Information Security Transformation Lead - Data Leakage Prevention
Job Description:
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates' physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Job Description:
The Information Security Transformation Lead will drive the design, integration, and execution of enterprise-wide transformation initiatives to strengthen data protection and data security capabilities within the Data Loss Prevention (DLP) organization. The role spans all DLP channels - endpoint, network, cloud, email, internet, and data at rest - ensuring the program evolves to meet advanced threats, regulatory requirements, and strategic business needs.
This highly technical position demands deep expertise in information security architecture, engineering, and threat detection with a proven track record in implementing modern, scalable, and secure data protection capabilities. The Transformation Lead serves as the strategic and technical lead for DLP transformation, ensuring the DLP organization delivers best-in-class data protection capabilities across all channels.
Key Responsibilities
- Own the DLP transformation roadmap for data protection and data security across all channels, aligning with enterprise information security architecture and DLP strategy.
- Conduct deep technical assessments of DLP and adjacent security capabilities, identifying architecture, tooling, and process gaps.
- Partner with control owners to develop functional and non-functional requirements for new capabilities, ensuring alignment to threat models and compliance requirements.
- Architect and guide the delivery of integrated data protection solutions, incorporating DLP tooling, encryption, cloud-native controls, and internet security capabilities.
- Develop and maintain threat models for data exfiltration and insider threat scenarios, mapping to frameworks such as MITRE ATT&CK.
- Oversee technical design for secure internet traffic inspection, advanced policy enforcement, and automation for faster detection and response.
- Ensure all transformation efforts meet regulatory, audit, and security policy standards (e.g., NIST 800-53, FFIEC, GDPR, CCPA).
- Act as a trusted advisor to GIS, CTO, and enterprise stakeholders on advanced data protection strategies and engineering practices.
- Provide clear executive-level reporting on transformation progress, security posture improvements, and program maturity.
Required Qualifications
- Minimum of 7 years of information security expertise in architecture, engineering, and operations, with focus areas in:
- DLP across endpoint, network, email, cloud, and data at rest
- Internet protocols, proxy and gateway security, firewall policy design
- Cloud security architectures and SaaS data protection
- Encryption, key management, and secure data handling
- Proven experience integrating data protection solutions with SIEM, SOAR, CASB, EDR/XDR, IAM, and secure web gateways.
- Strong capability in threat modeling and translating results into security architecture changes.
- Understanding of regulatory and industry standards for high-risk data in financial services and other regulated environments.
- Ability to lead technical design reviews and challenge architectural decisions to ensure security-by-design.
- Exceptional relationship management and influence skills across complex, global organizations.
Desired Qualifications
- Security certifications such as CISSP, CCSP, CISM, or GIAC.
- Automation and scripting skills (Python, PowerShell, etc.).
- Experience in AI-assisted anomaly detection for data security.
- Background in financial services or similarly regulated industries.
Want more jobs like this?
Get jobs in Charlotte, NC delivered to your inbox every week.

Skills:
- Cyber Security
- Data Privacy and Protection
- Problem Solving
- Process Management
- Threat Analysis
- Access and Identity Management
- Business Acumen
- Interpret Relevant Laws, Rules, and Regulations
- Risk Analytics
- Stakeholder Management
- Data Governance
- Data and Trend Analysis
- Incident Management
- Information Systems Management
- Technology System Assessment
Shift:
1st shift (United States of America)
Hours Per Week:
40
Pay Transparency details
US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540)
Pay and benefits information
Pay range
$140,000.00 - $200,000.00 annualized salary, offers to be determined based on experience, education and skill set.
Discretionary incentive eligible
This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.
Benefits
This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.
Perks and Benefits
Health and Wellness
- FSA
- HSA
- On-Site Gym
- Health Insurance
- Dental Insurance
- Vision Insurance
- Life Insurance
Parental Benefits
- Non-Birth Parent or Paternity Leave
- Birth Parent or Maternity Leave
Work Flexibility
Office Life and Perks
Vacation and Time Off
- Leave of Absence
- Personal/Sick Days
- Paid Holidays
- Paid Vacation
- Sabbatical
Financial and Retirement
- Performance Bonus
- Company Equity
- 401(K) With Company Matching
Professional Development
- Promote From Within
- Mentor Program
- Access to Online Courses
- Lunch and Learns
- Tuition Reimbursement
Diversity and Inclusion
- Diversity, Equity, and Inclusion Program