Jobs · Information Technology · Colorado

Information Security Officer – Global Banking & Markets (GBAM)

Bank of America · Denver, CO · 4 days ago
Information TechnologyFull-time

Responsibilities

  • Serve as the primary information security advisor and point of contact for assigned GBAM, providing guidance on cybersecurity risks, policies, standards, and controls.
  • Act as a subject matter expert in the development, implementation, and ongoing oversight of information security practices within the line of business.
  • Provide independent risk-based challenge and advisory support for technology initiatives, strategic programs, and implementation changes across the GBAM environment.
  • Influence and advocate for the prioritization of investments that strengthen the organization's security posture and reduce risk.
  • Advise business and technology leadership on cybersecurity risk issues and recommend actions that support the bank’s broader risk management, regulatory, and compliance objectives.
  • Collaborate with Risk, Technology, and Control partners to enhance security processes, governance frameworks, and risk management capabilities.
  • Partner with the Global BISO organization to ensure GIS policies, standards, requirements, and strategic initiatives are communicated, understood, and effectively implemented.
  • Establish and maintain strong relationships across business, technology, risk, and control functions to facilitate effective security risk management.
  • Conduct routine coordination with risk partners and technology teams to address vulnerabilities, control gaps, and remediation activities, with a focus on issues identified as elevated risk.
  • Drive remediation efforts for cybersecurity issues and support stakeholders in achieving sustainable solutions aligned with GIS standards, baselines, and control requirements.
  • Support ad hoc security consultations, risk assessments, governance activities, and executive reporting as required.

Requirements

  • Experience within information security, cybersecurity engineering, technology risk management, security operations, or security consulting functions.
  • Strong understanding of security controls, risk management practices, and cybersecurity frameworks applicable to enterprise systems, applications, cloud platforms, and network environments.
  • Demonstrated ability to communicate, influence, and negotiate effectively with senior business and technology leaders.
  • Strong analytical and problem-solving skills with the ability to assess risk and provide practical, business-aligned recommendations.
  • Understanding of vulnerability management concepts, associated tooling, and remediation governance processes.
  • Ability to independently manage competing priorities and oversee a diverse portfolio of work.
  • Strong communication and stakeholder management skills, including the ability to deliver challenging messages and drive issue resolution.
  • Proven ability to build relationships, establish credibility, and operate effectively across complex organizational environments.

Desired Qualifications

  • Experience with Artificial Intelligence (AI) governance, AI risk management, and responsible AI practices, including familiarity with emerging regulatory requirements, AI security controls, model risk considerations, and governance frameworks supporting the secure adoption of AI technologies.
  • Experience within large-scale technology and financial services organizations, with strong knowledge of application security risks, controls, and secure development practices.
  • Experience conducting formal security risk assessments and facilitating risk-based decision-making.
  • Deep technical understanding of technology infrastructure, cloud platforms, application architectures, and operational security practices.
  • Previous experience working within a highly regulated financial institution.
  • Demonstrated ability to work collaboratively within a matrixed Global Information Security organization.
  • Excellent verbal, written, and executive briefing skills, with experience producing management-level reporting and presentations.

Preferred Leadership Attributes

  • Trusted advisor mindset with strong business acumen.
  • Ability to balance risk management objectives with business enablement.
  • Proven capability to influence without direct authority across multiple organizations.
  • Strategic thinker with the ability to translate complex security risks into clear business outcomes and actionable recommendations.

Shift

1st shift (United States of America)

Hrs Per Week

40

Similar jobs