyber Security Assessor
Third Party Cyber Security Assessor

Bank of America • Washington

On-site
USD 95,000 - 143,600
Annual discretionary award based on performance
Industry-leading benefits
Paid time off
Onsite Third-Party Cybersecurity Assessor
Onsite Third-Party Cybersecurity Assessor

Bank of America • Denver (CO)

On-site
USD 90,000 - 130,000
Information Security Officer – Global Banking & Markets (GBAM)
Information Security Officer – Global Banking & Markets (GBAM)

Bank of America • Denver (CO)

On-site
USD 130,000 - 180,000
Senior Manual Ethical Hacker
Senior Manual Ethical Hacker

Bank of America • Denver (CO)

On-site
USD 160,000 - 205,000
Senior Manual Ethical Hacker
Senior Manual Ethical Hacker

Bank of America • Charlotte (NC)

On-site
USD 100,000 - 140,000
Information Security Officer – Global Banking & Markets (GBAM)
Information Security Officer – Global Banking & Markets (GBAM)

Bank of America • Chicago (IL)

On-site
USD 120,000 - 170,000
Senior Manual Ethical Hacker
Senior Manual Ethical Hacker

Bank of America • Seattle (WA)

On-site
USD 100,000 - 130,000
Senior Manual Ethical Hacker
Senior Manual Ethical Hacker

Koitecc Solutions • Denver (CO)

On-site
USD 160,000 - 205,000
Senior Manual Ethical Hacker
Senior Manual Ethical Hacker

Bank of America • Jersey City (NJ)

On-site
USD 160,000 - 205,000
Paid time off
Annual discretionary awards
Third Party Cyber Security Assessor
Third Party Cyber Security Assessor

Jobtailor • Colorado

On-site
USD 90,000 - 130,000