Compliance and Operational Risk Manager - Application Security and Technology Risk Oversight
Charlotte, North Carolina;Chicago, Illinois; Pennington, New Jersey; Plano, Texas
To proceed with your application, you must be at least 18 years of age.
Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Charlotte/Compliance-and-Operational-Risk-Manager---Application-Security-and-Technology-Risk-Oversight_26030466-2)
Bank of America employees are required to meet all posting eligibility requirements prior to applying for any new position.
Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Charlotte/Compliance-and-Operational-Risk-Manager---Application-Security-and-Technology-Risk-Oversight_26030466-2)
Refer a friend
To proceed with your application, you must be at least 18 years of age.
Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Charlotte/Compliance-and-Operational-Risk-Manager---Application-Security-and-Technology-Risk-Oversight_26030466-2)
Bank of America employees are required to meet all posting eligibility requirements prior to applying for any new position.
Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Charlotte/Compliance-and-Operational-Risk-Manager---Application-Security-and-Technology-Risk-Oversight_26030466-2)
Job Description:
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates' physical, emotional, and financial wellness through affordable, competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Job Description:
This job is responsible for executing second line of defense compliance and operational risk oversight for a Front Line Unit, Control Function, and/or Third Parties. Key responsibilities include ensuring requirements of the Global Compliance Enterprise Policy, the Operational Risk Management Enterprise Policy (collectively "the Policies"), the Compliance and Operational Risk Management Program and Standard Operating Procedures are implemented and identifying, challenging, escalating, and mitigating risks in a timely manner.
This role is responsible for providing independent second line of defense compliance and operational risk oversight across Front Line Units, Control Functions, and Third Parties. The position ensures adherence to the Global Compliance and Operational Risk Management framework, delivers effective challenge, and supports the timely identification, assessment, escalation, and mitigation of compliance and operational risks.
We are seeking an experienced Compliance & Operational Risk Manager to provide independent second line oversight of the Bank's most highest risk technology environments, including Application and Technology Security Assessments, Technology Third Party Risk Management, and emerging technology risks. This role serves as a trusted advisor and effective challenger to senior technology leaders, providing risk oversight, governance, and strategic advisory to support the Bank's cybersecurity, operational resilience, and regulatory objectives.
Responsibilities:
Assesses risks and effectiveness of Front-Line Unit (FLU) processes and controls to ensure compliance with applicable laws, rules, and regulations, while responding to regulatory inquiries, other audits, and examinations
Engages in activities to provide independent compliance and operational risk oversight of FLU or Control Function (CF) performance and any related third party/vendor relationships in alignment with the Global Compliance - Enterprise Policy, the Operational Risk Management - Enterprise Policy (collectively the Policies) and the Compliance and Operational Risk Management Program and Standard Operating Procedures
Identifies and escalates problems or issues that arise and drives actions to address the root causes that lead to compliance risk issues and/or operational risk losses
Monitors inventory of processes, risks, controls, and associated metrics for risk appetite and limits, reporting violations of compliance or regulatory activities
Assists in the development of independent risk management reporting for respective area(s) of coverage as input into country/regional governance and management routines
Analyzes and interprets applicable laws, rules, and regulations to provide clear and practical advice to stakeholders, and identify and manage risks
Reviews and challenges FLU/CF process, risk, Single Process Inventory, and FLU/CF Risk and Control Self-Assessment related to themes or trends, while monitoring the regulatory environment to identify regulatory changes applicable to area(s) of coverage
Monitor and assess adherence to Global Technology policies and standards
Perform inline review of ITGPST issue management activities, including remediation of regulatory issues
Providing independent second line oversight of the Bank's Application and Technology Security Assessment program, including assessment of control effectiveness, risk identification, issue management, and regulatory compliance.
Assessing technology and cyber risks across critical applications, business processes, and technology environments.
Reviewing and challenging risk acceptance decisions, remediation strategies, and control design associated with application security risks.
Monitoring emerging technology and AI-related risks, evaluating evolving cyber threats, governance frameworks, and control environments to ensure appropriate risk management practices.
Supporting executive reporting, governance routines, and strategic communications for senior leadership audiences.
Evaluating adherence to enterprise risk management standards, technology policies, and regulatory expectations.
Partnering across technology, cybersecurity, risk, audit, and business teams to strengthen operational resilience and risk management practices.
Required Qualifications:
7+ years of experience in operational risk, technology risk, information security, cybersecurity, , compliance, audit, or related risk management disciplines preferably within a large financial institution
Demonstrated expertise in cybersecurity, application security, technology governance, third-party technology risk management, or operational resilience.
Proven ability to influence and challenge senior leaders and executive stakeholders while maintaining effective partnerships.
Experience supporting regulatory examinations, audit engagements, issue remediation programs, and risk governance activities.
