girl looking into her desktop
Back to search results

Information Security Third Party Contract Review & Negotiations Risk Specialist

Denver, Colorado;

Job Description:

Are you passionate about working with the best information security team in the world?  Bank of America is hiring top talent to join our innovative and forward thinking team.

What We Do:

At Bank of America, we handle the finances of over 67 million client relationships every day, including helping them save, borrow, and invest for today and for their future.  We stand by our clients each and every day giving them the power to realize their personal financial goals and help make their financial lives better. 

The Global Information Security organization is responsible for protecting bank information systems, confidential and proprietary data, and customer information. The team:

  • Develops the bank’s Information security strategy and policy
  • Manages the Information security program and identifies and addresses vulnerabilities
  • Develops, deploys and manages a risk-based controls portfolio
  • Manages and operates a global security operations center that monitors, detects and responds to cybersecurity incidents

What We’re Looking For:

We’re looking for the next generation of Cyber security experts – those with a passion for growing a long-term career, building relationships and working with a team of innovative and forward thinking information security professionals.  Our cyber team is meant for those looking to make a real impact and build a career in information security.  The role is ideal for those who have a passion to work with industry leaders to protect our brand and the customer/client experience by proactively detecting, disrupting, and mitigating cyber security across the organization.

What You’ll Get:

From day one, you’ll receive training including hands-on practice, personalized coaching and dedicated support throughout your on-boarding experience.  With demonstrated success, you’ll have the opportunity to advance into many different roles with Global Information Security – with unlimited opportunity to grow throughout your career.  You will be supported with dedicated programs, tools, and resources throughout your career journey.

We’ll help you:

•Build a successful career at Bank of America through world-class training and on-boarding programs that set you up for success

•Grow in your current role through one-on-one coaching from managers who are invested in your success and training programs that help you excel, build new skills or take on additional responsibility

•Continuously learn and advance your career goals through intentional career paths to the next best role

•Use resources and innovative technologies to optimize the client experience

•Expand your business knowledge and network by partnering with experts in Global Information Security, Global Technology and other lines of business

•Become an expert in what you do

What you can look forward to:

•Ongoing professional development to deepen your skills and optimize your expertise as the industry evolves and changes

•Resources and dedicated support to help you reach your full potential throughout your career

•A benefits program designed to meet the diverse needs of our employees at every stage of their life and help them plan for tomorrow

•Progressive workplace practices and initiatives that promote inclusion

We’re a culture that:

•Believes in responsible growth and has a proven dedication to supporting the communities we serve.

•Provides continuous training and developmental opportunities to help people achieve their goals, whatever their background or experience.

•Believes diversity makes us stronger, so we can reflect, connect to and meet the diverse needs of our clients and customers around the world.

•Is committed to advancing our tools, technology, and ways of working. We always put our clients first to meet their evolving needs.

This position will be a member of the Assurance Risk and Contract Strategy (ARCS) team within the Cyber Security Assurance (CSA) organization in Global Information Security (GIS), and will provide support for vendor contract risk management efforts relating to information security. This position will interface with senior leaders and partners across GIS and the company, and directly with bank vendors, to develop perspectives on information security risk and drive effective risk management.

Key Responsibilities
-    Conduct third party contract reviews and negotiations as part of information security due diligence of vendors proposing or selected to provide products/services to Bank of America
-    Suggest alternate contractual terms to address concerns of the third party while maintaining adequate the information security protections for Bank of America
-    Lead escalation of deviations from the bank's standard information security material terms to senior information security and business leaders.

Required Skills:
•    Candidates must have at least 5 years of relevant experience.  (Previous information technology/security audit/assessment experience a plus.)
•    Individual must possess superior written and verbal communication skills including the ability to communicate clearly and concisely to all levels, up to and including executive level management, and explain the need for key controls to technical and non-technical resources.
•    Strong attention to detail, analytical skills, ability to multi-task, and ability to work both independently as well as part of a due diligence team are also required. 
•    Candidates must be able to plan, execute and document assessment due diligence activities following established processes and procedures.
•    Ability to mobilize and motivate teams; set direction and approach; resolve conflict; execute with limited information and ambiguity
•    Ability to interact with and influence senior-level technical and non-technical stakeholders
•    Ability to “connect the dots” across multiple data points, make connections upstream/downstream that may not be easily noticeable

Enterprise Job Description: Architects, engineers, designs, documents, or supports business solutions for Risk Management either from as technologist or a business analyst. Has deep knowledge of business functions and mastered their profession. Is a subject matter expert in technology, business, or operations and a thought leader for assisting senior technology or business leaders in determining the current and future direction in their area or related areas. Utilizes in-depth knowledge of technological alternatives, business requirements, and business environments to recommend innovations that enhance and/or provide a competitive advantage to the organization. Provides leadership and guidance on issues of critical importance to achieving business objectives. Has extensive & specific business knowledge or technical skillset e.g. Quantitative skills, Capital Markets, Credit Risk, Operational Risk, Compliance, Legal / Audit, Universal Bank: Typically requires 7-10 years of applicable experience.

Job Band:

H4

Shift: 

1st shift (United States of America)

Hours Per Week:

40

Weekly Schedule:

Referral Bonus Amount:

0

Job Description:

Are you passionate about working with the best information security team in the world?  Bank of America is hiring top talent to join our innovative and forward thinking team.

