Information Security Officer - Global Banking & Markets (GBAM)
Washington, District of Columbia;Chicago, Illinois; Denver, Colorado
To proceed with your application, you must be at least 18 years of age.
Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Washington/Information-Security-Officer---Global-Banking---Markets--GBAM-_26025249)
Bank of America employees are required to meet all posting eligibility requirements prior to applying for any new position.
Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Washington/Information-Security-Officer---Global-Banking---Markets--GBAM-_26025249)
Refer a friend
To proceed with your application, you must be at least 18 years of age.
Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Washington/Information-Security-Officer---Global-Banking---Markets--GBAM-_26025249)
Bank of America employees are required to meet all posting eligibility requirements prior to applying for any new position.
Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Washington/Information-Security-Officer---Global-Banking---Markets--GBAM-_26025249)
Job Description:
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates' physical, emotional, and financial wellness through affordable, competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Job Description:
The Information Security Officer (ISO) will serve as a key member of the Business Information Security Officer (BISO) organization, partnering closely with Global Banking & Markets (GBAM) Chief Information Officers (CIOs), Chief Technology Officers (CTOs), and business stakeholders to develop a deep understanding of business objectives, technology strategy, and associated cybersecurity risks.
Through strong partnerships and risk-based engagement, the ISO will provide strategic security guidance, challenge and oversight, helping ensure information security risks are effectively identified, assessed, and managed in alignment with enterprise policies, standards, and regulatory expectations. The successful candidate will become a trusted advisor to senior stakeholders, enabling informed risk decisions while supporting business innovation and growth.
Responsibilities
Serve as the primary information security advisor and point of contact for assigned GBAM, providing guidance on cybersecurity risks, policies, standards, and controls.
Act as a subject matter expert in the development, implementation, and ongoing oversight of information security practices within the line of business.
Provide independent risk-based challenge and advisory support for technology initiatives, strategic programs, and implementation changes across the GBAM environment.
Influence and advocate for the prioritization of investments that strengthen the organization's security posture and reduce risk.
Advise business and technology leadership on cybersecurity risk issues and recommend actions that support the bank's broader risk management, regulatory, and compliance objectives.
Collaborate with Risk, Technology, and Control partners to enhance security processes, governance frameworks, and risk management capabilities.
Partner with the Global BISO organization to ensure GIS policies, standards, requirements, and strategic initiatives are communicated, understood, and effectively implemented.
Establish and maintain strong relationships across business, technology, risk, and control functions to facilitate effective security risk management.
Conduct routine coordination with risk partners and technology teams to address vulnerabilities, control gaps, and remediation activities, with a focus on issues identified as elevated risk.
Drive remediation efforts for cybersecurity issues and support stakeholders in achieving sustainable solutions aligned with GIS standards, baselines, and control requirements.
Support ad hoc security consultations, risk assessments, governance activities, and executive reporting as required.
Required Qualifications
Experience within information security, cybersecurity engineering, technology risk management, security operations, or security consulting functions.
Strong understanding of security controls, risk management practices, and cybersecurity frameworks applicable to enterprise systems, applications, cloud platforms, and network environments.
Demonstrated ability to communicate, influence, and negotiate effectively with senior business and technology leaders.
Strong analytical and problem-solving skills with the ability to assess risk and provide practical, business-aligned recommendations.
Understanding of vulnerability management concepts, associated tooling, and remediation governance processes.
Ability to independently manage competing priorities and oversee a diverse portfolio of work.
Strong communication and stakeholder management skills, including the ability to deliver challenging messages and drive issue resolution.
Proven ability to build relationships, establish credibility, and operate effectively across complex organizational environments.
Desired Qualifications
Experience with Artificial Intelligence (AI) governance, AI risk management, and responsible AI practices, including familiarity with emerging regulatory requirements, AI security controls, model risk considerations, and governance frameworks supporting the secure adoption of AI technologies.
Experience within large-scale technology and financial services organizations, with strong knowledge of application security risks, controls, and secure development practices.
Experience conducting formal security risk assessments and facilitating risk-based decision-making.
Deep technical understanding of technology infrastructure, cloud platforms, application architectures, and operational security practices.
Previous experience working within a highly regulated financial institution.
Demonstrated ability to work collaboratively within a matrixed Global Information Security organization.
Excellent verbal, written, and executive briefing skills, with experience producing management-level reporting and presentations.
Preferred Leadership Attributes
Trusted advisor mindset with strong business acumen.
Ability to balance risk management objectives with business enablement.
Proven capability to influence without direct authority across multiple organizations.
Strategic thinker with the ability to translate complex security risks into clear business outcomes and actionable recommendations.
Required Skills
Controls Management
Cyber Security
Data Governance
Information Systems Management
Risk Management
Architecture
Customer and Client Focus
Executive Presence
Threat Analysis1
-
Vendor Management
Shift:
1st shift (United States of America)
Hours Per Week:
40
Bank of America and its affiliates consider for employment and hire qualified candidates without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity, in accordance with all applicable federal, state, provincial and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our teammates.
View your "Know your Rights (https://www.eeoc.gov/sites/default/files/2023-06/22-088\EEOC\KnowYourRights6.12.pdf) " poster.
View the LA County Fair Chance Ordinance (https://dcba.lacounty.gov/wp-content/uploads/2024/08/FCOE-Official-Notice-Eng-Final-8.30.2024.pdf) .
Bank of America aims to create a workplace free from the dangers and resulting consequences of illegal and illicit drug use and alcohol abuse. Our Drug-Free Workplace and Alcohol Policy ("Policy") establishes requirements to prevent the presence or use of illegal or illicit drugs or unauthorized alcohol on Bank of America premises and to provide a safe work environment.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. Should you be offered a role with Bank of America, your hiring manager will provide you with information on the in-office expectations associated with your role. These expectations are subject to change at any time and at the sole discretion of the Company. To the extent you have a disability or sincerely held religious belief for which you believe you need a reasonable accommodation from this requirement, you must seek an accommodation through the Bank's required accommodation request process before your first day of work.
This communication provides information about certain Bank of America benefits. Receipt of this document does not automatically entitle you to benefits offered by Bank of America. Every effort has been made to ensure the accuracy of this communication. However, if there are discrepancies between this communication and the official plan documents, the plan documents will always govern. Bank of America retains the discretion to interpret the terms or language used in any of its communications according to the provisions contained in the plan documents. Bank of America also reserves the right to amend or terminate any benefit plan in its sole discretion at any time for any reason.