Information Security Officer
Listed on 2025-12-27
-
IT/Tech
Cybersecurity, Information Security
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates' physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.
Bank of America is committed to an in‑office culture with specific requirements for office‑based attendance and allows for an appropriate level of flexibility for our teammates and businesses based on role‑specific considerations. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
The Business Information Security Officer (BISO) will be a functional member of the BISO organization and work closely with the Consumer, Small Business and Wealth Technology (CBWT) Chief Information Officers (CIOs)/Technology teams to develop a strong understanding of the business in order to have specialized information security risk‑based discussions. This relationship will ensure a focus on the right risk priorities. The BISO will act as the day‑to‑day point of contact providing guidance on information security topics, policies, and controls;
ultimately becoming a trusted advisor to our stakeholders. The BISO serves as a subject matter expert on the development, implementation, and maintenance of information security for the line of business (LOB), provides guidance and advocacy regarding the prioritization of LOB investments and the impact on information security, and advises LOB management on risk issues related to information security while recommending actions in support of the bank’s wider risk management and compliance programs.
- Provide advisory and oversight for changes within the CBWT environment related to security and leverage regional information security consultants and global operational response teams as needed.
- Work in collaboration with the Risk teams supporting them in their activities and helping them continue to develop processes and solutions.
- Work with the global BISO organization to ensure that GIS requirements and initiatives are communicated, discussed, and tracked in an effective, consistent and timely way.
- Establish and maintain a network of stakeholders and partners.
- Conduct routine liaison and coordination across the risk partners and technology groups to remediate GIS issues showing red or amber on the vulnerability remediation dashboard.
- Coordinate and drive remediation of ad‑hoc GIS issues and assist partners to reach a resolution in line with GIS baselines and standards.
- Assist business leaders and technology teams by supporting initiatives requiring Global Information Security (GIS) engagement and facilitating problem resolution for cyber security related issues.
- Serve as a common risk control partner in order to identify emerging security risks in the portfolio.
- Drive adherence to appropriate risk tolerance levels, operating in accordance with defined information security policies to protect against threats to data confidentiality, integrity, and availability.
- Promote awareness of current and emerging cybersecurity threats and advise on potential information security exposure.
- Assess and mitigate cyber security risks related to application, network, infrastructure, and public cloud.
- Interpret the information security requirements outlined in policies, standards, and procedures and reinforce requirements through education and awareness.
- Support teammates who serve as “security ambassadors” to help partners drive strategic and innovative risk mitigation priorities and navigate the GIS organization.
- Experience with in an information security technology operational, engineering or consulting team with good knowledge of the security controls and processes required within systems and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).