Third Party Cyber Security Assessor

Bank of America

Washington (District of Columbia)

On-site

USD 95,000 - 143,600

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Annual discretionary award based on performance
Industry-leading benefits
Paid time off

Job summary

Bank of America is looking for a professional to perform information security reviews of third-party vendors. The role requires evaluating a vendor’s security and compliance with the bank's standards and includes up to 10-15% travel for assessments.

The ideal candidate will have at least 3 years of experience in Information Security or IT Audit, strong communication skills, and knowledge of security controls and compliance measures. This position offers a competitive salary range of $95,000 to $143,600 annually.

Qualifications

  • Proven experience in information security and IT audit.
  • Strong technical writing and communication skills.
  • Ability to work effectively with varied partners and stakeholders.

Responsibilities

  • Conduct information security reviews of third parties providing services.
  • Manage relationships with third parties and escalate issues as needed.
  • Evaluate third party information security risks.

Skills

Information Security
Technical writing
Verbal communication
Risk Management
IT Compliance

Education

3 Years experience in Information Security and/or IT Audit

Tools

NIST standards
ISO27002 certification
CISSP certification
CEH certification
CISM certification
CISA certification

Job description

Position Summary:

This job is responsible for performing information security reviews of third parties that provide services to the bank. Key responsibilities include occasionally travelling to work onsite with third parties to collect and review documentation, including playbooks and evidence, during an assessment to determine if information security controls are in place and documenting the controls in assessment workpapers. Key responsibilities span pre‑assessment, assessment, and/or remediation activities.

Responsibilities:
  • Partners with third parties to ensure they are prepared for information security assessments including answering detailed questions
  • Evaluates a third parties information security risk with a holistic lens to determine if they meet Bank of America requirements
  • Discusses any information security gaps in the service provider's program with the third party
  • Escalates issues or risks identified during the assessment
  • Manages relationships with third parties and Enterprise Vendor Managers
  • Must be able to travel up to 10‑15% (i.e. once every other month)
  • The ability to interact with internal or external stakeholders including business partners and/or external parties to identify, analyze, and resolve complex problems or security gaps.
  • The ability to objectively assess information from various sources and synthesize it towards making a reasoned judgment
  • The ability to assess the security, effectiveness, and practicality of technology systems.
Required Qualifications:
  • 3 Years experience in Information Security and/or IT Audit
  • Technical writing and verbal communication skill
  • Ability to effectively work with partners at varying knowledge and organization levels.
  • Ability to communicate clearly and effectively with both technology/development and business partners - ability to translate between these two constituencies.
  • Technical skills include the domains of information security and business continuity including:
  • Security Controls (Infrastructure Security, Access Management, Physical Security, Application Security, etc.)
  • IT Compliance, SOX Compliance
  • Change Management
  • Enterprise Risk Management
  • Solid grasp of NIST, PCI, ISO, SDLC, COBIT, and ITIL standards
Desired Qualifications:
  • Information Security certifications, including ISO27002 / CISSP / CEH / CISM / CISA
  • Knowledge of NIST guidelines
Shift:

1st shift (United States of America)

Hours Per Week:

40

Pay Range:

$95,000.00 - $143,600.00 annualized salary, offers to be determined based on experience, education and skill set.

Discretionary Incentive Eligibility:

This role is eligible to participate in the annual discretionary plan. Employees may receive an annual discretionary award based on performance and contributions to the company.

Benefits:

This role is currently benefits eligible. We provide industry-leading benefits, paid time off, resources and support to help employees make a genuine impact and contribute to sustainable growth.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Third Party Cyber Security Assessor
Third Party Cyber Security Assessor

Bank of America • Denver (CO)

On-site
USD 90,000 - 130,000
Senior Manual Ethical Hacker
Senior Manual Ethical Hacker

Bank of America • Jersey City (NJ)

On-site
USD 160,000 - 205,000
Paid time off
Annual discretionary awards
Onsite Third-Party Cybersecurity Assessor
Onsite Third-Party Cybersecurity Assessor

Bank of America • Denver (CO)

On-site
USD 90,000 - 130,000
Senior Manual Ethical Hacker
Senior Manual Ethical Hacker

Bank of America • Washington

On-site
USD 98,000 - 135,000
Industry-leading benefits
Paid time off
Annual discretionary bonus
Information Security Officer - Global Banking & Markets (GBAM)
Information Security Officer - Global Banking & Markets (GBAM)

Bank of America • Washington

On-site
USD 99,000 - 145,000
Annual discretionary plan
Benefits eligible
Senior Manual Ethical Hacker
Senior Manual Ethical Hacker

Koitecc Solutions • Denver (CO)

On-site
USD 160,000 - 205,000
Information Security Officer - Global Banking & Markets (GBAM)
Information Security Officer - Global Banking & Markets (GBAM)

Bank of America • Chicago (IL)

On-site
USD 99,000 - 145,000
Discretionary incentive eligible
Benefits eligible
Senior Manual Ethical Hacker
Senior Manual Ethical Hacker

Bank of America • Denver (CO)

On-site
USD 160,000 - 205,000
Information Security Officer - Global Banking & Markets (GBAM)
Information Security Officer - Global Banking & Markets (GBAM)

Bank of America • Denver (CO)

On-site
USD 99,000 - 145,000
Benefits eligible
Annual discretionary plan
Senior Manual Ethical Hacker
Senior Manual Ethical Hacker

Bank of America • Seattle (WA)

On-site
USD 160,000 - 205,000
Industry-leading benefits
Paid time off
Discretionary incentive