Proven background in risk-related disciplines; strong experience with the Global Compliance & Operational Risk program from a 1st or 2nd line perspective.
Communicates with clarity and impact; comfortable engaging at the executive level and shaping outcomes.
Understanding of AI-related risks, governance considerations, cybersecurity implications, and the application of technology-enabled solutions to support risk management activities.
Familiarity with GCOR programs, Global Technology policies, and ITGPST processes and risks
Skilled in identifying, assessing, and remediating operational risks and issues.
Proficient in generating actionable insights through data analysis and reporting tools.
Builds trust, challenges constructively, and partners effectively across the enterprise.
Proficient in industry security frameworks (e.g., NIST CSF) and applicable Laws, Rules and Regulations.
Desired Qualifications:
Familiarity with Application Technology Security Assessments, vulnerability management, software development lifecycle controls, or application security testing programs.
Understanding of emerging technology risks, including AI governance, model risk considerations, and cybersecurity implications of AI-enabled technologies.
Professional certifications such as CISSP, CISM, CRISC, CISA, or equivalent risk and technology certifications.
Second or third line of defense experience or experience in a business risk and controls role
Strong familiarity with the Global Compliance & Operational Risk (GCOR) program and related tools / applications
Familiarity with the Issues Management program and tools
Demonstrated success leading targeted assessments, audits, or regulatory exam engagements, including authoring responses, report outs and observations
Constructively challenges; supports opinion and recommendations with facts and data
Demonstrates productive partnering with various stakeholders across the enterprise at all levels
Skills:
Advisory
Monitoring, Surveillance, and Testing
Regulatory Compliance
Reporting
Risk Management
Critical Thinking
Influence
Interpret Relevant Laws, Rules, and Regulations
Issue Management
Policies, Procedures, and Guidelines Management
Business Process Analysis
Decision Making
Negotiation
Process Management
Written Communications
Shift:
1st shift (United States of America)
Hours Per Week:
40
Bank of America and its affiliates consider for employment and hire qualified candidates without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity, in accordance with all applicable federal, state, provincial and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our teammates.
View your "Know your Rights (https://www.eeoc.gov/sites/default/files/2023-06/22-088\EEOC\KnowYourRights6.12.pdf) " poster.
View the LA County Fair Chance Ordinance (https://dcba.lacounty.gov/wp-content/uploads/2024/08/FCOE-Official-Notice-Eng-Final-8.30.2024.pdf) .
Bank of America aims to create a workplace free from the dangers and resulting consequences of illegal and illicit drug use and alcohol abuse. Our Drug-Free Workplace and Alcohol Policy ("Policy") establishes requirements to prevent the presence or use of illegal or illicit drugs or unauthorized alcohol on Bank of America premises and to provide a safe work environment.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. Should you be offered a role with Bank of America, your hiring manager will provide you with information on the in-office expectations associated with your role. These expectations are subject to change at any time and at the sole discretion of the Company. To the extent you have a disability or sincerely held religious belief for which you believe you need a reasonable accommodation from this requirement, you must seek an accommodation through the Bank's required accommodation request process before your first day of work.
This communication provides information about certain Bank of America benefits. Receipt of this document does not automatically entitle you to benefits offered by Bank of America. Every effort has been made to ensure the accuracy of this communication. However, if there are discrepancies between this communication and the official plan documents, the plan documents will always govern. Bank of America retains the discretion to interpret the terms or language used in any of its communications according to the provisions contained in the plan documents. Bank of America also reserves the right to amend or terminate any benefit plan in its sole discretion at any time for any reason.
Investment products offered through MLPF&S and insurance and annuity products offered through MLLA:
Are Not FDIC Insured Are Not Bank Guaranteed May Lose Value
Are Not Deposits Are Not Insured by Any Federal Government Agency Are not a condition to Any Banking Service or Activity
Merrill Lynch, Pierce, Fenner & Smith Incorporated (also referred to as "MLPF&S" or "Merrill") makes available certain investment products sponsored, managed, distributed or provided by companies that are affiliates of Bank of America Corporation ("BofA Corp."). MLPF&S is a registered broker-dealer, registered investment adviser, Member SIPC and a wholly owned subsidiary of BofA Corp. Insurance and annuity products are offered through Merrill Lynch Life Agency Inc., a licensed insurance agency and wholly owned subsidiary of Bank of America Corporation.
Trust, fiduciary and investment management services are provided by Bank of America, N.A., Member FDIC and wholly owned subsidiary of Bank of America Corporation ("BofA Corp.").
Bank of America Private Bank is a division of Bank of America, N.A.
Banking products are provided by Bank of America, N.A. and affiliated banks, Members FDIC and wholly owned subsidiaries of Bank of America Corporation.
© 2026 Bank of America Corporation. All rights reserved.