Information Security Controls Sr. Specialist
Company: Hispanic Technology Executive Council
Location: Denver
Posted on: May 3, 2025
Job Description:
Job Description:At Bank of America, we are guided by a common
purpose to help make financial lives better through the power of
every connection. We do this by driving Responsible Growth and
delivering for our clients, teammates, communities and shareholders
every day.Being a Great Place to Work is core to how we drive
Responsible Growth. This includes our commitment to being a diverse
and inclusive workplace, attracting and developing exceptional
talent, supporting our teammates physical, emotional, and financial
wellness, recognizing and rewarding performance, and how we make an
impact in the communities we serve.Bank of America is committed to
an in-office culture with specific requirements for office-based
attendance and which allows for an appropriate level of flexibility
for our teammates and businesses based on role-specific
considerations.At Bank of America, you can build a successful
career with opportunities to learn, grow, and make an impact. Join
us!Position Summary:The Independent Assessments program assesses
the Banks compliance with various regulatory requirements,
cybersecurity guidelines and frameworks. While the assessments are
organized, managed, and governed by a team of internal associates,
the requirements and frameworks are evaluated by an independent
third-party assessor.The Independent Assessment program consists of
5 primary assessments:1. Industry Framework Assessment2. SWIFT
Cyber Security Program3. FRB FedLine4. Sheltered Harbor5. ISO27001
& SOC2 readiness assessmentThe successful candidate should have
working knowledge of regulatory and industry cybersecurity
framework requirements and guidelines.The Info Security Controls
Specialist manages the assessment day to day activities to include
the following responsibilities:
- Conduct weekly status meetings.
- Supports industry assessment kickoff meetings.
- Provides assessment status updates to participants and the
senior leadership team.
- Prepares weekly status deck.
- Supports collection of assessment evidence files and documents
from enterprise subject matter experts
- Provides direction and insight to subject matter experts
regarding the assessment scope and requirements.
- Performs evidence review/analysis of compliance measured
against industry cybersecurity requirements.
- Performs quality assurance of assessment results.
- Helps prepare assessment results report.
- Maintains assessment documentation in the system of
record.
- Supports regulatory exams both regional and domestic.
- Supports corporation audit request.
- Works with Global Tech and enterprise controls partners
- Works with second line partners supporting targeted
assessments.
- Manage/support external auditor activities.
- Leads the independent third-party team of 4 to 5 members in
their evaluation of the Banks compliance with cybersecurity
requirements set forth by industry cybersecurity frameworks and
regulatory entities. Required Qualifications:
- 7 years technology and cybersecurity background
- Project management skills
- Policies, standards, and cybersecurity controls processes
comprehension
- Proficiency in MS office suite (e.g. Excel, Word, PPT)
- Experience with system of records Pega and Trident
- Cybersecurity domains and controls comprehension
- Strong communication skills with peers, subordinates, and
executive leadership
- Attention to detail.Desired Qualifications:
- Knowledge of industry cybersecurity frameworks
- CISSP Certificate
- ISO27001 & SOC2 assessment and audit experience
- This job will be open and accepting applications for a minimum
of seven days from the date it was posted.Shift:1st shift (United
States of America)Hours Per Week: 40Pay Transparency detailsUS - CO
- Denver - 1144 15th St - Denver Gis (CO9926), US - IL - Chicago -
540 W Madison St - Bank Of America Plaza (IL4540), US - NJ - Jersey
City - 101 Hudson St - 101 Hudson (NJ2101)Pay and benefits
informationPay range$130,000.00 - $176,900.00 annualized salary,
offers to be determined based on experience, education and skill
set.Discretionary incentive eligibleThis role is eligible to
participate in the annual discretionary plan. Employees are
eligible for an annual discretionary award based on their overall
individual performance results and behaviors, the performance and
contributions of their line of business and/or group; and the
overall success of the Company.BenefitsThis role is currently
benefits eligible. We provide industry-leading benefits, access to
paid time off, resources and support to our employees so they can
make a genuine impact and contribute to the sustainable growth of
our business and the communities we serve.
Keywords: Hispanic Technology Executive Council, Colorado Springs , Information Security Controls Sr. Specialist, Other , Denver, Colorado
Didn't find what you're looking for? Search again!
Loading more jobs...