Job Description:
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates' physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations.
Want more jobs like this?
Get jobs delivered to your inbox every week.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Job Description:
The Information Security Consultant - Cloud Security will be part of the Global Information Security (GIS) Cyber Security Assurance (CSA) Infrastructure Remediation Governance team. In this role, you will play an integral part in ensuring security of the cloud infrastructure by governing and overseeing remediation activities. As the Cloud Remediation Governance resource, you will collaborate closely with cross functional teams and stakeholders in IT, business technology groups, Risk Partners, and GIS teams across their respective LOBs. You will present key findings, progress, and escalate issues and be responsible for influencing the stakeholders to prioritize/execute risk management issues and lead remediation efforts.
Key responsibilities:
- Oversee remediation efforts for identified vulnerabilities and compliance/configuration violations in the cloud infrastructure environment.
- Analyze findings from security monitoring systems such as Aqua, Qualys Scanning, Network Configuration Compliance, and Security Compliance, to identify and direct a respond to all potential security incidents and data breaches.
- Review all current and existing vulnerabilities for active and acceptable remediation plans. These plans may be reviewed with LOB point of contacts, Application Owners, Data Owners / Custodians or System Administrators. Verify that remediation plans are implemented per remediation plan and GIS guidelines. Review and identify any potential gaps that may result in possible audit issues.
- Drive remediation of vulnerabilities and misconfiguration issues in public and private cloud
- Design and enhance vulnerability management process for public and private cloud.
- Serve as a key resource in improving the governance of end-user remediation and act as the subject matter expert of end-user remediation governance.
- Review all vulnerability scan results to identify all security risks and report on findings to appropriate partners.
- Respond to relevant requests received from stakeholders, or representatives of stakeholders, for investigation of potential reporting issues.
- Provide all necessary reports and presentations on the status of remediation efforts and all gaps and potential obstacles or issues to management and technical staff.
- Performs other related duties incidental to the work described herein and all special assignments as needed or assigned.
Required Qualifications
- 5+ years of experience in information security
- 2+ years of experience identifying vulnerabilities in a cloud environment and creating/reviewing plans for remediation
- Proven project management Skills
- Knowledgeable with cloud-native application development and application modernization
- Experience with one or more of Cloud Service Provider (i.e. AWS, and Azure) products and services
- Experience with Aqua, Qualys Scanning or similar security monitoring systems
- Excellent communication skills, and the ability to understand and translate cyber security threats from a technical perspective to business-line understanding and execution; ability to communicate risks and propose counter measures to senior technology executives
- Well-developed analytic, qualitative, and quantitative reasoning skills and demonstrated creative problem-solving abilities with complementary skills for log analytics and diagnosis skills utilizing regular expression and/or scripting
- Ability to work independently on initiatives with little oversight. Motivated and willing to learn
- Broad technical background utilizing security technologies, such as Cloud, Server and workstation Operating Systems, Network Security, Vulnerability Scanning Engines, and Compliance Management solutions
- Strong PC skills including Microsoft Office applications
Desired Qualifications
- Bachelors and/or Master's degree in Computer Science, Information Technology or related field
- Strong analytical skills/problem solving/conceptual thinking
- Ability to effectively communicate with Technical and Non-Technical business owners
- Lead internal efficiencies projects and development
Skills:
- Controls Management
- Cyber Security
- Data Governance
- Information Systems Management
- Risk Management
This job will be open and accepting applications for a minimum of seven days from the date it was posted.
Shift:
1st shift (United States of America)
Hours Per Week:
40
Pay Transparency details
US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540), US - NJ - Jersey City - 101 Hudson St - 101 Hudson (NJ2101)
Pay and benefits information
Pay range
$99,200.00 - $145,100.00 annualized salary, offers to be determined based on experience, education and skill set.
Discretionary incentive eligible
This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.
Benefits
This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.