Information Security Officer
Bank of America · Chicago, IL · Yesterday
Information TechnologyFull-time
About the role
The Information Security Officer will be a member of the Business Information Security Officer's (BISO) organization and partners with the Global Business Services (GBS) Line of Business and Technology Leaders (GDLs). In this role, you will support a group/team in developing business insight for focused information security risk discussions. This relationship will ensure a focus on the right risk priorities. You will also provide guidance on information security topics, policies and controls.
Responsibilities
- Contribute to the ongoing information security initiatives and improvements development, implementation and maintenance of information security for the line of business (LOB)
- Possess strong / experienced application development and/or application security background; with solid knowledge of SDLC from design, testing, deployment to post-production and the different risk elements associated with each step
- Serves as an Information Security subject matter expert and participates in the development, implementation and maintenance of information security for the line of business (LOB)
- Provides guidance and advocacy regarding the prioritization of LOB investments that impact information security
- Advises LOB management on risk issues related to information security and recommends actions in support of the bank's wider risk management and compliance programs
- Monitors information security trends internal and external to the bank and keeps LOB/CIO Partners informed about information security-related issues
- Manages quality control and reporting
- Ensures compliance with policies and laws
- Drives GIS/LOB risk deliverables
- Collaborates with risk partners on info security critical priorities
- Participates in senior LOB specific Risk Management & Business Continuity Routines
- Identifies and measures global information security (GIS) controls on most critical business processes or channels
- Has a working knowledge of security for computing platforms (PaaS)
- Has a solid grasp of security in big data and other instructed large data structures
- Ability to build strong Partner relationships with peer technology groups and supported LOB
- Supports the triage process with the client and helps them understand the GIS support structure
- Drives required risk culture and partnership with peer technology teams and supported LOB
- Participates in key CIO/COO operating routines to drive information security risk strategy
Required Qualifications
- 2-5 years of experience in technology and 5+ years in information security
- 2-5 years of experience in application development or application security
- Experience working on cloud implementations in Microsoft Azure, Amazon Web Services and Google Cloud Platform environments
- Must display subject matter experience in application security, vulnerability testing, system testing, and/or Agile lifecycle management
- Strong LOB knowledge/experience for the type of business they are aligned to (e.g. CSBB/GBM)
- 1-2 years of risk management experience or direct participation in risk management processes, including application risk classification and application control assessments
- Experience giving presentations and superb communication skills
Desired Qualifications
- Bachelor's and/or Master's degree in Computer Science, Information Technology or related field
Required Skills
- Controls Management
- Cyber Security
- Data Governance
- Information Systems Management
- Risk Management
- Architecture
- Customer and Client Focus
- Executive Presence
- Threat Analysis
- Vendor Management
- Self-Starter
- Emotional Intelligence
Schedule
1st shift (United States of America)