What We Do:

At Bank of America, we handle the finances of over 67 million client relationships every day, including helping them save, borrow, and invest for today and for their future.  We stand by our clients each and every day giving them the power to realize their personal financial goals and help make their financial lives better. 

The Global Information Security organization is responsible for protecting bank information systems, confidential and proprietary data, and customer information. The team:

  • Develops the bank’s Information security strategy and policy
  • Manages the Information security program and identifies and addresses vulnerabilities
  • Develops, deploys and manages a risk-based controls portfolio
  • Manages and operates a global security operations center that monitors, detects and responds to cybersecurity incidents

What We’re Looking For:

We’re looking for the next generation of Cyber security experts – those with a passion for growing a long-term career, building relationships and working with a team of innovative and forward thinking information security professionals.  Our cyber team is meant for those looking to make a real impact and build a career in information security.  The role is ideal for those who have a passion to work with industry leaders to protect our brand and the customer/client experience by proactively detecting, disrupting, and mitigating cyber security across the organization.

What You’ll Get:

From day one, you’ll receive training including hands-on practice, personalized coaching and dedicated support throughout your on-boarding experience.  With demonstrated success, you’ll have the opportunity to advance into many different roles with Global Information Security – with unlimited opportunity to grow throughout your career.  You will be supported with dedicated programs, tools, and resources throughout your career journey.

We’ll help you:

•Build a successful career at Bank of America through world-class training and on-boarding programs that set you up for success

•Grow in your current role through one-on-one coaching from managers who are invested in your success and training programs that help you excel, build new skills or take on additional responsibility

•Continuously learn and advance your career goals through intentional career paths to the next best role

•Use resources and innovative technologies to optimize the client experience

•Expand your business knowledge and network by partnering with experts in Global Information Security, Global Technology and other lines of business

•Become an expert in what you do

What you can look forward to:

•Ongoing professional development to deepen your skills and optimize your expertise as the industry evolves and changes

•Resources and dedicated support to help you reach your full potential throughout your career

•A benefits program designed to meet the diverse needs of our employees at every stage of their life and help them plan for tomorrow

•Progressive workplace practices and initiatives that promote inclusion

We’re a culture that:

•Believes in responsible growth and has a proven dedication to supporting the communities we serve.

•Provides continuous training and developmental opportunities to help people achieve their goals, whatever their background or experience.

•Believes diversity makes us stronger, so we can reflect, connect to and meet the diverse needs of our clients and customers around the world.

•Is committed to advancing our tools, technology, and ways of working. We always put our clients first to meet their evolving needs.

This position will be a member of the Assurance Risk and Contract Strategy (ARCS) team within the Cyber Security Assurance (CSA) organization in Global Information Security (GIS), and will provide support for vendor contract risk management efforts relating to information security. This position will interface with senior leaders and partners across GIS and the company, and directly with bank vendors, to develop perspectives on information security risk and drive effective risk management.

Key Responsibilities
-    Conduct third party contract reviews and negotiations as part of information security due diligence of vendors proposing or selected to provide products/services to Bank of America
-    Suggest alternate contractual terms to address concerns of the third party while maintaining adequate the information security protections for Bank of America
-    Lead escalation of deviations from the bank's standard information security material terms to senior information security and business leaders.

Required Skills:
•    Candidates must have at least 5 years of relevant experience.  (Previous information technology/security audit/assessment experience a plus.)
•    Individual must possess superior written and verbal communication skills including the ability to communicate clearly and concisely to all levels, up to and including executive level management, and explain the need for key controls to technical and non-technical resources.
•    Strong attention to detail, analytical skills, ability to multi-task, and ability to work both independently as well as part of a due diligence team are also required. 
•    Candidates must be able to plan, execute and document assessment due diligence activities following established processes and procedures.
•    Ability to mobilize and motivate teams; set direction and approach; resolve conflict; execute with limited information and ambiguity
•    Ability to interact with and influence senior-level technical and non-technical stakeholders
•    Ability to “connect the dots” across multiple data points, make connections upstream/downstream that may not be easily noticeable

Enterprise Job Description: Architects, engineers, designs, documents, or supports business solutions for Risk Management either from as technologist or a business analyst. Has deep knowledge of business functions and mastered their profession. Is a subject matter expert in technology, business, or operations and a thought leader for assisting senior technology or business leaders in determining the current and future direction in their area or related areas. Utilizes in-depth knowledge of technological alternatives, business requirements, and business environments to recommend innovations that enhance and/or provide a competitive advantage to the organization. Provides leadership and guidance on issues of critical importance to achieving business objectives. Has extensive & specific business knowledge or technical skillset e.g. Quantitative skills, Capital Markets, Credit Risk, Operational Risk, Compliance, Legal / Audit, Universal Bank: Typically requires 7-10 years of applicable experience.

Shift:

1st shift (United States of America)

Hours Per Week: 

40

Learn more about this role

Full time

JR-22055448

Band: H4

Manages People: No

Travel: No

Manager:

Talent Acquisition Contact:

Stuart Collier

Referral Bonus:

0

Colorado pay and benefits information

Colorado pay range:

$141,500 - $171,500 annualized salary, offers to be determined based on experience, education and skill set.

Discretionary incentive eligible

This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.

Benefits

This role is currently benefits eligible. We provide industry-leading benefits, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.